Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
ROh2ijuEpr.exe

Overview

General Information

Sample name:ROh2ijuEpr.exe
renamed because original name is a hash value
Original sample name:7b54b8972d8f870cb5cf66a4f9a92c78b56395ac802fb3d4bf05b18bbab9d5a4.exe
Analysis ID:1569042
MD5:37c4774a4906c4344c5f55d019033718
SHA1:7a8603814259adfd4934ffdfde0a7fd78e1ac42c
SHA256:7b54b8972d8f870cb5cf66a4f9a92c78b56395ac802fb3d4bf05b18bbab9d5a4
Tags:exeuser-JAMESWT_MHT
Infos:

Detection

Babuk, Conti
Score:76
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected Babuk Ransomware
Yara detected Conti ransomware
Yara detected Python Ransomware
AI detected suspicious sample
Deletes shadow drive data (may be related to ransomware)
Uses the Telegram API (likely for C&C communication)
Binary contains a suspicious time stamp
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to detect virtual machines (SGDT)
Contains functionality to query CPU information (cpuid)
Contains functionality to retrieve information about pressed keystrokes
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file does not import any functions
Potential key logger detected (key state polling based)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses Microsoft's Enhanced Cryptographic Provider

Classification

  • System is w10x64
  • ROh2ijuEpr.exe (PID: 3684 cmdline: "C:\Users\user\Desktop\ROh2ijuEpr.exe" MD5: 37C4774A4906C4344C5F55D019033718)
    • conhost.exe (PID: 2916 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • ROh2ijuEpr.exe (PID: 6436 cmdline: "C:\Users\user\Desktop\ROh2ijuEpr.exe" MD5: 37C4774A4906C4344C5F55D019033718)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
BabukBabuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.babuk
NameDescriptionAttributionBlogpost URLsLink
Conti, Conti LockConti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.
  • WIZARD SPIDER
https://malpedia.caad.fkie.fraunhofer.de/details/win.conti
No configs have been found
SourceRuleDescriptionAuthorStrings
Process Memory Space: ROh2ijuEpr.exe PID: 6436JoeSecurity_Conti_ransomwareYara detected Conti ransomwareJoe Security
    Process Memory Space: ROh2ijuEpr.exe PID: 6436JoeSecurity_babukYara detected Babuk RansomwareJoe Security
      Process Memory Space: ROh2ijuEpr.exe PID: 6436JoeSecurity_PythonRansomwareYara detected Python RansomwareJoe Security
        No Sigma rule has matched
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: Submited SampleIntegrated Neural Analysis Model: Matched 98.2% probability
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8F2410 ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_zalloc,CRYPTO_THREAD_lock_new,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,OPENSSL_sk_dup,X509_VERIFY_PARAM_new,X509_VERIFY_PARAM_inherit,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_malloc,memcpy,CRYPTO_new_ex_data,3_2_00007FFDFA8F2410
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D23DD EVP_MD_get_size,EVP_CIPHER_get_iv_length,EVP_CIPHER_get_key_length,CRYPTO_clear_free,CRYPTO_malloc,ERR_new,ERR_set_debug,3_2_00007FFDFA8D23DD
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8EE427 CRYPTO_THREAD_write_lock,3_2_00007FFDFA8EE427
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D198D CRYPTO_THREAD_write_lock,CRYPTO_THREAD_unlock,3_2_00007FFDFA8D198D
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA928390 CRYPTO_free,CRYPTO_free,CRYPTO_free,3_2_00007FFDFA928390
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8E2360 CRYPTO_THREAD_run_once,3_2_00007FFDFA8E2360
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA9343C0 EVP_MD_CTX_new,EVP_DigestInit,EVP_DigestUpdate,EVP_DigestUpdate,EVP_DigestFinal_ex,EVP_MD_CTX_free,CRYPTO_malloc,EVP_PKEY_CTX_ctrl,EVP_PKEY_encrypt,EVP_PKEY_CTX_free,ERR_new,ERR_set_debug,EVP_PKEY_CTX_free,CRYPTO_clear_free,ERR_new,ERR_set_debug,3_2_00007FFDFA9343C0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA93A3D0 ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free,CRYPTO_strndup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,3_2_00007FFDFA93A3D0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1D93 EVP_CIPHER_CTX_free,EVP_CIPHER_CTX_free,EVP_CIPHER_CTX_free,CRYPTO_zalloc,EVP_MAC_CTX_free,EVP_MAC_free,CRYPTO_free,EVP_CIPHER_CTX_free,EVP_MAC_fetch,EVP_MAC_CTX_new,EVP_MAC_free,EVP_CIPHER_CTX_new,EVP_CIPHER_fetch,OSSL_PARAM_construct_utf8_string,OSSL_PARAM_construct_end,EVP_MAC_init,EVP_DecryptInit_ex,EVP_CIPHER_free,EVP_CIPHER_free,EVP_CIPHER_free,EVP_MAC_CTX_get_mac_size,EVP_CIPHER_CTX_get_iv_length,EVP_MAC_final,CRYPTO_memcmp,CRYPTO_malloc,CRYPTO_free,CRYPTO_free,memcpy,ERR_clear_error,CRYPTO_free,EVP_CIPHER_CTX_free,EVP_MAC_CTX_free,CRYPTO_free,3_2_00007FFDFA8D1D93
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1361 CRYPTO_malloc,EVP_PKEY_set_type,EVP_PKEY_CTX_new_from_pkey,EVP_PKEY_CTX_free,ERR_pop_to_mark,CRYPTO_free,EVP_PKEY_free,3_2_00007FFDFA8D1361
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D4100 CRYPTO_free,3_2_00007FFDFA8D4100
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D19DD BN_copy,BN_free,BN_dup,BN_copy,BN_free,BN_dup,BN_copy,BN_free,BN_dup,BN_copy,BN_free,CRYPTO_free,CRYPTO_strdup,3_2_00007FFDFA8D19DD
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D2527 CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,3_2_00007FFDFA8D2527
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8EC080 CRYPTO_free,CRYPTO_memdup,3_2_00007FFDFA8EC080
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA9280C0 CRYPTO_memdup,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_free,CRYPTO_free,CRYPTO_free,3_2_00007FFDFA9280C0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8DE0AD ERR_set_debug,CRYPTO_free,CRYPTO_strdup,ERR_new,3_2_00007FFDFA8DE0AD
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8F20A0 memcpy,CRYPTO_THREAD_read_lock,OPENSSL_LH_retrieve,CRYPTO_THREAD_unlock,3_2_00007FFDFA8F20A0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA9300A0 CRYPTO_free,CRYPTO_memdup,3_2_00007FFDFA9300A0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA91E200 CRYPTO_free,CRYPTO_strdup,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,3_2_00007FFDFA91E200
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1389 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,3_2_00007FFDFA8D1389
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1F55 CRYPTO_THREAD_write_lock,CRYPTO_THREAD_unlock,3_2_00007FFDFA8D1F55
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA91E190 CRYPTO_free,3_2_00007FFDFA91E190
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D15E6 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,memcpy,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,memcpy,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_set_debug,ERR_set_error,3_2_00007FFDFA8D15E6
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D103C CRYPTO_malloc,COMP_expand_block,3_2_00007FFDFA8D103C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA91E700 CRYPTO_free,3_2_00007FFDFA91E700
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D120D EVP_PKEY_free,EVP_PKEY_free,CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_clear_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,memset,3_2_00007FFDFA8D120D
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D16A4 CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,3_2_00007FFDFA8D16A4
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA914660 CRYPTO_malloc,memset,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,ERR_new,ERR_set_debug,3_2_00007FFDFA914660
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D162C EVP_MD_CTX_new,ERR_new,ERR_set_debug,ERR_new,EVP_MD_get0_name,EVP_DigestSignInit_ex,ERR_new,ERR_set_debug,EVP_PKEY_CTX_set_rsa_padding,EVP_PKEY_CTX_set_rsa_pss_saltlen,ERR_new,EVP_DigestSignUpdate,EVP_DigestSignFinal,CRYPTO_malloc,EVP_DigestSignFinal,ERR_new,ERR_new,EVP_DigestSign,ERR_new,CRYPTO_malloc,EVP_DigestSign,BUF_reverse,ERR_new,CRYPTO_free,EVP_MD_CTX_free,ERR_new,ERR_new,ERR_new,ERR_set_debug,CRYPTO_free,EVP_MD_CTX_free,3_2_00007FFDFA8D162C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8EA6D0 CRYPTO_free,CRYPTO_free,OPENSSL_sk_pop_free,CRYPTO_free,3_2_00007FFDFA8EA6D0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA9126B0 ERR_new,ERR_set_debug,BN_num_bits,CRYPTO_malloc,ERR_new,ERR_set_debug,BN_bn2bin,ERR_new,ERR_set_debug,BN_clear_free,BN_clear_free,CRYPTO_clear_free,ERR_new,ERR_set_debug,BN_clear_free,BN_clear_free,BN_clear_free,3_2_00007FFDFA9126B0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D25F4 CRYPTO_malloc,ERR_new,ERR_set_debug,memcpy,memcpy,memcmp,memcmp,memcmp,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_clear_free,3_2_00007FFDFA8D25F4
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1F3C CRYPTO_malloc,ERR_new,ERR_set_debug,3_2_00007FFDFA8D1F3C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1CA3 CRYPTO_strdup,CRYPTO_free,3_2_00007FFDFA8D1CA3
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D2423 CRYPTO_zalloc,CRYPTO_zalloc,OBJ_nid2sn,EVP_get_digestbyname,OBJ_nid2sn,EVP_get_digestbyname,CRYPTO_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,3_2_00007FFDFA8D2423
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA91E781 CRYPTO_free,CRYPTO_free,3_2_00007FFDFA91E781
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1401 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_free,3_2_00007FFDFA8D1401
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1F28 ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_strdup,3_2_00007FFDFA8D1F28
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1ACD ERR_new,ERR_set_debug,CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcpy,memcpy,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_new,memcpy,ERR_new,memcpy,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free,3_2_00007FFDFA8D1ACD
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8E4530 OPENSSL_sk_num,X509_STORE_CTX_new_ex,ERR_new,ERR_set_debug,ERR_set_error,OPENSSL_sk_value,X509_STORE_CTX_init,ERR_new,ERR_set_debug,ERR_set_error,X509_STORE_CTX_free,X509_STORE_CTX_set_flags,CRYPTO_THREAD_run_once,X509_STORE_CTX_set_ex_data,OPENSSL_sk_num,X509_STORE_CTX_set0_dane,X509_STORE_CTX_set_default,X509_VERIFY_PARAM_set1,X509_STORE_CTX_set_verify_cb,X509_verify_cert,X509_STORE_CTX_get_error,OPENSSL_sk_pop_free,X509_STORE_CTX_get0_chain,X509_STORE_CTX_get1_chain,ERR_new,ERR_set_debug,ERR_set_error,X509_VERIFY_PARAM_move_peername,X509_STORE_CTX_free,3_2_00007FFDFA8E4530
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA946550 CRYPTO_memcmp,3_2_00007FFDFA946550
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1AC3 CRYPTO_THREAD_read_lock,CRYPTO_THREAD_unlock,3_2_00007FFDFA8D1AC3
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA904490 CRYPTO_realloc,memcpy,ERR_new,ERR_set_debug,ERR_set_error,3_2_00007FFDFA904490
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D18B6 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,3_2_00007FFDFA8D18B6
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D26E4 BIO_s_file,BIO_new,ERR_new,ERR_set_debug,BIO_ctrl,ERR_new,ERR_set_debug,strncmp,ERR_new,ERR_set_debug,strncmp,CRYPTO_realloc,memcpy,CRYPTO_free,CRYPTO_free,CRYPTO_free,PEM_read_bio,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,BIO_free,3_2_00007FFDFA8D26E4
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8F05E0 X509_VERIFY_PARAM_free,CRYPTO_free_ex_data,BIO_pop,BIO_free,BIO_free_all,BIO_free_all,BUF_MEM_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,SCT_LIST_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,EVP_MD_CTX_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,ASYNC_WAIT_CTX_free,CRYPTO_free,OPENSSL_sk_free,CRYPTO_THREAD_lock_free,CRYPTO_free,3_2_00007FFDFA8F05E0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D13D9 OPENSSL_sk_new_null,ERR_new,ERR_set_debug,X509_new_ex,d2i_X509,CRYPTO_free,OPENSSL_sk_push,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_set_error,ERR_new,ERR_new,ERR_set_debug,X509_free,OPENSSL_sk_pop_free,3_2_00007FFDFA8D13D9
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA936650 EVP_CIPHER_CTX_free,CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_free,3_2_00007FFDFA936650
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D24CD CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,memcpy,3_2_00007FFDFA8D24CD
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA928620 CRYPTO_memcmp,3_2_00007FFDFA928620
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1212 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,3_2_00007FFDFA8D1212
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1488 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,3_2_00007FFDFA8D1488
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D85A0 CRYPTO_zalloc,CRYPTO_free,3_2_00007FFDFA8D85A0
        Source: ROh2ijuEpr.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
        Source: Binary string: C:\Users\qt\work\qt\qtsvg\plugins\iconengines\qsvgicon.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtsvg\plugins\imageformats\qsvg.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: The standard debugger class (pdb.Pdb) is an example. source: ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1998907368.000002B7E3210000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971351400.000002B7E281B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1976706420.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970433771.000002B7E2814000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980724033.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983571863.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\generic\qtuiotouchplugin.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1781128700.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: @ compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG"OpenSSL 3.0.15 3 Sep 20243.0.15built on: Wed Sep 4 15:52:04 2024 UTCplatform: VC-WIN64A-masmOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "C:\Program Files\OpenSSL\lib\engines-3"MODULESDIR: "C:\Program Files\OpenSSL\lib\ossl-modules"CPUINFO: N/Anot availableget_and_lock..\s\crypto\ex_data.cossl_crypto_get_ex_new_index_exossl_crypto_new_ex_data_exCRYPTO_dup_ex_dataCRYPTO_set_ex_dataOPENSSL_WIN32_UTF8..\s\crypto\getenv.ccompiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG";CPUINFO: OPENSSL_ia32cap=0x%llx:0x%llxOPENSSL_ia32cap env:%sos-specificC:\Program Files\Common Files\SSLC:\Program Files\OpenSSL\lib\ossl-modules.dllCPUINFO: ..\s\crypto\init.cOPENSSL_init_cryptoOPENSSL_atexit..\s\crypto\initthread.c..\s\crypto\mem_sec.cassertion failed: (bit & 1) == 0assertion failed: list >= 0 && list < sh.freelist_sizeassertion failed: ((ptr - sh.arena) & ((sh.arena_size >> list) - 1)) == 0assertion failed: bit > 0 && bit < sh.bittable_sizeassertion failed: TESTBIT(table, bit)assertion failed: !TESTBIT(table, bit)assertion failed: WITHIN_FREELIST(list)assertion failed: WITHIN_ARENA(ptr)assertion failed: temp->next == NULL || WITHIN_ARENA(temp->next)assertion failed: (char **)temp->next->p_next == listassertion failed: WITHIN_FREELIST(temp2->p_next) || WITHIN_ARENA(temp2->p_next)assertion failed: size > 0assertion failed: (size & (size - 1)) == 0assertion failed: (minsize & (minsize - 1)) == 0assertion failed: sh.freelist != NULLassertion failed: sh.bittable != NULLassertion failed: sh.bitmalloc != NULLassertion failed: !sh_testbit(temp, slist, sh.bitmalloc)assertion failed: temp != sh.freelist[slist]assertion failed: sh.freelist[slist] == tempassertion failed: temp-(sh.arena_size >> slist) == sh_find_my_buddy(temp, slist)assertion failed: sh_testbit(chunk, list, sh.bittable)assertion failed: WITHIN_ARENA(chunk)assertion failed: sh_testbit(ptr, list, sh.bittable)assertion failed: ptr == sh_find_my_buddy(buddy, list)assertion failed: ptr != NULLassertion failed: !sh_testbit(ptr, list, sh.bitmalloc)assertion failed: sh.freelist[list] == ptr/*0123456789ABCDEFCRYPTO_memdup..\s\crypto\o_str.chexstr2buf_sepossl_hexstr2buf_sepbuf2hexstr_sepossl_buf2hexstr_sep..\s\crypto\packet.cwpacket_intern_init_lenWPACKET_start_sub_packet_len__..\s\crypto\param_build.cparam_pushparam_push_numOSSL_PARAM_BLD_push_BN_padNegative big numbers are unsupported for OSSL_PARAMOSSL_PARAM_BLD_push_utf8_stringOSSL_PARAM_BLD_push_utf8_ptrOSSL_PARAM_BLD_push_octet_stringOSSL_PARAM_BLD_p
        Source: Binary string: ~/.pdbrc source: ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989081522.000002B7E2436000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970789616.000002B7E2869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1988982211.000002B7E286A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961461803.000002B7E2861000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982809276.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: dpdb commands to execute as if given in a .pdbrc file0m source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG" source: ROh2ijuEpr.exe, 00000003.00000002.2002708965.00007FFDFAD52000.00000002.00000001.01000000.00000019.sdmp
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: ROh2ijuEpr.exe, 00000000.00000003.1802500436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: pdb.Pdb source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: d:\agent\_work\1\s\\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1770778003.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: If a file ".pdbrc" exists in your home directory or in the current source: ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983318461.000002B7E2808000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984587900.000002B7E2808000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1802644329.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: dpdb.Pdb` source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_hashlib.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1781128700.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_asyncio.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\generic\qtuiotouchplugin.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdbT source: ROh2ijuEpr.exe, 00000003.00000002.2003359614.00007FFDFB326000.00000002.00000001.01000000.00000011.sdmp
        Source: Binary string: placed in the .pdbrc file): source: ROh2ijuEpr.exe, 00000003.00000003.1984497184.000002B7E19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983318461.000002B7E2808000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1997930385.000002B7E280B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984587900.000002B7E2808000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_bz2.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdbGCTL source: ROh2ijuEpr.exe, 00000000.00000003.1802644329.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: d:\agent\_work\1\s\\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1770542971.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: pdb.Pdbr source: ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989081522.000002B7E2436000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970789616.000002B7E2869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1988982211.000002B7E286A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961461803.000002B7E2861000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982809276.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdbBB source: ROh2ijuEpr.exe, 00000000.00000003.1785081732.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\platformthemes\qxdgdesktopportal.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\unicodedata.pdb source: ROh2ijuEpr.exe, 00000003.00000002.2001701186.00007FFDFA8C7000.00000002.00000001.01000000.00000033.sdmp
        Source: Binary string: d:\agent\_work\1\s\\binaries\amd64ret\bin\amd64\\msvcp140_1.amd64.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1759663363.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_elementtree.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdb source: ROh2ijuEpr.exe, 00000003.00000002.2003359614.00007FFDFB326000.00000002.00000001.01000000.00000011.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1785081732.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qgif.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: d.pdbrc source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtga.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1783973276.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1802500436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: -c are executed after commands from .pdbrc files. source: ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971351400.000002B7E281B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1976706420.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970433771.000002B7E2814000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980724033.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983571863.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qicns.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: pdb commands to execute as if given in a .pdbrc file source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\select.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Initial commands are read from .pdbrc files in your home directory source: ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971351400.000002B7E281B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1976706420.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970433771.000002B7E2814000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980724033.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983571863.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: .pdbrc source: ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989081522.000002B7E2436000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970789616.000002B7E2869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1988982211.000002B7E286A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961461803.000002B7E2861000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982809276.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdbNN source: ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: d~/.pdbrc source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qwbmp.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\python3.pdb source: ROh2ijuEpr.exe, 00000003.00000002.1991032882.000002B7E0E20000.00000002.00000001.01000000.00000007.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\libEGL.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A87800 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,0_2_00007FF762A87800
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A88840 FindFirstFileExW,FindClose,0_2_00007FF762A88840
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA2AE4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF762AA2AE4
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A88840 FindFirstFileExW,FindClose,3_2_00007FF762A88840
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762AA2AE4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,3_2_00007FF762AA2AE4
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A87800 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,3_2_00007FF762A87800
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\AppData\Local\Temp\Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\AppData\Local\Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI36842\Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\AppData\Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\Jump to behavior

        Networking

        barindex
        Source: unknownDNS query: name: api.telegram.org
        Source: Joe Sandbox ViewIP Address: 149.154.167.220 149.154.167.220
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: global trafficDNS traffic detected: DNS query: api.telegram.org
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://.../back.jpeg
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995911731.000002B7E2130000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://aka.ms/vcpython27
        Source: ROh2ijuEpr.exe, 00000003.00000002.1994772474.000002B7E1A02000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966373385.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969913757.000002B7E1B16000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984497184.000002B7E19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982101411.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963385669.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963080661.000002B7E1B1D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983540772.000002B7E1805000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1978447243.000002B7E1801000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1994671358.000002B7E19BB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986984522.000002B7E17A5000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963747551.000002B7E1B15000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1985904359.000002B7E19B4000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966679097.000002B7E1B1E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972733319.000002B7E1B16000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971797186.000002B7E17FD000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://blog.cryptographyengineering.com/2012/05/how-to-choose-authenticated-encryption.html
        Source: ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.dig
        Source: ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digX
        Source: ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredID
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
        Source: ROh2ijuEpr.exe, 00000003.00000002.1994596188.000002B7E199A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962217868.000002B7E141B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967147366.000002B7E1999000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963665985.000002B7E1976000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970389525.000002B7E1783000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972568235.000002B7E1784000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968463857.000002B7E177E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964588757.000002B7E1977000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1893278217.000002B7E1785000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970111372.000002B7E199A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E177D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1985509571.000002B7E199A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989117014.000002B7E199A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1973193313.000002B7E142D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964103183.000002B7E141D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1981033586.000002B7E1784000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966598366.000002B7E142C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965750956.000002B7E141D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://code.activestate.com/recipes/577452-a-memoize-decorator-for-instance-methods/
        Source: ROh2ijuEpr.exe, 00000003.00000003.1964931483.000002B7E135E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1891883791.000002B7E1869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1890950701.000002B7E1869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1890950701.000002B7E1812000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970490763.000002B7E1363000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963695833.000002B7E1354000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1894089672.000002B7E1330000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963723315.000002B7E135D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://code.activestate.com/recipes/577916/
        Source: ROh2ijuEpr.exe, 00000003.00000003.1971740530.000002B7E2662000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1996828712.000002B7E25FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.certigna.fr/certignarootca.crl01
        Source: ROh2ijuEpr.exe, 00000003.00000003.1978029380.000002B7E261F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1991439320.000002B7E102A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967420787.000002B7E1009000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982631016.000002B7E2620000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983014111.000002B7E1025000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
        Source: ROh2ijuEpr.exe, 00000003.00000003.1970834515.000002B7E1344000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965489833.000002B7E133C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1992285422.000002B7E1345000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl
        Source: ROh2ijuEpr.exe, 00000003.00000003.1983540772.000002B7E1805000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1978447243.000002B7E1801000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971797186.000002B7E17FD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl#
        Source: ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.dhimyotis.com/certignarootca.crl
        Source: ROh2ijuEpr.exe, 00000003.00000003.1978029380.000002B7E261F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982631016.000002B7E2620000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crl
        Source: ROh2ijuEpr.exe, 00000003.00000003.1973072375.000002B7E17D7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982784444.000002B7E17D7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crl0
        Source: ROh2ijuEpr.exe, 00000003.00000003.1978029380.000002B7E261F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982631016.000002B7E2620000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crl
        Source: ROh2ijuEpr.exe, 00000003.00000003.1973072375.000002B7E17D7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982784444.000002B7E17D7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crl0
        Source: ROh2ijuEpr.exe, 00000003.00000003.1978029380.000002B7E261F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982631016.000002B7E2620000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl
        Source: ROh2ijuEpr.exe, 00000003.00000003.1978029380.000002B7E261F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982631016.000002B7E2620000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl0
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
        Source: ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
        Source: ROh2ijuEpr.exe, 00000000.00000003.1786304769.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
        Source: ROh2ijuEpr.exe, 00000003.00000003.1966373385.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982101411.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963385669.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1994671358.000002B7E19BB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986984522.000002B7E17A5000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1985904359.000002B7E19B4000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1985867788.000002B7E19AB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/groups/ST/toolkit/BCM/documents/proposedmodes/eax/eax-spec.pdf
        Source: ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963080661.000002B7E1B1D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966679097.000002B7E1B1E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/publications/nistpubs/800-38C/SP800-38C.pdf
        Source: ROh2ijuEpr.exe, 00000003.00000002.1994772474.000002B7E1A02000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969913757.000002B7E1B16000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984497184.000002B7E19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963747551.000002B7E1B15000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972733319.000002B7E1B16000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995447387.000002B7E1E20000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984497184.000002B7E19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1993868079.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1998075840.000002B7E2AB0000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995911731.000002B7E2130000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964763529.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://curl.haxx.se/rfc/cookie_spec.html
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998075840.000002B7E2AB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/3/library/subprocess#subprocess.Popen.kill
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998075840.000002B7E2AB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/3/library/subprocess#subprocess.Popen.returncode
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998075840.000002B7E2AB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/3/library/subprocess#subprocess.Popen.terminate
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/library/itertools.html#recipes
        Source: ROh2ijuEpr.exe, 00000003.00000003.1970834515.000002B7E1344000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965489833.000002B7E133C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1992285422.000002B7E1345000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/library/unittest.html
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995625869.000002B7E2030000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://foo/bar.tar.gz
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995625869.000002B7E2030000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://foo/bar.tgz
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998471018.000002B7E2DF0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://goo.gl/zeJZl.
        Source: ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://google.com/
        Source: ROh2ijuEpr.exe, 00000003.00000003.1973295666.000002B7E1AB2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://google.com/mail/
        Source: ROh2ijuEpr.exe, 00000003.00000003.1961986642.000002B7E1890000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965240050.000002B7E18A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972469095.000002B7E1751000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1993843529.000002B7E18A5000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980835556.000002B7E18A5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://mail.python.org/pipermail/python-dev/2012-June/120787.html.
        Source: ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.es
        Source: ROh2ijuEpr.exe, 00000003.00000003.1971740530.000002B7E2662000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.es0
        Source: ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.esY
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0A
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0C
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0N
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0O
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0X
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://opensource.apple.com/source/CF/CF-744.18/CFBinaryPList.c
        Source: ROh2ijuEpr.exe, 00000003.00000003.1987117257.000002B7E1A7E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://repository.swisssign.com/
        Source: ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1988247304.000002B7E1951000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965542566.000002B7E1909000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972928675.000002B7E190D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964763529.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980470769.000002B7E1910000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://repository.swisssign.com/G
        Source: ROh2ijuEpr.exe, 00000003.00000003.1970738904.000002B7E2689000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983111729.000002B7E2833000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971416873.000002B7E26A1000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971351400.000002B7E281B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1997000563.000002B7E26A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970433771.000002B7E2814000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1997956989.000002B7E2836000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972520297.000002B7E2829000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970767511.000002B7E26A0000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://tip.tcl.tk/48)
        Source: ROh2ijuEpr.exe, 00000003.00000003.1966373385.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982101411.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963385669.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1996364834.000002B7E2313000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986984522.000002B7E17A5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc4880
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc5297
        Source: ROh2ijuEpr.exe, 00000003.00000003.1972994990.000002B7E1B0D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969913757.000002B7E1B0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc5869
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc6125#section-6.4.3
        Source: ROh2ijuEpr.exe, 00000003.00000003.1989727599.000002B7E1A98000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1981715302.000002B7E1A92000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://web.cs.ucdavis.edu/~rogaway/ocb/license.htm
        Source: ROh2ijuEpr.exe, 00000003.00000003.1971740530.000002B7E2662000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0
        Source: ROh2ijuEpr.exe, 00000003.00000002.1996901968.000002B7E2619000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989356574.000002B7E2610000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984445540.000002B7E260B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl
        Source: ROh2ijuEpr.exe, 00000003.00000003.1971740530.000002B7E2662000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl0
        Source: ROh2ijuEpr.exe, 00000003.00000002.1996901968.000002B7E2619000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989356574.000002B7E2610000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984445540.000002B7E260B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crlH
        Source: ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/legislacion_c.htm
        Source: ROh2ijuEpr.exe, 00000003.00000003.1971740530.000002B7E2662000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/legislacion_c.htm0U
        Source: ROh2ijuEpr.exe, 00000003.00000003.1971740530.000002B7E2662000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es00
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
        Source: ROh2ijuEpr.exe, 00000003.00000003.1978167770.000002B7E1AA7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971740530.000002B7E2662000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982197645.000002B7E1AA8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983165935.000002B7E1AA8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986201293.000002B7E1AA9000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cert.fnmt.es/dpcs/
        Source: ROh2ijuEpr.exe, 00000003.00000003.1978167770.000002B7E1AA7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982197645.000002B7E1AA8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983165935.000002B7E1AA8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986201293.000002B7E1AA9000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cert.fnmt.es/dpcs/U
        Source: ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983540772.000002B7E1805000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1978447243.000002B7E1801000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963747551.000002B7E1B15000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971797186.000002B7E17FD000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cs.ucdavis.edu/~rogaway/papers/keywrap.pdf
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1854511612.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.digicert.com/CPS0
        Source: ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989081522.000002B7E2436000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1985234977.000002B7E1A6B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1985170894.000002B7E1A67000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982809276.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.firmaprofesional.com/cps0
        Source: ROh2ijuEpr.exe, 00000003.00000003.1983063984.000002B7E1959000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965542566.000002B7E1909000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972928675.000002B7E190D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964763529.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980470769.000002B7E1910000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iana.org/assignments/tls-parameters/tls-parameters.xml#tls-parameters-6
        Source: ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.quovadisglobal.com/cps
        Source: ROh2ijuEpr.exe, 00000003.00000003.1982631016.000002B7E2629000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1996926483.000002B7E2629000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969284404.000002B7E2625000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.quovadisglobal.com/cps0
        Source: ROh2ijuEpr.exe, 00000003.00000003.1989727599.000002B7E1A98000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1981715302.000002B7E1A92000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.rfc-editor.org/info/rfc7253
        Source: ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963747551.000002B7E1B15000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.tarsnap.com/scrypt/scrypt-slides.pdf
        Source: ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986394488.000002B7E249D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964512632.000002B7E2492000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://wwwsearch.sf.net/):
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot7838135800:AAF1s9LMwxii51PKljb116HEHDYvhMwpOrI/sendPhoto
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995447387.000002B7E1E20000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://bugs.python.org/issue44497.
        Source: ROh2ijuEpr.exe, 00000003.00000003.1964931483.000002B7E135E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982437571.000002B7E135E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963695833.000002B7E1354000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1894089672.000002B7E1330000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963723315.000002B7E135D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3.11/library/binascii.html#binascii.a2b_base64
        Source: ROh2ijuEpr.exe, 00000003.00000003.1883616682.000002B7E1332000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1991980145.000002B7E1220000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1883585380.000002B7E10D2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/howto/mro.html.
        Source: ROh2ijuEpr.exe, 00000003.00000003.1965346314.000002B7E102C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D10000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1991465206.000002B7E102F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1885309318.000002B7E1013000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.ExecutionLoader.get_filename
        Source: ROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D10000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.InspectLoader.get_code
        Source: ROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D94000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.InspectLoader.get_source
        Source: ROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D10000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.InspectLoader.is_package
        Source: ROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D94000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.Loader.create_module
        Source: ROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D10000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.Loader.exec_module
        Source: ROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D10000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.MetaPathFinder.invalidate_caches
        Source: ROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D10000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.PathEntryFinder.find_spec
        Source: ROh2ijuEpr.exe, 00000003.00000003.1965827967.000002B7DF44B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987678052.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1990770516.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962794102.000002B7DF426000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967554589.000002B7DF464000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.ResourceLoader.get_data
        Source: ROh2ijuEpr.exe, 00000003.00000003.1972469095.000002B7E1758000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980077773.000002B7E1760000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1993388559.000002B7E1774000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983810629.000002B7E1774000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/multiprocessing.html
        Source: ROh2ijuEpr.exe, 00000003.00000003.1969612912.000002B7E287F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962927092.000002B7E287B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961461803.000002B7E2861000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://exiv2.org/tags.html)
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://foss.heptapod.net/pypy/pypy/-/issues/3539
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995358637.000002B7E1D20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/BLAKE3-team/BLAKE3).
        Source: ROh2ijuEpr.exe, 00000003.00000003.1965827967.000002B7DF44B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987678052.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1990770516.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967420787.000002B7E1009000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962794102.000002B7DF426000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967554589.000002B7DF464000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/Unidata/MetPy/blob/a3424de66a44bf3a92b0dcacf4dff82ad7b86712/src/metpy/plots/wx_sy
        Source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E3908000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/asweigart/pyperclip/issues/55
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/giampaolo/psutil/issues/875.
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995625869.000002B7E2030000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/jaraco/jaraco.functools/issues/5
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/mhammond/pywin32
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/platformdirs/platformdirs
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998756767.000002B7E30E0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/psf/requests/pull/6710
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/packaging
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995358637.000002B7E1D20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/issues/1024.
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995447387.000002B7E1E20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/issues/417#issuecomment-392298401
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998907368.000002B7E3210000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/python-pillow/Pillow/
        Source: ROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D94000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/3.9/Lib/importlib/_bootstrap_external.py#L679-L688
        Source: ROh2ijuEpr.exe, 00000003.00000003.1967554589.000002B7DF464000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/abc.py
        Source: ROh2ijuEpr.exe, 00000003.00000003.1965827967.000002B7DF44B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987678052.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1990770516.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967420787.000002B7E1009000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962794102.000002B7DF426000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967554589.000002B7DF464000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/reader
        Source: ROh2ijuEpr.exe, 00000003.00000003.1965612784.000002B7E13A9000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1979936664.000002B7E13AC000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1886669982.000002B7E1760000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887260868.000002B7E13A6000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1889308781.000002B7E13A6000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962549508.000002B7E139E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1894089672.000002B7E1330000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1886522951.000002B7E1760000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987360757.000002B7E13AC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/issues/86361.
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995447387.000002B7E1E20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/importlib_metadata/issues/396
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/importlib_metadata/wiki/Development-Methodology
        Source: ROh2ijuEpr.exe, 00000003.00000003.1965827967.000002B7DF44B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987678052.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1990770516.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967420787.000002B7E1009000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962794102.000002B7DF426000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967554589.000002B7DF464000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/tensorflow/datasets/blob/master/tensorflow_datasets/core/utils/resource_utils.py#
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2192#issuecomment-821832963
        Source: ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2513#issuecomment-1152559900.
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2920
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2920p
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/3290
        Source: ROh2ijuEpr.exe, 00000003.00000002.1994772474.000002B7E1A02000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984497184.000002B7E19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971797186.000002B7E17FD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://google.com/
        Source: ROh2ijuEpr.exe, 00000003.00000002.1994772474.000002B7E1A02000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984497184.000002B7E19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971797186.000002B7E17FD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://google.com/mail
        Source: ROh2ijuEpr.exe, 00000003.00000003.1971797186.000002B7E17FD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://google.com/mail/
        Source: ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982809276.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://html.spec.whatwg.org/multipage/
        Source: ROh2ijuEpr.exe, 00000003.00000003.1984445540.000002B7E25FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/get
        Source: ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980911449.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1973295666.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983140161.000002B7E1ADA000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987147803.000002B7E1ADD000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/post
        Source: ROh2ijuEpr.exe, 00000003.00000003.1964763529.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://json.org
        Source: ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E177D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://mahler:8092/site-updates.py
        Source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E3950000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://mouseinfo.readthedocs.io
        Source: ROh2ijuEpr.exe, 00000003.00000003.1983063984.000002B7E1959000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1994469871.000002B7E195D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965542566.000002B7E1909000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972928675.000002B7E190D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964763529.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980470769.000002B7E1910000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995625869.000002B7E2030000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/guides/packaging-namespace-packages/.
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995911731.000002B7E2130000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/core-metadata/
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995358637.000002B7E1D20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/core-metadata/#core-metadata
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/entry-points/
        Source: ROh2ijuEpr.exe, 00000003.00000003.1967420787.000002B7E1009000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983014111.000002B7E1025000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/entry-points/#file-format
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/entry-points/0
        Source: ROh2ijuEpr.exe, 00000003.00000002.1994646832.000002B7E19AF000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1985867788.000002B7E19AB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/pyproject-toml/#declaring-project-metadata-the
        Source: ROh2ijuEpr.exe, 00000003.00000003.1967420787.000002B7E1009000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983014111.000002B7E1025000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/recording-installed-packages/#the-record-file
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995447387.000002B7E1E20000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995358637.000002B7E1D20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/specifications/entry-points/
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://paste.debian.net/plainh/724e4d05
        Source: ROh2ijuEpr.exe, 00000003.00000002.1993189298.000002B7E1620000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1885309318.000002B7E1013000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1881214977.000002B7E0FE1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://peps.python.org/pep-0205/
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995911731.000002B7E2130000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://peps.python.org/pep-0685/
        Source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38D8000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pyperclip.readthedocs.io/en/latest/index.html#not-implemented-error
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995625869.000002B7E2030000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/build/).
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://refspecs.linuxfoundation.org/elf/gabi4
        Source: ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980911449.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1973295666.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983140161.000002B7E1ADA000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987147803.000002B7E1ADD000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1998756767.000002B7E30E0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://requests.readthedocs.io
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998756767.000002B7E30E0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://requests.readthedocs.ioe
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995625869.000002B7E2030000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/
        Source: ROh2ijuEpr.exe, 00000003.00000003.1887998418.000002B7E14D1000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888715932.000002B7E1788000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888238760.000002B7E1787000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887918020.000002B7E1787000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/pkg_resources.html
        Source: ROh2ijuEpr.exe, 00000003.00000003.1890212392.000002B7E14D1000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888281347.000002B7E14D1000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888715932.000002B7E1788000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1892756590.000002B7E1457000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888238760.000002B7E1787000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887918020.000002B7E1787000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887998418.000002B7E141E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962186012.000002B7E14F6000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1889308781.000002B7E14D1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/pkg_resources.html#basic-resource-access
        Source: ROh2ijuEpr.exe, 00000003.00000002.1993189298.000002B7E1620000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packages
        Source: ROh2ijuEpr.exe, 00000003.00000002.1993189298.000002B7E1620000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packages0
        Source: ROh2ijuEpr.exe, 00000003.00000003.1888715932.000002B7E1788000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888238760.000002B7E1787000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887918020.000002B7E1787000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packagesr&
        Source: ROh2ijuEpr.exe, 00000003.00000003.1888715932.000002B7E1788000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888238760.000002B7E1787000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887918020.000002B7E1787000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packagesr&r
        Source: ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38D8000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983318461.000002B7E2808000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1997930385.000002B7E280B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984587900.000002B7E2808000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/questions/18905702/python-ctypes-and-mutable-buffers
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/questions/4457745#4457745.
        Source: ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38D8000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983318461.000002B7E2808000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1997930385.000002B7E280B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984587900.000002B7E2808000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/questions/455434/how-should-i-use-formatmessage-properly-in-c
        Source: ROh2ijuEpr.exe, 00000003.00000003.1973072375.000002B7E17D7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984339278.000002B7E17DB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987867864.000002B7E17DB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982784444.000002B7E17D7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc2388#section-4.4
        Source: ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963080661.000002B7E1B1D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966679097.000002B7E1B1E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc3610
        Source: ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983540772.000002B7E1805000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1978447243.000002B7E1801000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963747551.000002B7E1B15000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971797186.000002B7E17FD000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc5297
        Source: ROh2ijuEpr.exe, 00000003.00000003.1966373385.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982101411.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989081522.000002B7E2436000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963385669.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986984522.000002B7E17A5000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982809276.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc7231#section-4.3.6)
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995447387.000002B7E1E20000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://upload.pypi.org/legacy/
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#https-proxy-error-http-proxy
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#tls-warnings
        Source: ROh2ijuEpr.exe, 00000003.00000003.1969612912.000002B7E287F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962927092.000002B7E287B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961461803.000002B7E2861000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.archive.org/web/20120328125543/http://www.jpegcameras.com/libjpeg/libjpeg-3.html
        Source: ROh2ijuEpr.exe, 00000003.00000003.1967086024.000002B7E136E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964931483.000002B7E135E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1891883791.000002B7E1869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1890950701.000002B7E1869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1890950701.000002B7E1812000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963695833.000002B7E1354000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1894089672.000002B7E1330000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963723315.000002B7E135D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www-cs-faculty.stanford.edu/~knuth/fasc2a.ps.gz
        Source: ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.apache.org/licenses/LICENSE-2.0
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1769082596.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1766519044.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.digicert.com/CPS0
        Source: ROh2ijuEpr.exe, 00000003.00000003.1981569341.000002B7E195E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965542566.000002B7E1909000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972928675.000002B7E190D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1994520128.000002B7E1966000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986060804.000002B7E1963000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964763529.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980470769.000002B7E1910000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ietf.org/rfc/rfc2898.txt
        Source: ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.2003021149.00007FFDFAE94000.00000002.00000001.01000000.00000019.sdmp, ROh2ijuEpr.exe, 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: https://www.openssl.org/H
        Source: ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980911449.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1973295666.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983140161.000002B7E1ADA000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org
        Source: ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E177D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/
        Source: ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1981715302.000002B7E1A92000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.rfc-editor.org/rfc/rfc8259#section-8.1
        Source: ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wwww.certigna.fr/autorites/
        Source: ROh2ijuEpr.exe, 00000003.00000002.1996828712.000002B7E25FB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wwww.certigna.fr/autorites/0m
        Source: ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xmpp.org/getting-started/
        Source: ROh2ijuEpr.exe, 00000003.00000002.1994772474.000002B7E1A02000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984497184.000002B7E19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971797186.000002B7E17FD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://yahoo.com/
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
        Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
        Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA2E79A0 ClientToScreen,GetSystemMetrics,GetAsyncKeyState,GetAsyncKeyState,TrackPopupMenu,GetCursorPos,WindowFromPoint,3_2_00007FFDFA2E79A0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA2EBA40 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,3_2_00007FFDFA2EBA40

        Spam, unwanted Advertisements and Ransom Demands

        barindex
        Source: Yara matchFile source: Process Memory Space: ROh2ijuEpr.exe PID: 6436, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: ROh2ijuEpr.exe PID: 6436, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: ROh2ijuEpr.exe PID: 6436, type: MEMORYSTR
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: cmd /c vssadmin delete shadows /all /quiet
        Source: ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: dURcmd /c vssadmin delete shadows /all /quiet g
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA7BD40_2_00007FF762AA7BD4
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A8989B0_2_00007FF762A8989B
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A880200_2_00007FF762A88020
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA6E700_2_00007FF762AA6E70
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA1B380_2_00007FF762AA1B38
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A9132C0_2_00007FF762A9132C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A9EB240_2_00007FF762A9EB24
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA531C0_2_00007FF762AA531C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A93B880_2_00007FF762A93B88
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A96CF00_2_00007FF762A96CF0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A944500_2_00007FF762A94450
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A924200_2_00007FF762A92420
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AAA9980_2_00007FF762AAA998
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A911280_2_00007FF762A91128
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA2AE40_2_00007FF762AA2AE4
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A89A340_2_00007FF762A89A34
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A8A26D0_2_00007FF762A8A26D
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A9EFB80_2_00007FF762A9EFB8
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A927B80_2_00007FF762A927B8
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A937500_2_00007FF762A93750
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A9173C0_2_00007FF762A9173C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A90F1C0_2_00007FF762A90F1C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A93F8C0_2_00007FF762A93F8C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA70EC0_2_00007FF762AA70EC
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A990200_2_00007FF762A99020
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A88DC00_2_00007FF762A88DC0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A915380_2_00007FF762A91538
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A90D180_2_00007FF762A90D18
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A996D00_2_00007FF762A996D0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A9F6380_2_00007FF762A9F638
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A9AE200_2_00007FF762A9AE20
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA1B380_2_00007FF762AA1B38
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA76880_2_00007FF762AA7688
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA4E800_2_00007FF762AA4E80
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_701851603_2_70185160
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_701866443_2_70186644
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_701D80603_2_701D8060
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_701D91053_2_701D9105
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_701A61303_2_701A6130
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_701AB1703_2_701AB170
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_701961803_2_70196180
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_701A21B03_2_701A21B0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762AA7BD43_2_00007FF762AA7BD4
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A93F8C3_2_00007FF762A93F8C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762AA1B383_2_00007FF762AA1B38
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A9132C3_2_00007FF762A9132C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A9EB243_2_00007FF762A9EB24
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762AA531C3_2_00007FF762AA531C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A93B883_2_00007FF762A93B88
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A96CF03_2_00007FF762A96CF0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A944503_2_00007FF762A94450
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A924203_2_00007FF762A92420
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762AAA9983_2_00007FF762AAA998
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A911283_2_00007FF762A91128
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762AA2AE43_2_00007FF762AA2AE4
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A89A343_2_00007FF762A89A34
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A8A26D3_2_00007FF762A8A26D
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A9EFB83_2_00007FF762A9EFB8
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A927B83_2_00007FF762A927B8
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A937503_2_00007FF762A93750
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A9173C3_2_00007FF762A9173C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A90F1C3_2_00007FF762A90F1C
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA38FAA03_2_00007FFDFA38FAA0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA2DDA603_2_00007FFDFA2DDA60
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA38DA703_2_00007FFDFA38DA70
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA351B003_2_00007FFDFA351B00
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA2F79603_2_00007FFDFA2F7960
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA2E5A103_2_00007FFDFA2E5A10
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA355A303_2_00007FFDFA355A30
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D1D933_2_00007FFDFA8D1D93
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D87203_2_00007FFDFA8D8720
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D116D3_2_00007FFDFA8D116D
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA8D16FE3_2_00007FFDFA8D16FE
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: String function: 7019EC80 appears 107 times
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: String function: 00007FFDFA8D1325 appears 86 times
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: String function: 00007FF762A81E50 appears 93 times
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: String function: 00007FFDFA94D341 appears 227 times
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: String function: 00007FFDFA94D32F appears 80 times
        Source: unicodedata.pyd.0.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
        Source: pyarmor_runtime.pyd.0.drStatic PE information: Number of sections : 11 > 10
        Source: zlib1.dll.0.drStatic PE information: Number of sections : 12 > 10
        Source: libscipy_openblas64_-c16e4918366c6bc1f1cd71e28ca36fc0.dll.0.drStatic PE information: Number of sections : 11 > 10
        Source: python3.dll.0.drStatic PE information: No import functions for PE file found
        Source: ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamewin32pdh.pyd0 vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1859702920.00000277A1A34000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelibsslH vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1802500436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dllT vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_bz2.pyd. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1768451654.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameQt5WebSockets.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1781305385.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqjpeg.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqicns.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqsvgicon.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqwbmp.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1787664962.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqwebgl.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1764002342.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameQt5Network.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelibEGL.dll. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1762324734.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameQt5Gui.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1759663363.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140_1.dllT vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1789348776.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqwindowsvistastyle.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameselect.pyd. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1765841777.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameQt5QmlModels.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1788587783.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqwindows.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1803095096.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_ctypes.pyd. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqgif.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1787309391.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqoffscreen.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1802644329.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140_1.dllT vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamewin32pdh.pyd0 vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqxdgdesktopportal.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1803224122.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_decimal.pyd. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1761561663.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameQt5DBus.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1764733384.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameQt5Qml.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqsvg.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1770778003.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140_1.dllT vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqtuiotouchplugin.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1786985890.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqminimal.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_lzma.pyd. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1783973276.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqtga.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1786304769.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqwebp.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_elementtree.pyd. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1772636842.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelibGLESv2.dll4 vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_hashlib.pyd. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1781128700.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqico.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1760235944.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameQt5Core.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1785081732.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameqtiff.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamepywintypes313.dll0 vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1767657541.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameQt5Svg.dll( vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1759367074.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140.dllT vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_asyncio.pyd. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000000.00000003.1770542971.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dllT vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exeBinary or memory string: OriginalFilename vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000003.00000002.2003021149.00007FFDFAE94000.00000002.00000001.01000000.00000019.sdmpBinary or memory string: OriginalFilenamelibcryptoH vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpBinary or memory string: OriginalFilenamelibsslH vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000003.00000002.2001871335.00007FFDFA8CC000.00000002.00000001.01000000.00000033.sdmpBinary or memory string: OriginalFilenameunicodedata.pyd. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000003.00000002.2001614579.00007FFDFA80D000.00000002.00000001.01000000.00000035.sdmpBinary or memory string: OriginalFilenametcl86.dll. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000003.00000002.1991032882.000002B7E0E20000.00000002.00000001.01000000.00000007.sdmpBinary or memory string: OriginalFilenamepython3.dll. vs ROh2ijuEpr.exe
        Source: ROh2ijuEpr.exe, 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpBinary or memory string: OriginalFilenametk86.dll. vs ROh2ijuEpr.exe
        Source: classification engineClassification label: mal76.rans.troj.winEXE@4/1026@1/1
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Roaming\.LOGJump to behavior
        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2916:120:WilError_03
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842Jump to behavior
        Source: ROh2ijuEpr.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT Architecture FROM Win32_Processor
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
        Source: ROh2ijuEpr.exeString found in binary or memory: -help
        Source: ROh2ijuEpr.exeString found in binary or memory: -startline must be less than or equal to -endline
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile read: C:\Users\user\Desktop\ROh2ijuEpr.exeJump to behavior
        Source: unknownProcess created: C:\Users\user\Desktop\ROh2ijuEpr.exe "C:\Users\user\Desktop\ROh2ijuEpr.exe"
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeProcess created: C:\Users\user\Desktop\ROh2ijuEpr.exe "C:\Users\user\Desktop\ROh2ijuEpr.exe"
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeProcess created: C:\Users\user\Desktop\ROh2ijuEpr.exe "C:\Users\user\Desktop\ROh2ijuEpr.exe"Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: version.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: vcruntime140.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: libffi-8.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: propsys.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: vcruntime140_1.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: qt5core.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: userenv.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: netapi32.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: winmm.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: msvcp140.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: msvcp140_1.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: iphlpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: wbemcomn.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: amsi.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: wbemcomn.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: libcrypto-3.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: libssl-3.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: mswsock.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: powrprof.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: pdh.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: umpdc.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: wtsapi32.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: tcl86t.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: tk86t.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: zlib1.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: logoncli.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: samcli.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: dnsapi.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: rasadhlp.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeSection loaded: fwpuclnt.dllJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32Jump to behavior
        Source: ROh2ijuEpr.exeStatic PE information: Image base 0x140000000 > 0x60000000
        Source: ROh2ijuEpr.exeStatic file information: File size 63538768 > 1048576
        Source: ROh2ijuEpr.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
        Source: ROh2ijuEpr.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
        Source: ROh2ijuEpr.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
        Source: ROh2ijuEpr.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
        Source: ROh2ijuEpr.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
        Source: ROh2ijuEpr.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
        Source: ROh2ijuEpr.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
        Source: ROh2ijuEpr.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
        Source: Binary string: C:\Users\qt\work\qt\qtsvg\plugins\iconengines\qsvgicon.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1780469877.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtsvg\plugins\imageformats\qsvg.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1783692436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: The standard debugger class (pdb.Pdb) is an example. source: ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1998907368.000002B7E3210000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971351400.000002B7E281B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1976706420.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970433771.000002B7E2814000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980724033.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983571863.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\generic\qtuiotouchplugin.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1781128700.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: @ compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG"OpenSSL 3.0.15 3 Sep 20243.0.15built on: Wed Sep 4 15:52:04 2024 UTCplatform: VC-WIN64A-masmOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "C:\Program Files\OpenSSL\lib\engines-3"MODULESDIR: "C:\Program Files\OpenSSL\lib\ossl-modules"CPUINFO: N/Anot availableget_and_lock..\s\crypto\ex_data.cossl_crypto_get_ex_new_index_exossl_crypto_new_ex_data_exCRYPTO_dup_ex_dataCRYPTO_set_ex_dataOPENSSL_WIN32_UTF8..\s\crypto\getenv.ccompiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG";CPUINFO: OPENSSL_ia32cap=0x%llx:0x%llxOPENSSL_ia32cap env:%sos-specificC:\Program Files\Common Files\SSLC:\Program Files\OpenSSL\lib\ossl-modules.dllCPUINFO: ..\s\crypto\init.cOPENSSL_init_cryptoOPENSSL_atexit..\s\crypto\initthread.c..\s\crypto\mem_sec.cassertion failed: (bit & 1) == 0assertion failed: list >= 0 && list < sh.freelist_sizeassertion failed: ((ptr - sh.arena) & ((sh.arena_size >> list) - 1)) == 0assertion failed: bit > 0 && bit < sh.bittable_sizeassertion failed: TESTBIT(table, bit)assertion failed: !TESTBIT(table, bit)assertion failed: WITHIN_FREELIST(list)assertion failed: WITHIN_ARENA(ptr)assertion failed: temp->next == NULL || WITHIN_ARENA(temp->next)assertion failed: (char **)temp->next->p_next == listassertion failed: WITHIN_FREELIST(temp2->p_next) || WITHIN_ARENA(temp2->p_next)assertion failed: size > 0assertion failed: (size & (size - 1)) == 0assertion failed: (minsize & (minsize - 1)) == 0assertion failed: sh.freelist != NULLassertion failed: sh.bittable != NULLassertion failed: sh.bitmalloc != NULLassertion failed: !sh_testbit(temp, slist, sh.bitmalloc)assertion failed: temp != sh.freelist[slist]assertion failed: sh.freelist[slist] == tempassertion failed: temp-(sh.arena_size >> slist) == sh_find_my_buddy(temp, slist)assertion failed: sh_testbit(chunk, list, sh.bittable)assertion failed: WITHIN_ARENA(chunk)assertion failed: sh_testbit(ptr, list, sh.bittable)assertion failed: ptr == sh_find_my_buddy(buddy, list)assertion failed: ptr != NULLassertion failed: !sh_testbit(ptr, list, sh.bitmalloc)assertion failed: sh.freelist[list] == ptr/*0123456789ABCDEFCRYPTO_memdup..\s\crypto\o_str.chexstr2buf_sepossl_hexstr2buf_sepbuf2hexstr_sepossl_buf2hexstr_sep..\s\crypto\packet.cwpacket_intern_init_lenWPACKET_start_sub_packet_len__..\s\crypto\param_build.cparam_pushparam_push_numOSSL_PARAM_BLD_push_BN_padNegative big numbers are unsupported for OSSL_PARAMOSSL_PARAM_BLD_push_utf8_stringOSSL_PARAM_BLD_push_utf8_ptrOSSL_PARAM_BLD_push_octet_stringOSSL_PARAM_BLD_p
        Source: Binary string: ~/.pdbrc source: ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989081522.000002B7E2436000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970789616.000002B7E2869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1988982211.000002B7E286A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961461803.000002B7E2861000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982809276.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: dpdb commands to execute as if given in a .pdbrc file0m source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG" source: ROh2ijuEpr.exe, 00000003.00000002.2002708965.00007FFDFAD52000.00000002.00000001.01000000.00000019.sdmp
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: ROh2ijuEpr.exe, 00000000.00000003.1802500436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: pdb.Pdb source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: d:\agent\_work\1\s\\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1770778003.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: If a file ".pdbrc" exists in your home directory or in the current source: ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983318461.000002B7E2808000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984587900.000002B7E2808000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1802644329.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: dpdb.Pdb` source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_hashlib.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1803480374.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1781128700.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_asyncio.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\generic\qtuiotouchplugin.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1780030600.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdbT source: ROh2ijuEpr.exe, 00000003.00000002.2003359614.00007FFDFB326000.00000002.00000001.01000000.00000011.sdmp
        Source: Binary string: placed in the .pdbrc file): source: ROh2ijuEpr.exe, 00000003.00000003.1984497184.000002B7E19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983318461.000002B7E2808000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1997930385.000002B7E280B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984587900.000002B7E2808000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_bz2.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1802840487.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdbGCTL source: ROh2ijuEpr.exe, 00000000.00000003.1802644329.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: d:\agent\_work\1\s\\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1770542971.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: pdb.Pdbr source: ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989081522.000002B7E2436000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970789616.000002B7E2869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1988982211.000002B7E286A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961461803.000002B7E2861000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982809276.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdbBB source: ROh2ijuEpr.exe, 00000000.00000003.1785081732.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\platformthemes\qxdgdesktopportal.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1789133780.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\unicodedata.pdb source: ROh2ijuEpr.exe, 00000003.00000002.2001701186.00007FFDFA8C7000.00000002.00000001.01000000.00000033.sdmp
        Source: Binary string: d:\agent\_work\1\s\\binaries\amd64ret\bin\amd64\\msvcp140_1.amd64.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1759663363.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_elementtree.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1803365518.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdb source: ROh2ijuEpr.exe, 00000003.00000002.2003359614.00007FFDFB326000.00000002.00000001.01000000.00000011.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1785081732.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qgif.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1780670955.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: d.pdbrc source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtga.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1783973276.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1802500436.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: -c are executed after commands from .pdbrc files. source: ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971351400.000002B7E281B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1976706420.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970433771.000002B7E2814000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980724033.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983571863.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qicns.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1780873499.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: pdb commands to execute as if given in a .pdbrc file source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\select.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1875174756.00000277A1A34000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: Initial commands are read from .pdbrc files in your home directory source: ROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971351400.000002B7E281B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1976706420.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970433771.000002B7E2814000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980724033.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983571863.000002B7E281C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: .pdbrc source: ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989081522.000002B7E2436000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1970789616.000002B7E2869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1988982211.000002B7E286A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961461803.000002B7E2861000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982809276.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdbNN source: ROh2ijuEpr.exe, 00000000.00000003.1803588959.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: d~/.pdbrc source: ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38B0000.00000004.00001000.00020000.00000000.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qwbmp.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1786151123.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\1\b\bin\amd64\python3.pdb source: ROh2ijuEpr.exe, 00000003.00000002.1991032882.000002B7E0E20000.00000002.00000001.01000000.00000007.sdmp
        Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\libEGL.pdb source: ROh2ijuEpr.exe, 00000000.00000003.1772267367.00000277A1A10000.00000004.00000020.00020000.00000000.sdmp
        Source: ROh2ijuEpr.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
        Source: ROh2ijuEpr.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
        Source: ROh2ijuEpr.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
        Source: ROh2ijuEpr.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
        Source: ROh2ijuEpr.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
        Source: msvcp140-d64049c6e3865410a7dda6a7e9f0c575.dll.0.drStatic PE information: 0xB3DF2F63 [Mon Aug 17 15:25:23 2065 UTC]
        Source: _MD5.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xa544
        Source: pyarmor_runtime.pyd.0.drStatic PE information: real checksum: 0xa26a7 should be: 0xa3662
        Source: _chacha20.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x351a
        Source: _SHA1.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xf079
        Source: _scrypt.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x4714
        Source: _raw_blowfish.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xe4b7
        Source: _pkcs1_decode.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x10c34
        Source: blake3.cp313-win_amd64.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x8e32f
        Source: _curve448.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x1a70d
        Source: _raw_cbc.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x5ba2
        Source: _MD2.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xeba3
        Source: _raw_arc2.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x13220
        Source: _raw_cast.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xc443
        Source: _raw_ctr.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xdcf9
        Source: _modexp.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x172cd
        Source: _ghash_clmul.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xac61
        Source: _Salsa20.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xb9f9
        Source: _RIPEMD160.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x69e1
        Source: _SHA384.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x1655d
        Source: _BLAKE2s.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x5f6b
        Source: _poly1305.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xbf54
        Source: _SHA224.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x1037a
        Source: _raw_aes.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xbec9
        Source: win32pdh.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xf0c9
        Source: _raw_ecb.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x4671
        Source: pywintypes313.dll.0.drStatic PE information: real checksum: 0x0 should be: 0x21b11
        Source: _BLAKE2b.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x120c3
        Source: _raw_aesni.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x646e
        Source: _raw_ocb.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x11289
        Source: _ed448.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x1eae6
        Source: md__mypyc.cp313-win_amd64.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x1ee46
        Source: _raw_cfb.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xed0d
        Source: _raw_des.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x13f62
        Source: _curve25519.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x1023e
        Source: _MD4.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x9e2d
        Source: _rust.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x77a3da
        Source: _raw_des3.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x1d746
        Source: _ed25519.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x10701
        Source: _raw_ofb.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x10ea2
        Source: _ec_ws.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xbf2b1
        Source: _keccak.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xdc9d
        Source: _ARC4.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x9b3a
        Source: _raw_eksblowfish.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xca96
        Source: _psutil_windows.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x1f645
        Source: _cffi.cp313-win_amd64.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xac6d6
        Source: _ghash_portable.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xe5b7
        Source: md.cp313-win_amd64.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x47a9
        Source: _SHA512.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0xdf25
        Source: backend_c.cp313-win_amd64.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x82076
        Source: _SHA256.pyd.0.drStatic PE information: real checksum: 0x0 should be: 0x6eb8
        Source: libscipy_openblas64_-c16e4918366c6bc1f1cd71e28ca36fc0.dll.0.drStatic PE information: section name: .xdata
        Source: libssl-3.dll.0.drStatic PE information: section name: .00cfg
        Source: libcrypto-3.dll.0.drStatic PE information: section name: .00cfg
        Source: python313.dll.0.drStatic PE information: section name: PyRuntim
        Source: zlib1.dll.0.drStatic PE information: section name: .xdata
        Source: pyarmor_runtime.pyd.0.drStatic PE information: section name: .xdata
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ecb.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\_core\_multiarray_tests.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\python313.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_generator.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_cfb.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_aes.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA384.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\linalg\_umath_linalg.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ocb.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy.libs\msvcp140-d64049c6e3865410a7dda6a7e9f0c575.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_sfc64.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_bounded_integers.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_cast.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA512.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_ed448.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\zlib1.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\mtrand.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\cryptography\hazmat\bindings\_rust.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\blake3\blake3.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_ghash_clmul.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_ec_ws.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_RIPEMD160.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_common.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ctr.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_ARC4.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_curve448.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_Salsa20.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_MD4.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\pyarmor_runtime_000000\pyarmor_runtime.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\unicodedata.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\tcl86t.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\pywin32_system32\pywintypes313.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_BLAKE2b.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_philox.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_poly1305.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA224.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\libcrypto-3.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\libssl-3.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_MD5.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\fft\_pocketfft_umath.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\charset_normalizer\md__mypyc.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\_wmi.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_blowfish.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\zstandard\backend_c.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Math\_modexp.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\pyexpat.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_chacha20.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\win32\win32pdh.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy.libs\libscipy_openblas64_-c16e4918366c6bc1f1cd71e28ca36fc0.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_ghash_portable.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_BLAKE2s.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\libffi-8.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\bit_generator.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ofb.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_ed25519.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_pcg64.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_aesni.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_des3.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_cbc.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Protocol\_scrypt.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\_tkinter.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA256.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_pkcs1_decode.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\zstandard\_cffi.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\select.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_arc2.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_keccak.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\psutil\_psutil_windows.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_des.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_mt19937.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\tk86t.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_eksblowfish.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_curve25519.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA1.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\_core\_multiarray_umath.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_MD2.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\charset_normalizer\md.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI36842\python3.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A84C40 GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,0_2_00007FF762A84C40
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA918816 sgdt fword ptr [rax]3_2_00007FFDFA918816
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ecb.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\_core\_multiarray_tests.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\python313.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_generator.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_cfb.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA384.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_aes.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\linalg\_umath_linalg.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ocb.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_sfc64.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy.libs\msvcp140-d64049c6e3865410a7dda6a7e9f0c575.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_cast.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_bounded_integers.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA512.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_ed448.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\mtrand.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\cryptography\hazmat\bindings\_rust.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_ghash_clmul.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\blake3\blake3.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_ec_ws.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_RIPEMD160.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ctr.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_common.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_ARC4.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_curve448.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_MD4.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_Salsa20.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\pyarmor_runtime_000000\pyarmor_runtime.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\unicodedata.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_BLAKE2b.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\pywin32_system32\pywintypes313.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_philox.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_poly1305.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA224.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_MD5.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\fft\_pocketfft_umath.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\charset_normalizer\md__mypyc.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_blowfish.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\_wmi.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\zstandard\backend_c.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Math\_modexp.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\pyexpat.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\win32\win32pdh.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_chacha20.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy.libs\libscipy_openblas64_-c16e4918366c6bc1f1cd71e28ca36fc0.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_ghash_portable.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_BLAKE2s.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ofb.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\bit_generator.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_ed25519.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_pcg64.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_aesni.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_des3.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_cbc.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Protocol\_scrypt.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\_tkinter.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA256.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_pkcs1_decode.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\zstandard\_cffi.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\select.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_arc2.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_keccak.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_des.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\psutil\_psutil_windows.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_mt19937.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_eksblowfish.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_curve25519.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA1.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\_core\_multiarray_umath.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_MD2.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\python3.dllJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI36842\charset_normalizer\md.cp313-win_amd64.pydJump to dropped file
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_0-18777
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeAPI coverage: 2.9 %
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT Architecture FROM Win32_Processor
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A87800 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,0_2_00007FF762A87800
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A88840 FindFirstFileExW,FindClose,0_2_00007FF762A88840
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA2AE4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF762AA2AE4
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A88840 FindFirstFileExW,FindClose,3_2_00007FF762A88840
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762AA2AE4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,3_2_00007FF762AA2AE4
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FF762A87800 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,3_2_00007FF762A87800
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\AppData\Local\Temp\Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\AppData\Local\Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI36842\Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\AppData\Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeFile opened: C:\Users\user\Jump to behavior
        Source: ROh2ijuEpr.exe, 00000000.00000003.1854485530.00000277A1A34000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: j2aTPs+9xYa9+bG3tD60B8jzljHz7aRP+KNOjSkVWLjVb3/ubCK1sK9IRQq9qEmU
        Source: ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1994382042.000002B7E18FA000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982050723.000002B7E18FA000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967312752.000002B7E18F9000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964763529.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllgY
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: ro.kernel.qemu
        Source: ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: dro.kernel.qemu
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A9B558 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF762A9B558
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA46F0 GetProcessHeap,0_2_00007FF762AA46F0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeProcess token adjusted: DebugJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeProcess token adjusted: DebugJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A8C8A0 SetUnhandledExceptionFilter,0_2_00007FF762A8C8A0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A9B558 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF762A9B558
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A8C6FC IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF762A8C6FC
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A8BE60 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF762A8BE60
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 3_2_00007FFDFA3CFB90 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,3_2_00007FFDFA3CFB90
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeProcess created: C:\Users\user\Desktop\ROh2ijuEpr.exe "C:\Users\user\Desktop\ROh2ijuEpr.exe"Jump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AAA7E0 cpuid 0_2_00007FF762AAA7E0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Util VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PIL VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PIL VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PIL VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PIL VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PIL VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\bin VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\bin VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\bin VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins\imageformats VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins\imageformats VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins\imageformats VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins\imageformats VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins\platforms VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins\platforms VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\plugins VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5\Qt5\translations VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\PyQt5 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\encoding VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\http1.0 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data\msgs VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_tcl_data VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\Desktop\ROh2ijuEpr.exe VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\Desktop\ROh2ijuEpr.exe VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\_ctypes.pyd VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\Desktop\ROh2ijuEpr.exe VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\Desktop\ROh2ijuEpr.exe VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\Desktop\ROh2ijuEpr.exe VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\Desktop\ROh2ijuEpr.exe VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842 VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI36842\base_library.zip VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762A8C5E0 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF762A8C5E0
        Source: C:\Users\user\Desktop\ROh2ijuEpr.exeCode function: 0_2_00007FF762AA6E70 _get_daylight,_get_daylight,_get_daylight,_get_daylight,_get_daylight,GetTimeZoneInformation,0_2_00007FF762AA6E70
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid Accounts11
        Windows Management Instrumentation
        1
        DLL Side-Loading
        11
        Process Injection
        1
        Masquerading
        21
        Input Capture
        2
        System Time Discovery
        Remote Services21
        Input Capture
        1
        Web Service
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault Accounts2
        Command and Scripting Interpreter
        Boot or Logon Initialization Scripts1
        DLL Side-Loading
        2
        Virtualization/Sandbox Evasion
        LSASS Memory31
        Security Software Discovery
        Remote Desktop Protocol1
        Archive Collected Data
        22
        Encrypted Channel
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain Accounts1
        Native API
        Logon Script (Windows)Logon Script (Windows)11
        Process Injection
        Security Account Manager2
        Virtualization/Sandbox Evasion
        SMB/Windows Admin SharesData from Network Shared Drive1
        Non-Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
        Deobfuscate/Decode Files or Information
        NTDS2
        File and Directory Discovery
        Distributed Component Object ModelInput Capture2
        Application Layer Protocol
        Traffic DuplicationData Destruction
        Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
        Obfuscated Files or Information
        LSA Secrets23
        System Information Discovery
        SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
        Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
        Timestomp
        Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
        DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
        DLL Side-Loading
        DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
        Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
        File Deletion
        Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        ROh2ijuEpr.exe3%ReversingLabsWin64.Malware.Generic
        SourceDetectionScannerLabelLink
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_ARC4.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_Salsa20.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_chacha20.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_pkcs1_decode.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_aes.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_aesni.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_arc2.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_blowfish.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_cast.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_cbc.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_cfb.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ctr.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_des.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_des3.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ecb.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_eksblowfish.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ocb.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_raw_ofb.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_BLAKE2b.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_BLAKE2s.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_MD2.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_MD4.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_MD5.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_RIPEMD160.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA1.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA224.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA256.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA384.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_SHA512.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_ghash_clmul.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_ghash_portable.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_keccak.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Hash\_poly1305.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Math\_modexp.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Protocol\_scrypt.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_curve25519.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_curve448.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_ec_ws.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_ed25519.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\PublicKey\_ed448.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\_tkinter.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\_wmi.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\blake3\blake3.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\charset_normalizer\md.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\charset_normalizer\md__mypyc.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\cryptography\hazmat\bindings\_rust.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\libcrypto-3.dll0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\libffi-8.dll0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\libssl-3.dll0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy.libs\libscipy_openblas64_-c16e4918366c6bc1f1cd71e28ca36fc0.dll0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy.libs\msvcp140-d64049c6e3865410a7dda6a7e9f0c575.dll0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\_core\_multiarray_tests.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\_core\_multiarray_umath.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\fft\_pocketfft_umath.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\linalg\_umath_linalg.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_bounded_integers.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_common.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_generator.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_mt19937.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_pcg64.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_philox.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\_sfc64.cp313-win_amd64.pyd0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\_MEI36842\numpy\random\bit_generator.cp313-win_amd64.pyd0%ReversingLabs
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://repository.swisssign.com/G0%Avira URL Cloudsafe
        http://cacerts.digX0%Avira URL Cloudsafe
        https://urllib3.readthedocs.io/en/latest/advanced-usage.html#https-proxy-error-http-proxy0%Avira URL Cloudsafe
        https://peps.python.org/pep-0205/0%Avira URL Cloudsafe
        https://xmpp.org/getting-started/0%Avira URL Cloudsafe
        http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l5350%Avira URL Cloudsafe
        https://exiv2.org/tags.html)0%Avira URL Cloudsafe
        https://mahler:8092/site-updates.py0%Avira URL Cloudsafe
        http://wwwsearch.sf.net/):0%Avira URL Cloudsafe
        https://paste.debian.net/plainh/724e4d050%Avira URL Cloudsafe
        NameIPActiveMaliciousAntivirus DetectionReputation
        api.telegram.org
        149.154.167.220
        truefalse
          high
          NameSourceMaliciousAntivirus DetectionReputation
          https://github.com/asweigart/pyperclip/issues/55ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E3908000.00000004.00001000.00020000.00000000.sdmpfalse
            high
            https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdfROh2ijuEpr.exe, 00000003.00000003.1983063984.000002B7E1959000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1994469871.000002B7E195D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965542566.000002B7E1909000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972928675.000002B7E190D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964763529.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980470769.000002B7E1910000.00000004.00000020.00020000.00000000.sdmpfalse
              high
              https://api.telegram.org/botROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpfalse
                high
                https://github.com/giampaolo/psutil/issues/875.ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpfalse
                  high
                  https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packagesROh2ijuEpr.exe, 00000003.00000002.1993189298.000002B7E1620000.00000004.00001000.00020000.00000000.sdmpfalse
                    high
                    http://aka.ms/vcpython27ROh2ijuEpr.exe, 00000003.00000002.1995911731.000002B7E2130000.00000004.00001000.00020000.00000000.sdmpfalse
                      high
                      http://repository.swisssign.com/GROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1988247304.000002B7E1951000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965542566.000002B7E1909000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972928675.000002B7E190D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964763529.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980470769.000002B7E1910000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://github.com/mhammond/pywin32ROh2ijuEpr.exe, 00000000.00000003.2008325450.00000277A19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000002.2008893669.00000277A1A0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        http://docs.python.org/library/unittest.htmlROh2ijuEpr.exe, 00000003.00000003.1970834515.000002B7E1344000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965489833.000002B7E133C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1992285422.000002B7E1345000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          https://setuptools.pypa.io/en/latest/ROh2ijuEpr.exe, 00000003.00000002.1995625869.000002B7E2030000.00000004.00001000.00020000.00000000.sdmpfalse
                            high
                            https://github.com/tensorflow/datasets/blob/master/tensorflow_datasets/core/utils/resource_utils.py#ROh2ijuEpr.exe, 00000003.00000003.1965827967.000002B7DF44B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987678052.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1990770516.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967420787.000002B7E1009000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962794102.000002B7DF426000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967554589.000002B7DF464000.00000004.00000020.00020000.00000000.sdmpfalse
                              high
                              https://packaging.python.org/en/latest/specifications/recording-installed-packages/#the-record-fileROh2ijuEpr.exe, 00000003.00000003.1967420787.000002B7E1009000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983014111.000002B7E1025000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                http://goo.gl/zeJZl.ROh2ijuEpr.exe, 00000003.00000002.1998471018.000002B7E2DF0000.00000004.00001000.00020000.00000000.sdmpfalse
                                  high
                                  https://tools.ietf.org/html/rfc2388#section-4.4ROh2ijuEpr.exe, 00000003.00000003.1973072375.000002B7E17D7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984339278.000002B7E17DB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987867864.000002B7E17DB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982784444.000002B7E17D7000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    https://www.apache.org/licenses/LICENSE-2.0ROh2ijuEpr.exe, 00000000.00000003.1859742462.00000277A1A13000.00000004.00000020.00020000.00000000.sdmpfalse
                                      high
                                      https://packaging.python.org/en/latest/specifications/core-metadata/ROh2ijuEpr.exe, 00000003.00000002.1995911731.000002B7E2130000.00000004.00001000.00020000.00000000.sdmpfalse
                                        high
                                        https://docs.python.org/3.11/library/binascii.html#binascii.a2b_base64ROh2ijuEpr.exe, 00000003.00000003.1964931483.000002B7E135E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982437571.000002B7E135E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963695833.000002B7E1354000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1894089672.000002B7E1330000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963723315.000002B7E135D000.00000004.00000020.00020000.00000000.sdmpfalse
                                          high
                                          https://github.com/pypa/packagingROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmpfalse
                                            high
                                            http://cacerts.digXROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://packaging.python.org/en/latest/specifications/entry-points/#file-formatROh2ijuEpr.exe, 00000003.00000003.1967420787.000002B7E1009000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983014111.000002B7E1025000.00000004.00000020.00020000.00000000.sdmpfalse
                                              high
                                              https://api.telegram.org/bot7838135800:AAF1s9LMwxii51PKljb116HEHDYvhMwpOrI/sendPhotoROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                high
                                                https://refspecs.linuxfoundation.org/elf/gabi4ROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpfalse
                                                  high
                                                  https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packages0ROh2ijuEpr.exe, 00000003.00000002.1993189298.000002B7E1620000.00000004.00001000.00020000.00000000.sdmpfalse
                                                    high
                                                    https://github.com/urllib3/urllib3/issues/2192#issuecomment-821832963ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                      high
                                                      http://docs.python.org/3/library/subprocess#subprocess.Popen.killROh2ijuEpr.exe, 00000003.00000002.1998075840.000002B7E2AB0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                        high
                                                        https://tools.ietf.org/html/rfc3610ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963080661.000002B7E1B1D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966679097.000002B7E1B1E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpfalse
                                                          high
                                                          https://github.com/platformdirs/platformdirsROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpfalse
                                                            high
                                                            https://peps.python.org/pep-0205/ROh2ijuEpr.exe, 00000003.00000002.1993189298.000002B7E1620000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1885309318.000002B7E1013000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1881214977.000002B7E0FE1000.00000004.00000020.00020000.00000000.sdmpfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            http://crl.dhimyotis.com/certignarootca.crlROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpfalse
                                                              high
                                                              http://curl.haxx.se/rfc/cookie_spec.htmlROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                high
                                                                http://ocsp.accv.esROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                  high
                                                                  http://docs.python.org/3/library/subprocess#subprocess.Popen.returncodeROh2ijuEpr.exe, 00000003.00000002.1998075840.000002B7E2AB0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                    high
                                                                    https://stackoverflow.com/questions/455434/how-should-i-use-formatmessage-properly-in-cROh2ijuEpr.exe, 00000003.00000003.1962597265.000002B7E27FE000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38D8000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983318461.000002B7E2808000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962755886.000002B7E2807000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1997930385.000002B7E280B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984587900.000002B7E2808000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                      high
                                                                      https://docs.python.org/3/library/importlib.html#importlib.abc.ExecutionLoader.get_filenameROh2ijuEpr.exe, 00000003.00000003.1965346314.000002B7E102C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D10000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1991465206.000002B7E102F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1885309318.000002B7E1013000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                        high
                                                                        https://urllib3.readthedocs.io/en/latest/advanced-usage.html#https-proxy-error-http-proxyROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                        • Avira URL Cloud: safe
                                                                        unknown
                                                                        https://github.com/python/cpython/blob/3.9/Lib/importlib/_bootstrap_external.py#L679-L688ROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D94000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                          high
                                                                          https://httpbin.org/getROh2ijuEpr.exe, 00000003.00000003.1984445540.000002B7E25FC000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                            high
                                                                            https://exiv2.org/tags.html)ROh2ijuEpr.exe, 00000003.00000003.1969612912.000002B7E287F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962927092.000002B7E287B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961461803.000002B7E2861000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://packaging.python.org/en/latest/specifications/entry-points/ROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                              high
                                                                              http://cacerts.digROh2ijuEpr.exe, 00000000.00000003.1802737261.00000277A1A10000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                high
                                                                                https://github.com/python-pillow/Pillow/ROh2ijuEpr.exe, 00000003.00000002.1998907368.000002B7E3210000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                  high
                                                                                  https://setuptools.pypa.io/en/latest/pkg_resources.html#basic-resource-accessROh2ijuEpr.exe, 00000003.00000003.1890212392.000002B7E14D1000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888281347.000002B7E14D1000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888715932.000002B7E1788000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1892756590.000002B7E1457000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888238760.000002B7E1787000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887918020.000002B7E1787000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887998418.000002B7E141E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962186012.000002B7E14F6000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1889308781.000002B7E14D1000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                    high
                                                                                    https://pypi.org/project/build/).ROh2ijuEpr.exe, 00000003.00000002.1995625869.000002B7E2030000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                      high
                                                                                      https://docs.python.org/3/library/importlib.html#importlib.abc.InspectLoader.get_codeROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D10000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                        high
                                                                                        https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packagesr&ROh2ijuEpr.exe, 00000003.00000003.1888715932.000002B7E1788000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888238760.000002B7E1787000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887918020.000002B7E1787000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                          high
                                                                                          https://wwww.certigna.fr/autorites/0mROh2ijuEpr.exe, 00000003.00000002.1996828712.000002B7E25FB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                            high
                                                                                            https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/readerROh2ijuEpr.exe, 00000003.00000003.1965827967.000002B7DF44B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987678052.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1990770516.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967420787.000002B7E1009000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962794102.000002B7DF426000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967554589.000002B7DF464000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                              high
                                                                                              http://foo/bar.tgzROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995625869.000002B7E2030000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                high
                                                                                                https://github.com/python/cpython/issues/86361.ROh2ijuEpr.exe, 00000003.00000003.1965612784.000002B7E13A9000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1979936664.000002B7E13AC000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1886669982.000002B7E1760000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887260868.000002B7E13A6000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1889308781.000002B7E13A6000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962549508.000002B7E139E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1894089672.000002B7E1330000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1886522951.000002B7E1760000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987360757.000002B7E13AC000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                  high
                                                                                                  http://mail.python.org/pipermail/python-dev/2012-June/120787.html.ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                    high
                                                                                                    https://wwww.certigna.fr/autorites/ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                      high
                                                                                                      https://www-cs-faculty.stanford.edu/~knuth/fasc2a.ps.gzROh2ijuEpr.exe, 00000003.00000003.1967086024.000002B7E136E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964931483.000002B7E135E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1891883791.000002B7E1869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1890950701.000002B7E1869000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1890950701.000002B7E1812000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963695833.000002B7E1354000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1894089672.000002B7E1330000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963723315.000002B7E135D000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                        high
                                                                                                        https://docs.python.org/3/library/importlib.html#importlib.abc.Loader.exec_moduleROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D10000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                          high
                                                                                                          https://docs.python.org/3/library/importlib.html#importlib.abc.MetaPathFinder.invalidate_cachesROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D10000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                            high
                                                                                                            https://packaging.python.org/en/latest/guides/packaging-namespace-packages/.ROh2ijuEpr.exe, 00000003.00000002.1995625869.000002B7E2030000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                              high
                                                                                                              https://packaging.python.org/en/latest/specifications/pyproject-toml/#declaring-project-metadata-theROh2ijuEpr.exe, 00000003.00000002.1994646832.000002B7E19AF000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1985867788.000002B7E19AB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                high
                                                                                                                http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535ROh2ijuEpr.exe, 00000003.00000003.1961986642.000002B7E1890000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1965240050.000002B7E18A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972469095.000002B7E1751000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1993843529.000002B7E18A5000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980835556.000002B7E18A5000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                • Avira URL Cloud: safe
                                                                                                                unknown
                                                                                                                https://github.com/Unidata/MetPy/blob/a3424de66a44bf3a92b0dcacf4dff82ad7b86712/src/metpy/plots/wx_syROh2ijuEpr.exe, 00000003.00000003.1965827967.000002B7DF44B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987678052.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1990770516.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967420787.000002B7E1009000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962794102.000002B7DF426000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967554589.000002B7DF464000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                  high
                                                                                                                  https://xmpp.org/getting-started/ROh2ijuEpr.exe, 00000000.00000003.1875204178.00000277A1A13000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                  • Avira URL Cloud: safe
                                                                                                                  unknown
                                                                                                                  https://docs.python.org/3/library/multiprocessing.htmlROh2ijuEpr.exe, 00000003.00000003.1972469095.000002B7E1758000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980077773.000002B7E1760000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1993388559.000002B7E1774000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983810629.000002B7E1774000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                    high
                                                                                                                    https://github.com/pypa/setuptools/issues/417#issuecomment-392298401ROh2ijuEpr.exe, 00000003.00000002.1995447387.000002B7E1E20000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                      high
                                                                                                                      https://packaging.python.org/en/latest/specifications/core-metadata/#core-metadataROh2ijuEpr.exe, 00000003.00000002.1995358637.000002B7E1D20000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                        high
                                                                                                                        http://crl.securetrust.com/STCA.crlROh2ijuEpr.exe, 00000003.00000003.1978029380.000002B7E261F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982631016.000002B7E2620000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                          high
                                                                                                                          http://wwwsearch.sf.net/):ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986394488.000002B7E249D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1964512632.000002B7E2492000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                          • Avira URL Cloud: safe
                                                                                                                          unknown
                                                                                                                          https://github.com/python/importlib_metadata/wiki/Development-MethodologyROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                            high
                                                                                                                            http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0ROh2ijuEpr.exe, 00000003.00000003.1971740530.000002B7E2662000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                              high
                                                                                                                              http://www.accv.es/legislacion_c.htmROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                high
                                                                                                                                http://tools.ietf.org/html/rfc6125#section-6.4.3ROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                  high
                                                                                                                                  http://crl.xrampsecurity.com/XGCA.crl0ROh2ijuEpr.exe, 00000003.00000003.1978029380.000002B7E261F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982631016.000002B7E2620000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                    high
                                                                                                                                    https://bugs.python.org/issue44497.ROh2ijuEpr.exe, 00000003.00000002.1995447387.000002B7E1E20000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995537168.000002B7E1F30000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                      high
                                                                                                                                      http://www.cert.fnmt.es/dpcs/ROh2ijuEpr.exe, 00000003.00000003.1978167770.000002B7E1AA7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971740530.000002B7E2662000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982197645.000002B7E1AA8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983165935.000002B7E1AA8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986201293.000002B7E1AA9000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                        high
                                                                                                                                        https://setuptools.pypa.io/en/latest/pkg_resources.htmlROh2ijuEpr.exe, 00000003.00000003.1887998418.000002B7E14D1000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888715932.000002B7E1788000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888238760.000002B7E1787000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887918020.000002B7E1787000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                          high
                                                                                                                                          https://google.com/mailROh2ijuEpr.exe, 00000003.00000002.1994772474.000002B7E1A02000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984497184.000002B7E19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971797186.000002B7E17FD000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                            high
                                                                                                                                            https://packaging.python.org/specifications/entry-points/ROh2ijuEpr.exe, 00000003.00000002.1995447387.000002B7E1E20000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995358637.000002B7E1D20000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                              high
                                                                                                                                              https://github.com/jaraco/jaraco.functools/issues/5ROh2ijuEpr.exe, 00000003.00000002.1995164756.000002B7E1B20000.00000004.00001000.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1995625869.000002B7E2030000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                high
                                                                                                                                                http://www.accv.es00ROh2ijuEpr.exe, 00000003.00000003.1971740530.000002B7E2662000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971634653.000002B7E264D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1968510623.000002B7E262B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969310358.000002B7E2633000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                  high
                                                                                                                                                  https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/abc.pyROh2ijuEpr.exe, 00000003.00000003.1967554589.000002B7DF464000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                    high
                                                                                                                                                    http://www.rfc-editor.org/info/rfc7253ROh2ijuEpr.exe, 00000003.00000003.1989727599.000002B7E1A98000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1981715302.000002B7E1A92000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                      high
                                                                                                                                                      http://csrc.nist.gov/publications/nistpubs/800-38C/SP800-38C.pdfROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963080661.000002B7E1B1D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966679097.000002B7E1B1E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                        high
                                                                                                                                                        https://foss.heptapod.net/pypy/pypy/-/issues/3539ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                          high
                                                                                                                                                          https://github.com/urllib3/urllib3/issues/2513#issuecomment-1152559900.ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                            high
                                                                                                                                                            http://google.com/ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                              high
                                                                                                                                                              https://mahler:8092/site-updates.pyROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E177D000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                                              unknown
                                                                                                                                                              https://github.com/BLAKE3-team/BLAKE3).ROh2ijuEpr.exe, 00000003.00000002.1995358637.000002B7E1D20000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                high
                                                                                                                                                                http://crl.securetrust.com/SGCA.crlROh2ijuEpr.exe, 00000003.00000003.1978029380.000002B7E261F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982631016.000002B7E2620000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                  high
                                                                                                                                                                  http://.../back.jpegROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                    high
                                                                                                                                                                    https://tools.ietf.org/html/rfc7231#section-4.3.6)ROh2ijuEpr.exe, 00000003.00000003.1966373385.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982101411.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989081522.000002B7E2436000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963385669.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986984522.000002B7E17A5000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982809276.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                      high
                                                                                                                                                                      http://tools.ietf.org/html/rfc5869ROh2ijuEpr.exe, 00000003.00000003.1972994990.000002B7E1B0D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969913757.000002B7E1B0A000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                        high
                                                                                                                                                                        https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packagesr&rROh2ijuEpr.exe, 00000003.00000003.1888715932.000002B7E1788000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1888238760.000002B7E1787000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1887918020.000002B7E1787000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                          high
                                                                                                                                                                          http://blog.cryptographyengineering.com/2012/05/how-to-choose-authenticated-encryption.htmlROh2ijuEpr.exe, 00000003.00000002.1994772474.000002B7E1A02000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966373385.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969913757.000002B7E1B16000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1984497184.000002B7E19FB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982101411.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963385669.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963080661.000002B7E1B1D000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983540772.000002B7E1805000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1978447243.000002B7E1801000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E18C7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1994671358.000002B7E19BB000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E19A8000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1986984522.000002B7E17A5000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1963747551.000002B7E1B15000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1985904359.000002B7E19B4000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966679097.000002B7E1B1E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1972733319.000002B7E1B16000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1971797186.000002B7E17FD000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961538386.000002B7E1AFA000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                            high
                                                                                                                                                                            https://httpbin.org/postROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1980911449.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961027539.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1973295666.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1983140161.000002B7E1ADA000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987147803.000002B7E1ADD000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1AD3000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                              high
                                                                                                                                                                              https://pyperclip.readthedocs.io/en/latest/index.html#not-implemented-errorROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E38D8000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                high
                                                                                                                                                                                https://docs.python.org/3/library/importlib.html#importlib.abc.InspectLoader.get_sourceROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D94000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                  high
                                                                                                                                                                                  https://paste.debian.net/plainh/724e4d05ROh2ijuEpr.exe, 00000003.00000002.1998268505.000002B7E2BB0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                  • Avira URL Cloud: safe
                                                                                                                                                                                  unknown
                                                                                                                                                                                  http://www.firmaprofesional.com/cps0ROh2ijuEpr.exe, 00000003.00000003.1963955040.000002B7E241C000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1989081522.000002B7E2436000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1975941232.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1985234977.000002B7E1A6B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1985170894.000002B7E1A67000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962349220.000002B7E1A5E000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982809276.000002B7E2430000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1969791157.000002B7E1A5F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1966700425.000002B7E242F000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1961675051.000002B7E1A53000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                    high
                                                                                                                                                                                    https://mouseinfo.readthedocs.ioROh2ijuEpr.exe, 00000003.00000002.1999244521.000002B7E3950000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                      high
                                                                                                                                                                                      https://docs.python.org/3/library/importlib.html#importlib.abc.PathEntryFinder.find_specROh2ijuEpr.exe, 00000003.00000002.1990850699.000002B7E0D10000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                        high
                                                                                                                                                                                        https://github.com/urllib3/urllib3/issues/2920ROh2ijuEpr.exe, 00000003.00000002.1998595729.000002B7E2FC0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                          high
                                                                                                                                                                                          http://crl.securetrust.com/SGCA.crl0ROh2ijuEpr.exe, 00000003.00000003.1973072375.000002B7E17D7000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962452431.000002B7E17A2000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1982784444.000002B7E17D7000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                            high
                                                                                                                                                                                            https://docs.python.org/3/library/importlib.html#importlib.abc.ResourceLoader.get_dataROh2ijuEpr.exe, 00000003.00000003.1965827967.000002B7DF44B000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1987678052.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000002.1990770516.000002B7DF465000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1962794102.000002B7DF426000.00000004.00000020.00020000.00000000.sdmp, ROh2ijuEpr.exe, 00000003.00000003.1967554589.000002B7DF464000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                              high
                                                                                                                                                                                              • No. of IPs < 25%
                                                                                                                                                                                              • 25% < No. of IPs < 50%
                                                                                                                                                                                              • 50% < No. of IPs < 75%
                                                                                                                                                                                              • 75% < No. of IPs
                                                                                                                                                                                              IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                                              149.154.167.220
                                                                                                                                                                                              api.telegram.orgUnited Kingdom
                                                                                                                                                                                              62041TELEGRAMRUfalse
                                                                                                                                                                                              Joe Sandbox version:41.0.0 Charoite
                                                                                                                                                                                              Analysis ID:1569042
                                                                                                                                                                                              Start date and time:2024-12-05 11:37:12 +01:00
                                                                                                                                                                                              Joe Sandbox product:CloudBasic
                                                                                                                                                                                              Overall analysis duration:0h 7m 52s
                                                                                                                                                                                              Hypervisor based Inspection enabled:false
                                                                                                                                                                                              Report type:full
                                                                                                                                                                                              Cookbook file name:default.jbs
                                                                                                                                                                                              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                                              Number of analysed new started processes analysed:6
                                                                                                                                                                                              Number of new started drivers analysed:0
                                                                                                                                                                                              Number of existing processes analysed:0
                                                                                                                                                                                              Number of existing drivers analysed:0
                                                                                                                                                                                              Number of injected processes analysed:0
                                                                                                                                                                                              Technologies:
                                                                                                                                                                                              • HCA enabled
                                                                                                                                                                                              • EGA enabled
                                                                                                                                                                                              • AMSI enabled
                                                                                                                                                                                              Analysis Mode:default
                                                                                                                                                                                              Analysis stop reason:Timeout
                                                                                                                                                                                              Sample name:ROh2ijuEpr.exe
                                                                                                                                                                                              renamed because original name is a hash value
                                                                                                                                                                                              Original Sample Name:7b54b8972d8f870cb5cf66a4f9a92c78b56395ac802fb3d4bf05b18bbab9d5a4.exe
                                                                                                                                                                                              Detection:MAL
                                                                                                                                                                                              Classification:mal76.rans.troj.winEXE@4/1026@1/1
                                                                                                                                                                                              EGA Information:
                                                                                                                                                                                              • Successful, ratio: 100%
                                                                                                                                                                                              HCA Information:
                                                                                                                                                                                              • Successful, ratio: 89%
                                                                                                                                                                                              • Number of executed functions: 77
                                                                                                                                                                                              • Number of non-executed functions: 251
                                                                                                                                                                                              Cookbook Comments:
                                                                                                                                                                                              • Found application associated with file extension: .exe
                                                                                                                                                                                              • Stop behavior analysis, all processes terminated
                                                                                                                                                                                              • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe
                                                                                                                                                                                              • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                                                                                                                                                              • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                                              • Report size exceeded maximum capacity and may have missing disassembly code.
                                                                                                                                                                                              • Report size getting too big, too many NtCreateFile calls found.
                                                                                                                                                                                              • Report size getting too big, too many NtOpenFile calls found.
                                                                                                                                                                                              • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                                                                                                              • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                                                                                              • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                                                                                                                                                                                              • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                                                                                                              • VT rate limit hit for: ROh2ijuEpr.exe
                                                                                                                                                                                              No simulations
                                                                                                                                                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                              149.154.167.220REQUEST FOR QUOATION AND PRICES 0106-24_pdf.exeGet hashmaliciousGuLoader, MassLogger RATBrowse
                                                                                                                                                                                                Patch.exeGet hashmaliciousPureLog Stealer, XWormBrowse
                                                                                                                                                                                                  RuntimeBroker.exeGet hashmaliciousPureLog Stealer, XWormBrowse
                                                                                                                                                                                                    FACTURA PROFORMA 611 MICROMENT IN LONDON_pdf.exeGet hashmaliciousPureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                      rOJS25YL2e.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                        Uii3leknna.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                          Uii3leknna.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                            DxWl6xEBp7.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                              DxWl6xEBp7.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                Teklif Talebi #U0130hale No_14991_PDF.exeGet hashmaliciousPureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                  api.telegram.orgREQUEST FOR QUOATION AND PRICES 0106-24_pdf.exeGet hashmaliciousGuLoader, MassLogger RATBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  Patch.exeGet hashmaliciousPureLog Stealer, XWormBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  RuntimeBroker.exeGet hashmaliciousPureLog Stealer, XWormBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  FACTURA PROFORMA 611 MICROMENT IN LONDON_pdf.exeGet hashmaliciousPureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  rOJS25YL2e.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  Uii3leknna.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  Uii3leknna.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  DxWl6xEBp7.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  DxWl6xEBp7.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  Teklif Talebi #U0130hale No_14991_PDF.exeGet hashmaliciousPureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                  TELEGRAMRUREQUEST FOR QUOATION AND PRICES 0106-24_pdf.exeGet hashmaliciousGuLoader, MassLogger RATBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  Patch.exeGet hashmaliciousPureLog Stealer, XWormBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  RuntimeBroker.exeGet hashmaliciousPureLog Stealer, XWormBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  FACTURA PROFORMA 611 MICROMENT IN LONDON_pdf.exeGet hashmaliciousPureLog Stealer, Snake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  Ttok18.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                  • 149.154.167.99
                                                                                                                                                                                                                  jtkhikadjthsad.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                  • 149.154.167.99
                                                                                                                                                                                                                  file.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                  • 149.154.167.99
                                                                                                                                                                                                                  rOJS25YL2e.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  Uii3leknna.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  Uii3leknna.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                  • 149.154.167.220
                                                                                                                                                                                                                  No context
                                                                                                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                  C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_ARC4.pydzed.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                    back.ps1Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                      zed.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                        file.exeGet hashmaliciousPython Stealer, Amadey, LummaC Stealer, Nymaim, StealcBrowse
                                                                                                                                                                                                                          file.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, CryptbotBrowse
                                                                                                                                                                                                                              file.exeGet hashmaliciousAmadey, XWormBrowse
                                                                                                                                                                                                                                file.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                  Payload.exeGet hashmaliciousPython Stealer, BLX Stealer, XLABB GrabberBrowse
                                                                                                                                                                                                                                    Payload.exeGet hashmaliciousPython Stealer, BLX Stealer, XLABB GrabberBrowse
                                                                                                                                                                                                                                      C:\Users\user\AppData\Local\Temp\_MEI36842\Crypto\Cipher\_Salsa20.pydzed.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                        back.ps1Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                          zed.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                            file.exeGet hashmaliciousPython Stealer, Amadey, LummaC Stealer, Nymaim, StealcBrowse
                                                                                                                                                                                                                                              file.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                file.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                  file.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    file.exeGet hashmaliciousAmadey, CryptbotBrowse
                                                                                                                                                                                                                                                      file.exeGet hashmaliciousAmadey, XWormBrowse
                                                                                                                                                                                                                                                        file.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11264
                                                                                                                                                                                                                                                          Entropy (8bit):4.640339306680604
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:dLklddyTHThob0q/tJRrlDfNYSOcqgYCWt:ZgcdZq/JJD6gRWt
                                                                                                                                                                                                                                                          MD5:BCD8CAAF9342AB891BB1D8DD45EF0098
                                                                                                                                                                                                                                                          SHA1:EE7760BA0FF2548F25D764F000EFBB1332BE6D3E
                                                                                                                                                                                                                                                          SHA-256:78725D2F55B7400A3FCAFECD35AF7AEB253FBC0FFCDF1903016EB0AABD1B4E50
                                                                                                                                                                                                                                                          SHA-512:8B6FB53AECB514769985EBFDAB1B3C739024597D9C35905E04971D5422256546F7F169BF98F9BAF7D9F42A61CFF3EE7A20664989D3000773BF5EDA10CB3A0C24
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Joe Sandbox View:
                                                                                                                                                                                                                                                          • Filename: zed.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: back.ps1, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: zed.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: Payload.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: Payload.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          Reputation:moderate, very likely benign file
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......r^J.6?$.6?$.6?$.?G..2?$.dJ%.4?$.}G%.5?$.6?%..?$.dJ!.<?$.dJ .>?$.dJ'.5?$..J,.7?$..J$.7?$..J..7?$..J&.7?$.Rich6?$.........................PE..d...Y..f.........." ................P........................................p............`..........................................'......0(..d....P.......@...............`..(....!...............................!..8............ ...............................text............................... ..`.rdata..Z.... ......................@..@.data...H....0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......(..............@..@.reloc..(....`.......*..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):13824
                                                                                                                                                                                                                                                          Entropy (8bit):5.0194545642425075
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:4t/1nCuqaL0kt7AznuRmceS4lDFhAlcqgcLg:F/k1ACln4lDogcLg
                                                                                                                                                                                                                                                          MD5:F19CB847E567A31FAB97435536C7B783
                                                                                                                                                                                                                                                          SHA1:4C8BFE404AF28C1781740E7767619A5E2D2FF2B7
                                                                                                                                                                                                                                                          SHA-256:1ECE1DC94471D6977DBE2CEEBA3764ADF0625E2203D6257F7C781C619D2A3DAD
                                                                                                                                                                                                                                                          SHA-512:382DC205F703FC3E1F072F17F58E321E1A65B86BE7D9D6B07F24A02A156308A7FEC9B1A621BA1F3428FD6BB413D14AE9ECB2A2C8DD62A7659776CFFDEBB6374C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Joe Sandbox View:
                                                                                                                                                                                                                                                          • Filename: zed.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: back.ps1, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: zed.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                          Reputation:moderate, very likely benign file
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.:...:...:...3.j.>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...........................PE..d...Z..f.........." ................P.....................................................`..........................................8......H9..d....`.......P..L............p..(....1...............................1..8............0...............................text...h........................... ..`.rdata..r....0......................@..@.data...H....@.......,..............@....pdata..L....P......................@..@.rsrc........`.......2..............@..@.reloc..(....p.......4..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):13312
                                                                                                                                                                                                                                                          Entropy (8bit):5.037456384995606
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:st/1nCuqaL0ktPMn1ENe3erKr5br0YbsiDw6a9lkOcqgRGd:p/kpMIodrXbsiDS95gRGd
                                                                                                                                                                                                                                                          MD5:DC14677EA8A8C933CC41F9CCF2BEDDC1
                                                                                                                                                                                                                                                          SHA1:A6FB87E8F3540743097A467ABE0723247FDAF469
                                                                                                                                                                                                                                                          SHA-256:68F081E96AE08617CF111B21EDED35C1774A5EF1223DF9A161C9445A78F25C73
                                                                                                                                                                                                                                                          SHA-512:3ABA4CFCBBE4B350AB3230D488BD75186427E3AAAF38D19E0E1C7330F16795AD77FB6E26FF39AF29EAF4F5E8C42118CB680F90AFBFCA218AEDA64DC444675BA2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:moderate, very likely benign file
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.:...:...:...3.j.>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...........................PE..d...Z..f.........." ................P.....................................................`......................................... 8.......8..d....`.......P..d............p..(....1...............................1..8............0...............................text............................... ..`.rdata.......0......................@..@.data...H....@.......*..............@....pdata..d....P.......,..............@..@.rsrc........`.......0..............@..@.reloc..(....p.......2..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):14336
                                                                                                                                                                                                                                                          Entropy (8bit):5.09191874780435
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:rMVsiXeqVb0lIb0Pj5Jdfpm68WZDInU282tacqgYLg:rM7ali0Pj5JxCaDuUlgYLg
                                                                                                                                                                                                                                                          MD5:C09BB8A30F0F733C81C5C5A3DAD8D76D
                                                                                                                                                                                                                                                          SHA1:46FD3BA87A32D12F4EE14601D1AD73B78EDC81D1
                                                                                                                                                                                                                                                          SHA-256:8A1B751DB47CE7B1D3BD10BEBFFC7442BE4CFB398E96E3B1FF7FB83C88A8953D
                                                                                                                                                                                                                                                          SHA-512:691AC74FAE930E9CEABE782567EFB99C50DD9B8AD607DD7F99A5C7DF2FA2BEB7EDFE2EBB7095A72DA0AE24E688FBABD340EAE8B646D5B8C394FEE8DDD5E60D31
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:moderate, very likely benign file
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......r^:.6?T.6?T.6?T.?G..2?T.dJU.4?T.}GU.5?T.6?U..?T.dJQ.<?T.dJP.>?T.dJW.5?T..J\.7?T..JT.7?T..J..7?T..JV.7?T.Rich6?T.........................PE..d...X..f.........." ................P.....................................................`.........................................`8.......8..d....`.......P..(............p..(....1...............................1..8............0...............................text............................... ..`.rdata..6....0....... ..............@..@.data...x....@......................@....pdata..(....P.......0..............@..@.rsrc........`.......4..............@..@.reloc..(....p.......6..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36352
                                                                                                                                                                                                                                                          Entropy (8bit):6.541423493519083
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:f/UlZA5PUEllvxL/7v/iKBt5ByU0xGitqzSEkxGG7+tpKHb/LZ7fr52EkifcMxme:klcR7JriEbwDaS4j990th9VDBV
                                                                                                                                                                                                                                                          MD5:0AB25F99CDAACA6B11F2ECBE8223CAD5
                                                                                                                                                                                                                                                          SHA1:7A881B3F84EF39D97A31283DE6D7B7AE85C8BAE6
                                                                                                                                                                                                                                                          SHA-256:6CE8A60D1AB5ADC186E23E3DE864D7ADF6BDD37E3B0C591FA910763C5C26AF60
                                                                                                                                                                                                                                                          SHA-512:11E89EEF34398DF3B144A0303E08B3A4CAF41A9A8CA618C18135F561731F285F8CF821D81179C2C45F6EEB0E496D9DD3ECF6FF202A3C453C80AFEF8582D06C17
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......r^J.6?$.6?$.6?$.?G..2?$.dJ%.4?$.}G%.5?$.6?%..?$.dJ!.<?$.dJ .>?$.dJ'.5?$..J,.7?$..J$.7?$..J..7?$..J&.7?$.Rich6?$.........................PE..d...V..f.........." .....H...H......P.....................................................`.........................................p...........d...............................0......................................8............`...............................text...xG.......H.................. ..`.rdata.."6...`...8...L..............@..@.data...H...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..0...........................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):15360
                                                                                                                                                                                                                                                          Entropy (8bit):5.367749645917753
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:YiJBj5fq/Rk0kPLhOZ3UucCWuSKPEkA2bD9JXx03cqg5YUMLgs:/k1kTMZEjCWNaA2DTx0g5YUMLg
                                                                                                                                                                                                                                                          MD5:B6EA675C3A35CD6400A7ECF2FB9530D1
                                                                                                                                                                                                                                                          SHA1:0E41751AA48108D7924B0A70A86031DDE799D7D6
                                                                                                                                                                                                                                                          SHA-256:76EF4C1759B5553550AB652B84F8E158BA8F34F29FD090393815F06A1C1DC59D
                                                                                                                                                                                                                                                          SHA-512:E31FD33E1ED6D4DA3957320250282CFD9EB3A64F12DE4BD2DFE3410F66725164D96B27CAA34C501D1A535A5A2442D5F070650FD3014B4B92624EE00F1C3F3197
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.:...:...:...3.z.>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...........................PE..d...V..f.........." ......... ......P.....................................................`..........................................9......$:..d....`.......P...............p..(....1...............................1..8............0.. ............................text............................... ..`.rdata.......0......."..............@..@.data...8....@.......2..............@....pdata.......P.......4..............@..@.rsrc........`.......8..............@..@.reloc..(....p.......:..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):16384
                                                                                                                                                                                                                                                          Entropy (8bit):5.41148259289073
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:w3d9FkHaz0EJvrj+CYuz7ucc9dG7otDr22KcqgOiewZjW:YkHEJzj+X6769lDzagO/w
                                                                                                                                                                                                                                                          MD5:F14E1AA2590D621BE8C10321B2C43132
                                                                                                                                                                                                                                                          SHA1:FD84D11619DFFDF82C563E45B48F82099D9E3130
                                                                                                                                                                                                                                                          SHA-256:FCE70B3DAFB39C6A4DB85D2D662CB9EB9C4861AA648AD7436E7F65663345D177
                                                                                                                                                                                                                                                          SHA-512:A86B9DF163007277D26F2F732ECAB9DBCA8E860F8B5809784F46702D4CEA198824FDEF6AB98BA7DDC281E8791C10EABA002ABDA6F975323B36D5967E0443C1E4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.g.:...:...:...3...>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...................PE..d...W..f.........." ....."... ......P.....................................................`.........................................pI.......J..d....p.......`..................(....B...............................B..8............@...............................text...( .......".................. ..`.rdata..<....@.......&..............@..@.data...H....P.......6..............@....pdata.......`.......8..............@..@.rsrc........p.......<..............@..@.reloc..(............>..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20992
                                                                                                                                                                                                                                                          Entropy (8bit):6.041302713678401
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:kUX0JfbRz5MLZA0nmwzMDYpJgLa0Mp8NDBcxgprAM:6NbRzWXwDqgLa1uBfP
                                                                                                                                                                                                                                                          MD5:B127CAE435AEB8A2A37D2A1BC1C27282
                                                                                                                                                                                                                                                          SHA1:2A7BF8BF7F24B2381370BA6B41FB640EE42BDCCD
                                                                                                                                                                                                                                                          SHA-256:538B1253B5929254ED92129FA0957DB26CDDF34A8372BA0BF19D20D01549ADA3
                                                                                                                                                                                                                                                          SHA-512:4FE027E46D5132CA63973C67BD5394F2AC74DD4BBCFE93CB16136FAB4B6BF67BECB5A0D4CA359FF9426DA63CA81F793BBF1B79C8A9D8372C53DCB5796D17367E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.g.:...:...:...3...>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...................PE..d...W..f.........." .....$...0......P.....................................................`.........................................0Y.......Y..d............p..................0....Q...............................R..8............@...............................text....".......$.................. ..`.rdata.......@... ...(..............@..@.data...H....`.......H..............@....pdata.......p.......J..............@..@.rsrc................N..............@..@.reloc..0............P..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):24576
                                                                                                                                                                                                                                                          Entropy (8bit):6.530656045206549
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:cEDwUBi9SPu71omZXmrfXA+UA10ol31tuXVYdAgYj:FsUBXmoEXmrXA+NNxWFYfo
                                                                                                                                                                                                                                                          MD5:2E15AA6F97ED618A3236CFA920988142
                                                                                                                                                                                                                                                          SHA1:A9D556D54519D3E91FA19A936ED291A33C0D1141
                                                                                                                                                                                                                                                          SHA-256:516C5EA47A7B9A166F2226ECBA79075F1A35EFFF14D87E00006B34496173BB78
                                                                                                                                                                                                                                                          SHA-512:A6C75C4A285753CC94E45500E8DD6B6C7574FB7F610FF65667F1BEC8D8B413FC10514B7D62F196C2B8D017C308C5E19E2AEF918021FA81D0CB3D8CED37D8549A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.:...:...:...3.j.>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...........................PE..d...W..f.........." .....$...>............................................................`..........................................h.......i..d...............................0....a...............................a..8............@...............................text....#.......$.................. ..`.rdata..:-...@.......(..............@..@.data...H....p.......V..............@....pdata...............X..............@..@.rsrc................\..............@..@.reloc..0............^..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):12288
                                                                                                                                                                                                                                                          Entropy (8bit):4.7080156150187396
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:lF/1n7Guqaj0ktfEJwX1fYwCODR3lncqg0Gd6l:RGXkJEm1feODxDg0Gd6
                                                                                                                                                                                                                                                          MD5:40390F2113DC2A9D6CFAE7127F6BA329
                                                                                                                                                                                                                                                          SHA1:9C886C33A20B3F76B37AA9B10A6954F3C8981772
                                                                                                                                                                                                                                                          SHA-256:6BA9C910F755885E4D356C798A4DD32D2803EA4CFABB3D56165B3017D0491AE2
                                                                                                                                                                                                                                                          SHA-512:617B963816838D649C212C5021D7D0C58839A85D4D33BBAF72C0EC6ECD98B609080E9E57AF06FA558FF302660619BE57CC974282826AB9F21AE0D80FBAA831A1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.g.:...:...:...3...>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...................PE..d...X..f.........." ................P.....................................................`..........................................8.......8..d....`.......P..X............p..(....1...............................1..8............0...............................text............................... ..`.rdata.......0......................@..@.data...H....@.......&..............@....pdata..X....P.......(..............@..@.rsrc........`.......,..............@..@.reloc..(....p......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):12800
                                                                                                                                                                                                                                                          Entropy (8bit):5.159963979391524
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:kblRgfeqfz0RP767fB4A84DgVD6eDcqgzbkLgmf:BwRj67p84Dg6eVgzbkLgmf
                                                                                                                                                                                                                                                          MD5:899895C0ED6830C4C9A3328CC7DF95B6
                                                                                                                                                                                                                                                          SHA1:C02F14EBDA8B631195068266BA20E03210ABEABC
                                                                                                                                                                                                                                                          SHA-256:18D568C7BE3E04F4E6026D12B09B1FA3FAE50FF29AC3DEAF861F3C181653E691
                                                                                                                                                                                                                                                          SHA-512:0B4C50E40AF92BC9589668E13DF417244274F46F5A66E1FC7D1D59BC281969BA319305BECEA119385F01CC4603439E4B37AFA2CF90645425210848A02839E3E7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......r^..6?..6?..6?..?G..2?..dJ..4?..}G..5?..6?...?..dJ..<?..dJ..>?..dJ..5?...J..7?...J..7?...Jk.7?...J..7?..Rich6?..................PE..d...Y..f.........." ................P.....................................................`..........................................8......x9..d....`.......P..d............p..(....1...............................1..8............0...............................text............................... ..`.rdata.......0......................@..@.data...H....@.......(..............@....pdata..d....P.......*..............@..@.rsrc........`......................@..@.reloc..(....p.......0..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):14848
                                                                                                                                                                                                                                                          Entropy (8bit):5.270418334522813
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:vktJ1gifqQGRk0IP73AdXdmEEEEEm9uhiFEQayDZVMcqgnF6+6Lg:vkdU1ID3AdXd49urQPDggnUjLg
                                                                                                                                                                                                                                                          MD5:C4C525B081F8A0927091178F5F2EE103
                                                                                                                                                                                                                                                          SHA1:A1F17B5EA430ADE174D02ECC0B3CB79DBF619900
                                                                                                                                                                                                                                                          SHA-256:4D86A90B2E20CDE099D6122C49A72BAE081F60EB2EEA0F76E740BE6C41DA6749
                                                                                                                                                                                                                                                          SHA-512:7C06E3E6261427BC6E654B2B53518C7EAA5F860A47AE8E80DC3F8F0FED91E122CB2D4632188DC44123FB759749B5425F426CD1153A8F84485EF0491002B26555
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......r^z.6?..6?..6?..?G..2?..dJ..4?..}G..5?..6?...?..dJ..<?..dJ..>?..dJ..5?...J..7?...J..7?...J..7?...J..7?..Rich6?..........................PE..d...Y..f.........." ......... ......P.....................................................`.........................................`9.......:..d....`.......P...............p..(....1...............................1..8............0.. ............................text............................... ..`.rdata.......0....... ..............@..@.data........@.......0..............@....pdata.......P.......2..............@..@.rsrc........`.......6..............@..@.reloc..(....p.......8..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):56832
                                                                                                                                                                                                                                                          Entropy (8bit):4.231032526864278
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:0qcmHBeNL1dO/qHkpnYcZiGKdZHDLY84vnKAnK2rZA21agVF:fEiqHHx4vZDV
                                                                                                                                                                                                                                                          MD5:F9E266F763175B8F6FD4154275F8E2F0
                                                                                                                                                                                                                                                          SHA1:8BE457700D58356BC2FA7390940611709A0E5473
                                                                                                                                                                                                                                                          SHA-256:14D2799BE604CBDC668FDE8834A896EEE69DAE0E0D43B37289FCCBA35CEF29EC
                                                                                                                                                                                                                                                          SHA-512:EB3E37A3C3FF8A65DEF6FA20941C8672A8197A41977E35AE2DC6551B5587B84C2703758320559F2C93C0531AD5C9D0F6C36EC5037669DC5CE78EB3367D89877B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........PK..1%..1%..1%..I...1%.D$..1%.I$..1%..1$..1%.D ..1%.D!..1%.D&..1%..D-..1%..D%..1%..D...1%..D'..1%.Rich.1%.........................PE..d...X..f.........." .....6...................................................0............`.................................................\...d...............l............ ..0... ...............................@...8............P...............................text....5.......6.................. ..`.rdata.......P.......:..............@..@.data...H...........................@....pdata..l...........................@..@.rsrc...............................@..@.reloc..0.... ......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):57344
                                                                                                                                                                                                                                                          Entropy (8bit):4.252429732285762
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:J4cmHBeIzNweVy/CHkRnYcZiGKdZHDLq80vnKAnKBrZGsURygUX:GEO6CHnX0vZb7
                                                                                                                                                                                                                                                          MD5:DECF524B2D53FCD7D4FA726F00B3E5FC
                                                                                                                                                                                                                                                          SHA1:E87C6ED4004F2772B888C5B5758AA75FE99D2F6F
                                                                                                                                                                                                                                                          SHA-256:58F7053EE70467D3384C73F299C0DFD63EEF9744D61D1980D9D2518974CA92D4
                                                                                                                                                                                                                                                          SHA-512:EAFF4FD80843743E61CE635FBADF4E5D9CF2C3E97F3C48350BD9E755F4423AC6867F9FE8746BD5C54E1402B18E8A55AEEF7ACA098C7CF4186DC4C1235EB35DF2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........PK..1%..1%..1%..I...1%.D$..1%.I$..1%..1$..1%.D ..1%.D!..1%.D&..1%..D-..1%..D%..1%..D...1%..D'..1%.Rich.1%.........................PE..d...X..f.........." .....8...................................................0............`.....................................................d............................ ..0... ...............................@...8............P...............................text...X7.......8.................. ..`.rdata......P.......<..............@..@.data...H...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..0.... ......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10240
                                                                                                                                                                                                                                                          Entropy (8bit):4.690163963718492
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:Yddz2KTnThIz0qfteRY4zp+D3PLui8p1cqgHCWt:k2E9RqfCXp+D3juRpLgiWt
                                                                                                                                                                                                                                                          MD5:80BB1E0E06ACAF03A0B1D4EF30D14BE7
                                                                                                                                                                                                                                                          SHA1:B20CAC0D2F3CD803D98A2E8A25FBF65884B0B619
                                                                                                                                                                                                                                                          SHA-256:5D1C2C60C4E571B88F27D4AE7D22494BED57D5EC91939E5716AFA3EA7F6871F6
                                                                                                                                                                                                                                                          SHA-512:2A13AB6715B818AD62267AB51E55CD54714AEBF21EC9EA61C2AEFD56017DC84A6B360D024F8682A2E105582B9C5FE892ECEBD2BEF8A492279B19FFD84BC83FA5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........@................../....../...../......+.......*......-......&....................,....Rich...........................PE..d...X..f.........." ................P........................................p............`.........................................0'.......'..P....P.......@...............`..(....!...............................!..8............ ...............................text............................... ..`.rdata....... ......................@..@.data...H....0....... ..............@....pdata.......@......."..............@..@.rsrc........P.......$..............@..@.reloc..(....`.......&..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):22016
                                                                                                                                                                                                                                                          Entropy (8bit):6.1215844022564285
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:nUX0JfbRwUtPMbNv37t6K5jwbDEpJgLa0Mp8xCkgJrAm:jNbRw8EbxwKBwbD+gLa1nh
                                                                                                                                                                                                                                                          MD5:3727271FE04ECB6D5E49E936095E95BC
                                                                                                                                                                                                                                                          SHA1:46182698689A849A8C210A8BF571D5F574C6F5B1
                                                                                                                                                                                                                                                          SHA-256:3AF5B35DCD5A3B6C7E88CEE53F355AAFFF40F2C21DABD4DE27DBB57D1A29B63B
                                                                                                                                                                                                                                                          SHA-512:5BED1F4DF678FE90B8E3F1B7C4F68198463E579209B079CB4A40DCAC01CE26AA2417DBE029B196F6F2C6AFAD560E2D1AF9F089ABE37EAD121CA10EE69D9659ED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.g.:...:...:...3...>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...................PE..d...W..f.........." .....(...0......P.....................................................`.........................................0Y.......Y..d............p..................0....Q...............................R..8............@...............................text...H'.......(.................. ..`.rdata.......@... ...,..............@..@.data...H....`.......L..............@....pdata.......p.......N..............@..@.rsrc................R..............@..@.reloc..0............T..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):17920
                                                                                                                                                                                                                                                          Entropy (8bit):5.293810509074883
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:4PHoDUntQjNB+/yw/pogeXOvXoTezczOo3p9iJgDQ3iNgnVbwhA:dUOhBcDRogeXOfoTezcio3pUJgDQ3i+
                                                                                                                                                                                                                                                          MD5:78AEF441C9152A17DD4DC40C7CC9DF69
                                                                                                                                                                                                                                                          SHA1:6BB6F8426AFA6522E647DFC82B1B64FAF3A9781F
                                                                                                                                                                                                                                                          SHA-256:56E4E4B156295F1AAA22ECB5481841DE2A9EB84845A16E12A7C18C7C3B05B707
                                                                                                                                                                                                                                                          SHA-512:27B27E77BE81B29D42359FE28531225383860BCD19A79044090C4EA58D9F98009A254BF63585979C60B3134D47B8233941ABB354A291F23C8641A4961FA33107
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...Y..f.........." .....(... ......P.....................................................`.........................................pI......lJ..d....p.......`..................(....A...............................A..8............@...............................text....'.......(.................. ..`.rdata.......@.......,..............@..@.data........P.......<..............@....pdata.......`.......>..............@..@.rsrc........p.......B..............@..@.reloc..(............D..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11776
                                                                                                                                                                                                                                                          Entropy (8bit):4.862619033406922
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:0Ga+F/1NtJ9t4udqaj01rlALnNNJSS2sP+YEdMN+F9FdKaWDULk+VOmWbucX6gR7:PF/1n7Guqaj0ktfEON+bMDUlJcqg0Gd
                                                                                                                                                                                                                                                          MD5:19E0ABF76B274C12FF624A16713F4999
                                                                                                                                                                                                                                                          SHA1:A4B370F556B925F7126BF87F70263D1705C3A0DB
                                                                                                                                                                                                                                                          SHA-256:D9FDA05AE16C5387AB46DC728C6EDCE6A3D0A9E1ABDD7ACB8B32FC2A17BE6F13
                                                                                                                                                                                                                                                          SHA-512:D03033EA5CF37641FBD802EBEB5019CAEF33C9A78E01519FEA88F87E773DCA92C80B74BA80429B530694DAD0BFA3F043A7104234C7C961E18D48019D90277C8E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.g.:...:...:...3...>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...................PE..d...Y..f.........." ................P.....................................................`..........................................8.......8..d....`.......P..X............p..(....1...............................1..8............0...............................text............................... ..`.rdata.......0......................@..@.data...H....@.......$..............@....pdata..X....P.......&..............@..@.rsrc........`.......*..............@..@.reloc..(....p.......,..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):14336
                                                                                                                                                                                                                                                          Entropy (8bit):5.227045547076371
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:saF/1n7Guqaj0ktrE8o2o+V2rQnjt1wmg9jtveDn4clG6VcqgOvgdd:swGXkFE8Zo+AojO9jZeDf5rgOvgz
                                                                                                                                                                                                                                                          MD5:309D6F6B0DD022EBD9214F445CAC7BB9
                                                                                                                                                                                                                                                          SHA1:ABD22690B7AD77782CFC0D2393D0C038E16070B0
                                                                                                                                                                                                                                                          SHA-256:4FBE188C20FB578D4B66349D50AA6FFE4AB86844FB6427C57738F36780D1E2E2
                                                                                                                                                                                                                                                          SHA-512:D1951FE92F83E7774E8E877815BED6E6216D56EF18B7F1C369D678CB6E1814243659E9FA7ABC0D22FB5B34A9D50A51D5A89BA00AE1FDD32157FD0FF9902FB4B7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.g.:...:...:...3...>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...................PE..d...U..f.........." ................P.....................................................`..........................................8.......9..d....`.......P..@............p..(....2...............................2..8............0...............................text...x........................... ..`.rdata.......0....... ..............@..@.data...H....@......................@....pdata..@....P.......0..............@..@.rsrc........`.......4..............@..@.reloc..(....p.......6..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):13824
                                                                                                                                                                                                                                                          Entropy (8bit):5.176369829782773
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:rF/1n7Guqaj0ktrESsrUW+SBjsK5tcQmEreD2mf1AoxkVcqgOvgXQ:rGXkFE/UW575tA2eDp1Ao2rgOvgX
                                                                                                                                                                                                                                                          MD5:D54FEB9A270B212B0CCB1937C660678A
                                                                                                                                                                                                                                                          SHA1:224259E5B684C7AC8D79464E51503D302390C5C9
                                                                                                                                                                                                                                                          SHA-256:032B83F1003A796465255D9B246050A196488BAC1260F628913E536314AFDED4
                                                                                                                                                                                                                                                          SHA-512:29955A6569CA6D039B35BB40C56AEEB75FC765600525D0B469F72C97945970A428951BAB4AF9CD21B3161D5BBA932F853778E2674CA83B14F7ABA009FA53566F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.g.:...:...:...3...>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...................PE..d...U..f.........." ................P.....................................................`..........................................8.......9..d....`.......P..@............p..(....2...............................2..8............0...............................text...h........................... ..`.rdata.......0......................@..@.data...H....@.......,..............@....pdata..@....P......................@..@.rsrc........`.......2..............@..@.reloc..(....p.......4..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):14336
                                                                                                                                                                                                                                                          Entropy (8bit):5.047563322651927
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:6alCvH32p3/2pnEhKnLg9yH8puzoFaPERIQAvHD9CIg5kP:5CvHmp3OpnEhmLg9yH8puzoFaPERIQgI
                                                                                                                                                                                                                                                          MD5:52DCD4151A9177CF685BE4DF48EA9606
                                                                                                                                                                                                                                                          SHA1:F444A4A5CBAE9422B408420115F0D3FF973C9705
                                                                                                                                                                                                                                                          SHA-256:D54375DC0652358A6E4E744F1A0EAEEAD87ACCD391A20D6FF324FE14E988A122
                                                                                                                                                                                                                                                          SHA-512:64C54B89F2637759309ECC6655831C3A6755924ED70CBC51614061542EB9BA9A8AECF6951EB3AB92447247DC4D7D846C88F4957DBBE4484A9AB934343EE27178
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...Q..f.........." ......... ......P.....................................................`.........................................@9.......9..d....`.......P..(............p..(....2...............................2..8............0...............................text...X........................... ..`.rdata..@....0......................@..@.data...x....@......................@....pdata..(....P.......0..............@..@.rsrc........`.......4..............@..@.reloc..(....p.......6..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):13824
                                                                                                                                                                                                                                                          Entropy (8bit):5.09893680790018
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:xsiXeqVb0lwbH4P01sAD7I/9hAkwDWzBEbcqgqLg:valqH4M1sAD7KvpwDFtgqLg
                                                                                                                                                                                                                                                          MD5:F929B1A3997427191E07CF52AC883054
                                                                                                                                                                                                                                                          SHA1:C5EA5B68586C2FB09E5FDD20D4DD616D06F5CBA6
                                                                                                                                                                                                                                                          SHA-256:5386908173074FABD95BF269A9DF0A4E1B21C0576923186F449ABF4A820F6A8E
                                                                                                                                                                                                                                                          SHA-512:2C79DBCE2C21214D979AB86DD989D41A3AFA7FCB7F3B79BA9974E2EE8F832DD7CA20C1C87C0C380DB037D776FE6D0851D60AD55A08AFDE0003B7E59214DD2F3B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...R..f.........." ................P.....................................................`.........................................08.......8..d....`.......P..(............p..(....1...............................2..8............0...............................text............................... ..`.rdata..0....0......................@..@.data........@.......,..............@....pdata..(....P......................@..@.rsrc........`.......2..............@..@.reloc..(....p.......4..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):15360
                                                                                                                                                                                                                                                          Entropy (8bit):5.451865349855574
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:KfwogDHER1wuiDSyoGTgDZOviNgEPrLg:ugDHELwuiDScTgDwi+EP
                                                                                                                                                                                                                                                          MD5:1FA5E257A85D16E916E9C22984412871
                                                                                                                                                                                                                                                          SHA1:1AC8EE98AD0A715A1B40AD25D2E8007CDC19871F
                                                                                                                                                                                                                                                          SHA-256:D87A9B7CAD4C451D916B399B19298DC46AAACC085833C0793092641C00334B8E
                                                                                                                                                                                                                                                          SHA-512:E4205355B647C6E28B7E4722328F51DC2EB3A109E9D9B90F7C53D7A80A5A4B10E40ABDDAB1BA151E73EF3EB56941F843535663F42DCE264830E6E17BB659EADF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...R..f.........." ..... ..........P.....................................................`..........................................8......`9..d....`.......P..X............p..(....1...............................1..8............0...............................text............ .................. ..`.rdata.......0.......$..............@..@.data........@.......2..............@....pdata..X....P.......4..............@..@.rsrc........`.......8..............@..@.reloc..(....p.......:..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):13824
                                                                                                                                                                                                                                                          Entropy (8bit):5.104245335186531
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:3F/1n7Guqaj0kt7/Ev9kt0Qwac6QzD8iD0QocqgI4G0S:nGXkd/EvGt9wacNDvAgI4v
                                                                                                                                                                                                                                                          MD5:FAD578A026F280C1AE6F787B1FA30129
                                                                                                                                                                                                                                                          SHA1:9A3E93818A104314E172A304C3D117B6A66BEB55
                                                                                                                                                                                                                                                          SHA-256:74A1FF0801F4704158684267CD8E123F83FB6334FE522C1890AC4A0926F80AB1
                                                                                                                                                                                                                                                          SHA-512:ACF8F5B382F3B4C07386505BBDCAF625D13BCC10AA93ED641833E3548261B0AD1063E2F59BE2FCD2AFAF3D315CB3FC5EB629CEFC168B33CFD65A3A6F1120F7FF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.g.:...:...:...3...>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...................PE..d...U..f.........." ......... ......P.....................................................`..........................................9.......:..d....`.......P...............p..(...@3..............................`3..8............0...............................text...H........................... ..`.rdata.......0......................@..@.data...H....@.......,..............@....pdata.......P......................@..@.rsrc........`.......2..............@..@.reloc..(....p.......4..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):17920
                                                                                                                                                                                                                                                          Entropy (8bit):5.671305741258107
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:APHoDUntQj0sKhDOJ+0QPSfu6rofDjiZzgE+kbwb:VUOYsKNO466DjoUE+
                                                                                                                                                                                                                                                          MD5:556E6D0E5F8E4DA74C2780481105D543
                                                                                                                                                                                                                                                          SHA1:7A49CDEF738E9FE9CD6CD62B0F74EAD1A1774A33
                                                                                                                                                                                                                                                          SHA-256:247B0885CF83375211861F37B6DD1376AED5131D621EE0137A60FE7910E40F8B
                                                                                                                                                                                                                                                          SHA-512:28FA0CE6BDBCC5E95B80AADC284C12658EF0C2BE63421AF5627776A55050EE0EA0345E30A15B744FC2B2F5B1B1BBB61E4881F27F6E3E863EBAAEED1073F4CDA1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...R..f.........." .....*..........P.....................................................`..........................................H......hI..d....p.......`..X...............(....A...............................A..8............@...............................text....).......*.................. ..`.rdata.......@......................@..@.data........P.......<..............@....pdata..X....`.......>..............@..@.rsrc........p.......B..............@..@.reloc..(............D..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):21504
                                                                                                                                                                                                                                                          Entropy (8bit):5.878701941774916
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:EJWo4IRCGHX1KXqHGcvYHp5RYcARQOj4MSTjqgPmJD1OhgkxEv:EcIRnHX1P/YtswvaD1Rk
                                                                                                                                                                                                                                                          MD5:2F2655A7BBFE08D43013EDDA27E77904
                                                                                                                                                                                                                                                          SHA1:33D51B6C423E094BE3E34E5621E175329A0C0914
                                                                                                                                                                                                                                                          SHA-256:C734ABBD95EC120CB315C43021C0E1EB1BF2295AF9F1C24587334C3FCE4A5BE1
                                                                                                                                                                                                                                                          SHA-512:8AF99ACC969B0E560022F75A0CDCAA85D0BDEADADEACD59DD0C4500F94A5843EA0D4107789C1A613181B1F4E5252134A485EF6B1D9D83CDB5676C5FEE4D49B90
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...S..f.........." .....6... ......P.....................................................`.........................................@Z......([..d............p..................(....R...............................R..8............P...............................text....5.......6.................. ..`.rdata..x....P.......:..............@..@.data........`.......J..............@....pdata.......p.......L..............@..@.rsrc................P..............@..@.reloc..(............R..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):21504
                                                                                                                                                                                                                                                          Entropy (8bit):5.881781476285865
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:EJWo4IRCGHXfKXqHGcvYHp5RYcARQOj4MSTjqgPmJD12gkxEv:EcIRnHXfP/YtswvaD1zk
                                                                                                                                                                                                                                                          MD5:CDE035B8AB3D046B1CE37EEE7EE91FA0
                                                                                                                                                                                                                                                          SHA1:4298B62ED67C8D4F731D1B33E68D7DC9A58487FF
                                                                                                                                                                                                                                                          SHA-256:16BEA322D994A553B293A724B57293D57DA62BC7EAF41F287956B306C13FD972
                                                                                                                                                                                                                                                          SHA-512:C44FDEE5A210459CE4557351E56B2D357FD4937F8EC8EACEAB842FEE29761F66C2262FCBAAC837F39C859C67FA0E23D13E0F60B3AE59BE29EB9D8ABAB0A572BB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...S..f.........." .....6... ......P.....................................................`.........................................@Z......([..d............p..................(....R...............................R..8............P...............................text....5.......6.................. ..`.rdata..x....P.......:..............@..@.data........`.......J..............@....pdata.......p.......L..............@..@.rsrc................P..............@..@.reloc..(............R..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):26624
                                                                                                                                                                                                                                                          Entropy (8bit):5.837887867708438
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:e839Cc4itui0gel9soFdkO66MlPGXmXcyYDTzks:Ns4u/FZ6nPxMLDvk
                                                                                                                                                                                                                                                          MD5:999D431197D7E06A30E0810F1F910B9A
                                                                                                                                                                                                                                                          SHA1:9BFF781221BCFFD8E55485A08627EC2A37363C96
                                                                                                                                                                                                                                                          SHA-256:AB242B9C9FB662C6F7CB57F7648F33983D6FA3BB0683C5D4329EC2CC51E8C875
                                                                                                                                                                                                                                                          SHA-512:A5DD92DD471ADB44EEFE5919EF9CA3978724E21174DF5B3A9C1F0AB462F928E5A46A460D02417DB7522F5DE3BFEED5EEE6B1EAFAF3E621722E85E72675F7096F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...T..f.........." .....H..."......P.....................................................`..........................................k.......l..d...............................(...pd...............................d..8............`...............................text....F.......H.................. ..`.rdata.......`.......L..............@..@.data................^..............@....pdata...............`..............@..@.rsrc................d..............@..@.reloc..(............f..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):26624
                                                                                                                                                                                                                                                          Entropy (8bit):5.895310340516013
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:lcX9Nf4ttui0gel9soFdkO66MlPGXmXc/vDTOvk:a38u/FZ6nPxM3DAk
                                                                                                                                                                                                                                                          MD5:0931ABBF3AED459B1A2138B551B1D3BB
                                                                                                                                                                                                                                                          SHA1:9EC0296DDAF574A89766A2EC035FC30073863AB0
                                                                                                                                                                                                                                                          SHA-256:1729A0DC6B80CB7A3C07372B98B10D3C6C613EA645240878E1FDE6A992FA06F1
                                                                                                                                                                                                                                                          SHA-512:9F970BB4D10B94F525DDDDE307C7DA5E672BBFB3A3866A34B89B56ADA99476724FD690A4396857182749294F67F36DB471A048789FB715D2A7DAF46917FC1947
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...T..f.........." .....H..."......P.....................................................`.........................................@l......(m..d...............................(....d...............................e..8............`...............................text...hG.......H.................. ..`.rdata..x....`.......L..............@..@.data................^..............@....pdata...............`..............@..@.rsrc................d..............@..@.reloc..(............f..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):12800
                                                                                                                                                                                                                                                          Entropy (8bit):4.967737129255606
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:dMpWt/1nCuqaL0kt7TsEx2fiTgDZqGF0T7cqgkLgJ:k/k1Ts64DDJyBgkLg
                                                                                                                                                                                                                                                          MD5:5F057A380BACBA4EF59C0611549C0E02
                                                                                                                                                                                                                                                          SHA1:4B758D18372D71F0AA38075F073722A55B897F71
                                                                                                                                                                                                                                                          SHA-256:BCB14DAC6C87C24269D3E60C46B49EFFB1360F714C353318F5BBAA48C79EC290
                                                                                                                                                                                                                                                          SHA-512:E1C99E224745B86EE55822C1DBCB4555A11EC31B72D87B46514917EB61E0258A1C6D38C4F592969C17EB4F0F74DA04BCECA31CF1622720E95F0F20E9631792E8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......r^J.6?$.6?$.6?$.?G..2?$.dJ%.4?$.}G%.5?$.6?%..?$.dJ!.<?$.dJ .>?$.dJ'.5?$..J,.7?$..J$.7?$..J..7?$..J&.7?$.Rich6?$.........................PE..d...V..f.........." ................P.....................................................`.........................................P8.......8..d....`.......P...............p..(....1...............................1..8............0...............................text............................... ..`.rdata..2....0......................@..@.data...H....@.......(..............@....pdata.......P.......*..............@..@.rsrc........`......................@..@.reloc..(....p.......0..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):13312
                                                                                                                                                                                                                                                          Entropy (8bit):5.007867576025166
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:bMt/1nCuqaL0ktPH0T7fwtF4zDn2rGacqgRGd:1/kpU3Yv4zDXqgRGd
                                                                                                                                                                                                                                                          MD5:49BCA1B7DF076D1A550EE1B7ED3BD997
                                                                                                                                                                                                                                                          SHA1:47609C7102F5B1BCA16C6BAD4AE22CE0B8AEE9E9
                                                                                                                                                                                                                                                          SHA-256:49E15461DCB76690139E71E9359F7FCF92269DCCA78E3BFE9ACB90C6271080B2
                                                                                                                                                                                                                                                          SHA-512:8574D7FA133B72A4A8D1D7D9FDB61053BC88C2D238B7AC7D519BE19972B658C44EA1DE433885E3206927C75DD5D1028F74999E048AB73189585B87630F865466
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.:...:...:...3.j.>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...........................PE..d...V..f.........." ................P.....................................................`..........................................8.......8..d....`.......P..X............p..(....1...............................1..8............0...............................text............................... ..`.rdata.......0......................@..@.data...H....@.......*..............@....pdata..X....P.......,..............@..@.rsrc........`.......0..............@..@.reloc..(....p.......2..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):15872
                                                                                                                                                                                                                                                          Entropy (8bit):5.226023387740053
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:rfRKTN+HLjRskTdf4WazSTkwjEvuY2bylHDiYIgovg:mcHfRl5pauoSjy5DiE
                                                                                                                                                                                                                                                          MD5:CB5CFDD4241060E99118DEEC6C931CCC
                                                                                                                                                                                                                                                          SHA1:1E7FED96CF26C9F4730A4621CA9D18CECE3E0BCE
                                                                                                                                                                                                                                                          SHA-256:A8F809B6A417AF99B75EEEEA3ECD16BDA153CBDA4FFAB6E35CE1E8C884D899C4
                                                                                                                                                                                                                                                          SHA-512:8A89E3563C14B81353D251F9F019D8CBF07CB98F78452B8522413C7478A0D77B9ABF2134E4438145D6363CDA39721D2BAE8AD13D1CDACCBB5026619D95F931CF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...U..f.........." ..... ... ......P.....................................................`..........................................9.......9..d....`.......P..X............p..(...p2...............................2..8............0...............................text............ .................. ..`.rdata..@....0.......$..............@..@.data........@.......4..............@....pdata..X....P.......6..............@..@.rsrc........`.......:..............@..@.reloc..(....p.......<..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):14848
                                                                                                                                                                                                                                                          Entropy (8bit):5.262055670423592
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:C/ZN2eq/b04PAHH41F6fnVS0sVn+5CA5Z1cD66WGcqgFjLg:vI4IHHaQfSVnCZyDImgFjLg
                                                                                                                                                                                                                                                          MD5:18D2D96980802189B23893820714DA90
                                                                                                                                                                                                                                                          SHA1:5DEE494D25EB79038CBC2803163E2EF69E68274C
                                                                                                                                                                                                                                                          SHA-256:C2FD98C677436260ACB9147766258CB99780A007114AED37C87893DF1CF1A717
                                                                                                                                                                                                                                                          SHA-512:0317B65D8F292332C5457A6B15A77548BE5B2705F34BB8F4415046E3E778580ABD17B233E6CC2755C991247E0E65B27B5634465646715657B246483817CACEB7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...V..f.........." ................P.....................................................`..........................................8.......9..d....`.......P..|............p..(....1...............................1..8............0...............................text............................... ..`.rdata.......0......."..............@..@.data........@.......0..............@....pdata..|....P.......2..............@..@.rsrc........`.......6..............@..@.reloc..(....p.......8..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36352
                                                                                                                                                                                                                                                          Entropy (8bit):5.913843738203007
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:dspbXtHQY4ubrttQza9CHnZXQsnecAlOF0qZLAXxQI3Sya6XPpMg3Yx8MnDcCPSq:7Y44UagH6cAFCLUSYpMg3YDzPo5kG9G
                                                                                                                                                                                                                                                          MD5:EF472BA63FD22922CA704B1E7B95A29E
                                                                                                                                                                                                                                                          SHA1:700B68E7EF95514D5E94D3C6B10884E1E187ACD8
                                                                                                                                                                                                                                                          SHA-256:66EEF4E6E0CEEEF2C23A758BFBEDAE7C16282FC93D0A56ACAFC40E871AC3F01C
                                                                                                                                                                                                                                                          SHA-512:DC2060531C4153C43ABF30843BCB5F8FA082345CA1BB57F9AC8695EDDB28FF9FDA8132B6B6C67260F779D95FCADCAE2811091BCA300AB1E041FAE6CC7B50ABD8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......:..P~...~...~...w.3.x...,...|...5...}...~...U...,...u...,...v...,...}.......|............._.............Rich~...................PE..d...^..f.........." .....`...0......`.....................................................`..........................................~..|...L...d...............<...............(....q...............................q..8............p..(............................text...X^.......`.................. ..`.rdata.......p.......d..............@..@.data................x..............@....pdata..<...........................@..@.rsrc...............................@..@.reloc..(...........................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):12288
                                                                                                                                                                                                                                                          Entropy (8bit):4.735350805948923
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:rhsC3eqv6b0q3OQ3rHu5bc64OhD2I/p3cqgONLg:r/Hq3jHuY64OhDJJgONLg
                                                                                                                                                                                                                                                          MD5:3B1CE70B0193B02C437678F13A335932
                                                                                                                                                                                                                                                          SHA1:063BFD5A32441ED883409AAD17285CE405977D1F
                                                                                                                                                                                                                                                          SHA-256:EB2950B6A2185E87C5318B55132DFE5774A5A579259AB50A7935A7FB143EA7B1
                                                                                                                                                                                                                                                          SHA-512:0E02187F17DFCFD323F2F0E62FBFE35F326DCF9F119FC8B15066AFAEEE4EB7078184BC85D571B555E9E67A2DD909EC12D8A67E3D075E9B1283813EF274E05C0D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......r^:.6?T.6?T.6?T.?G..2?T.dJU.4?T.}GU.5?T.6?U..?T.dJQ.<?T.dJP.>?T.dJW.5?T..J\.7?T..JT.7?T..J..7?T..JV.7?T.Rich6?T.........................PE..d...Z..f.........." ................P.....................................................`..........................................8..d....8..d....`.......P..4............p..(....1...............................1..8............0...............................text...H........................... ..`.rdata..0....0......................@..@.data........@.......&..............@....pdata..4....P.......(..............@..@.rsrc........`.......,..............@..@.reloc..(....p......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):22528
                                                                                                                                                                                                                                                          Entropy (8bit):5.705606408072877
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:19BcRxBmau38CYIl9bhgIW0mvufueNr359/tjGGDEFSegqrA:NcRy38J+9dmvufFtaGDV
                                                                                                                                                                                                                                                          MD5:FF33C306434DEC51D39C7BF1663E25DA
                                                                                                                                                                                                                                                          SHA1:665FCF47501F1481534597C1EAC2A52886EF0526
                                                                                                                                                                                                                                                          SHA-256:D0E3B6A2D0E073B2D9F0FCDB051727007943A17A4CA966D75EBA37BECDBA6152
                                                                                                                                                                                                                                                          SHA-512:66A909DC9C3B7BD4050AA507CD89B0B3A661C85D33C881522EC9568744953B698722C1CBFF093F9CBCD6119BD527FECAB05A67F2E32EC479BE47AFFA4377362C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.g.:...:...:...3...>...h...8...q...9...:.......h...1...h...2...h...9.......;.......;.......;.......;...Rich:...................PE..d...\..f.........." .....6...$......P.....................................................`.........................................`Y......`Z..d............p..................(....R..............................0R..8............P...............................text...(5.......6.................. ..`.rdata.......P.......:..............@..@.data........`.......J..............@....pdata.......p.......P..............@..@.rsrc................T..............@..@.reloc..(............V..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):70656
                                                                                                                                                                                                                                                          Entropy (8bit):6.0189903352673655
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:Jfju4GgRMgWWnEDZiECgd/iwOXUQdbhov0Clb8Cx4hpK8ithLFIDullRPwDHxXOa:pXRMgWiEDZiECgd/iwOXUQdbhov0ClbU
                                                                                                                                                                                                                                                          MD5:F267BF4256F4105DAD0D3E59023011ED
                                                                                                                                                                                                                                                          SHA1:9BC6CA0F375CE49D5787C909D290C07302F58DA6
                                                                                                                                                                                                                                                          SHA-256:1DDE8BE64164FF96B2BAB88291042EB39197D118422BEE56EB2846E7A2D2F010
                                                                                                                                                                                                                                                          SHA-512:A335AF4DBF1658556ED5DC13EE741419446F7DAEC6BD2688B626A803FA5DD76463D6367C224E0B79B17193735E2C74BA417C26822DAEEF05AC3BAB1588E2DE83
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......:..P~...~...~...w.3.x...,...|...5...}...~...U...,...u...,...v...,...}.......|............._.............Rich~...................PE..d...\..f.........." .........8......`........................................P............`.............................................0.......d....0....... ..$............@..(.......................................8............................................text...8........................... ..`.rdata..............................@..@.data...............................@....pdata..$.... ......................@..@.rsrc........0......................@..@.reloc..(....@......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):770560
                                                                                                                                                                                                                                                          Entropy (8bit):7.613224993327352
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:XtIrHoxJ8gf1266y8IXhJvCKAmqVLzcrZgYIMGv1iLD9yQvG6h:XtIrHoxJFf1p34hcrn5Go9yQO6
                                                                                                                                                                                                                                                          MD5:1EFD7F7CB1C277416011DE6F09C355AF
                                                                                                                                                                                                                                                          SHA1:C0F97652AC2703C325AB9F20826A6F84C63532F2
                                                                                                                                                                                                                                                          SHA-256:AB45FA80A68DB1635D41DC1A4AAD980E6716DAC8C1778CB5F30CDB013B7DF6E6
                                                                                                                                                                                                                                                          SHA-512:2EC4B88A1957733043BBD63CEAA6F5643D446DB607B3267FAD1EC611E6B0AF697056598AAC2AE5D44AB2B9396811D183C32BCE5A0FF34E583193A417D1C5226B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........s.. .. .. ... .. ..!.. ..!.. .. .. ..!.. ..!.. ..!.. \..!.. \..!.. \.r .. \..!.. Rich.. ................PE..d...[..f.........." ................`.....................................................`.............................................h.......d...............................0......................................8...............(............................text............................... ..`.rdata..............................@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..0...........................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):26112
                                                                                                                                                                                                                                                          Entropy (8bit):5.8551858881598795
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:BczadRwoF2MZ81n0XTyMCYIl9bhgIW0mv8aeadRcwRwftjGLD2pRQNgQQ77k:2udRf2MuMJ+9dmv8aea34taLDcfQ
                                                                                                                                                                                                                                                          MD5:C5FB377F736ED731B5578F57BB765F7A
                                                                                                                                                                                                                                                          SHA1:5BA51E11F4DE1CAEDEBA0F7D4D10EC62EC109E01
                                                                                                                                                                                                                                                          SHA-256:32073DF3D5C85ABCE7D370D6E341EF163A8350F6A9EDC775C39A23856CCFDD53
                                                                                                                                                                                                                                                          SHA-512:D361BCDAF2C700D5A4AC956D96E00961432C05A1B692FC870DB53A90F233A6D24AA0C3BE99E40BD8E5B7C6C1B2BCDCDCFC545292EF321486FFC71C5EA7203E6A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.G.:.).:.).:.).3...>.).h.(.8.).q.(.9.).:.(...).h.,.1.).h.-.2.).h.*.9.)...!.;.)...).;.).....;.)...+.;.).Rich:.).........................PE..d...]..f.........." .....B...&......P.....................................................`..........................................i..0....k..d...............................(... b..............................@b..8............`...............................text....A.......B.................. ..`.rdata..P....`.......F..............@..@.data........p.......V..............@....pdata...............^..............@..@.rsrc................b..............@..@.reloc..(............d..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):84992
                                                                                                                                                                                                                                                          Entropy (8bit):6.064677498000638
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:BrYNvxcZeLrIeNs2qkTwe57DsuP45PqAqVDK9agdUiwOXyQdDrov0slb8gx4TBKW:Br4vxcZeLrIeN1TvHsuP45yAqVDK9ag3
                                                                                                                                                                                                                                                          MD5:8A0C0AA820E98E83AC9B665A9FD19EAF
                                                                                                                                                                                                                                                          SHA1:6BF5A14E94D81A55A164339F60927D5BF1BAD5C4
                                                                                                                                                                                                                                                          SHA-256:4EE3D122DCFFE78E6E7E76EE04C38D3DC6A066E522EE9F7AF34A09649A3628B1
                                                                                                                                                                                                                                                          SHA-512:52496AE7439458DEDB58A65DF9FFDCC3A7F31FC36FE7202FB43570F9BB03ABC0565F5EF32E5E6C048ED3EBC33018C19712E58FF43806119B2FB5918612299E7E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......:..P~...~...~...w.3.x...,...|...5...}...~...U...,...u...,...v...,...}.......|............._.............Rich~...................PE..d...^..f.........." .........8......`.....................................................`..........................................C..h...HE..d....p.......`..l...............(....1...............................1..8............0...............................text............................... ..`.rdata.......0......................@..@.data........P.......4..............@....pdata..l....`.......>..............@..@.rsrc........p.......H..............@..@.reloc..(............J..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):15297
                                                                                                                                                                                                                                                          Entropy (8bit):4.708378368926237
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:hmv1gdEYEiNrVhTBvAn1ca1f5lwHoJr0vwuxqsP/5jxA:o1gdEvgbloCof9ixqspW
                                                                                                                                                                                                                                                          MD5:ED228F0F60AE9AEC28AB9171D5AE9590
                                                                                                                                                                                                                                                          SHA1:7F061CF0C699D125A5531E3480C21964452F45EA
                                                                                                                                                                                                                                                          SHA-256:4AC56FC63E400943BAB13F1D4C418502138908E1D488C24AEE6131D3D17552AA
                                                                                                                                                                                                                                                          SHA-512:794CC671C08BFC50980820A6389B9D0D3514619AD0A8F18EFD5554CBBF2482192DF00B9D3B05FEE45F42276E63E2375FB28E193930D426245035B4B0E3E14ED8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......cs_CZB...H.(.......(.......0T......0T......5w...0..Uj......`.......a[......a[....$.......p..........t.......t...........!..1"....T.39....T.39.......s...0......(......7/.................B<s...L..MQ......M^../q..........J..6@.0....*B.O5Q..'..O5^..(A..)Q...X..)^......o>..........+....J..6.......4....t.....8dz..5..D ....R.D ......k.A.....k.A.....k.N.....k.N.......n.."....I..........................2...21......2>..........d.............T..G...4...w...!N......&O......&....!..".......#E..,...,.......)....Q..$/...^..$................$a......6.>.. t......5...K.......K....)......5E.W.b..-.._Xa..%a._Xn..%...GA......GN...?......,9..~.......TH..3..!....*..K.H..4h.........pA...J..pN..........7..P.~.. ..o.....0..(....*..(..........3V..~....T.s.1.....s.>..._.o....0..o....1p.z.q..........'9.....#........^.........h....2................Z..e... .i..8J......(.D.o.v.o.d.e.m. .p.r.o. .t.o. .b.y. .m.o.h.l.o. .b...t.,. .~.e. .d.o.k.u.m.e.n.t.a.c.e. .j.e. .s.t...l.e. .j.e.a.t...
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4795
                                                                                                                                                                                                                                                          Entropy (8bit):4.530246422531362
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:X82wNlnKfN1LMFy7LsF3ZqBFZjWo0koBLqBXXjGL0qU7UqB7zoElmP5MUu4DZIHU:XM01f7eOnoB8X2s7Vfg5Mi4beXiOUu
                                                                                                                                                                                                                                                          MD5:1D09BEE1FB55A173F7EB39B9A662A170
                                                                                                                                                                                                                                                          SHA1:C77F0A148262A91679F19689E4790B754D45D5D5
                                                                                                                                                                                                                                                          SHA-256:6BB092552A398687119F6D52145F04BF8373977446D8F00C0DCBD56B96829F0F
                                                                                                                                                                                                                                                          SHA-512:BE5A31A6135E8DB024A8B0EB20C4D8EECBF76861F83FF83B4CA97327DB74AD94BB5D77B4E0A59A33B697C32A4EACD61B8C878951F2C545385C74D99FCE56FEE1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......daB.....%.....m.0T......Uj....V.`....................k.B<s.....B\>..........6.+.s...............t.....D ....|.k.N...9...I...O..2.......G....B...N...O..............!..K...._..........GN...........@.K.H.............pN..............>.....~.....m..%c.....z.q....i..........U.n.a.v.n.g.i.v.e.t..........Untitled.....QHelp.....D.K.a.n. .i.k.k.e. .k.o.p.i.e.r.e. .s.a.m.l.i.n.g.s.f.i.l.e.n.:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....6.K.a.n. .i.k.k.e. .o.p.r.e.t.t.e. .m.a.p.p.e.n.:. .%.1..........Cannot create directory: %1.....QHelpCollectionHandler.....V.K.a.n. .i.k.k.e. .o.p.r.e.t.t.e. .i.n.d.e.k.s.t.a.b.e.l.l.e.r. .i. .f.i.l.e.n. .%.1...........&Cannot create index tables in file %1......QHelpCollectionHandler.....J.K.a.n. .i.k.k.e. .o.p.r.e.t.t.e. .t.a.b.e.l.l.e.r. .i. .f.i.l.e.n. .%.1........... Cannot create tables in file %1......QHelpCollectionHandler.....P.K.a.n. .i.k.k.e. .i.n.d.l...s.e. .s.q.l.i.t.e.-.d.a.t.a.b.a.s.e.-.d.r
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7570
                                                                                                                                                                                                                                                          Entropy (8bit):4.550982634910665
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:8y/gPmmhL/7LlSivP6kBL7jb0RNUzzpld4UGG3Ik18fLP0L7fGc0OeVP8a8hiAwj:1OD7hx/Bv3oNuFX4iqgv34fZsu
                                                                                                                                                                                                                                                          MD5:3B070D169E3381E2FB081172934AAD00
                                                                                                                                                                                                                                                          SHA1:70886EB7EF566B296D0814BD4C2440AC176699D6
                                                                                                                                                                                                                                                          SHA-256:9962523FBAE9F1E4C3B5C3C16860D059291CB30DC5EBE5A5EDA4C836A03FED1E
                                                                                                                                                                                                                                                          SHA-512:271B730B5A7358E923BBBC6FA074A72DA52FA47E3B7726779EF7034200EDA09BF0E1AE4E7B11B59F76805F48DC285F6EFC245EB9C7F4A748BE82B25CEE1DDCAE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......deB..........B.%.....5.0T......K:^.....Uj....?.`.....f..YJ...V.E.4...............>............B<s...z.B\>...\........+.s...Q.zq....C..9....4..vR...B..@.......@.......:......8Z......g.N......F....>...........t.....D ......k.N.......I......^....|.`#....I..2....<..G....^...N.........................;..........K....y..........GN......NO...........,.K.H.............pN......V...................."..........>.............~........%c.....z.q....i........".F.i.l.t.e.r. .h.i.n.z.u.f...g.e.n..........Add Filter.....FilterNameDialogClass.....".N.a.m.e. .d.e.s. .F.i.l.t.e.r.s.:..........Filter Name:.....FilterNameDialogClass.......O.h.n.e. .T.i.t.e.l..........Untitled.....QHelp.....\.D.i.e. .K.a.t.a.l.o.g.d.a.t.e.i. .k.a.n.n. .n.i.c.h.t. .k.o.p.i.e.r.t. .w.e.r.d.e.n.:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....\.D.a.s. .V.e.r.z.e.i.c.h.n.i.s. .k.a.n.n. .n.i.c.h.t. .a.n.g.e.l.e.g.t. .w.e.r.d.e.n.:. .%.1..........Cannot create directory: %
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):16
                                                                                                                                                                                                                                                          Entropy (8bit):4.0
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4n:CwZ
                                                                                                                                                                                                                                                          MD5:BCEBCF42735C6849BDECBB77451021DD
                                                                                                                                                                                                                                                          SHA1:4884FD9AF6890647B7AF1AEFA57F38CCA49AD899
                                                                                                                                                                                                                                                          SHA-256:9959B510B15D18937848AD13007E30459D2E993C67E564BADBFC18F935695C85
                                                                                                                                                                                                                                                          SHA-512:F951B511FFB1A6B94B1BCAE9DF26B41B2FF829560583D7C83E70279D1B5304BDE299B3679D863CAD6BB79D0BEDA524FC195B7F054ECF11D2090037526B451B78
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`...
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10704
                                                                                                                                                                                                                                                          Entropy (8bit):4.481291573289571
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:q9J9j7e4BQhD0h61nnKz+DJF/45ojDU9V1Wa/rmtIBMH:Wp64ShDnnKz+FhjQpWa/ytoMH
                                                                                                                                                                                                                                                          MD5:9EDF433AB9EE5FC7CF7782370150B26A
                                                                                                                                                                                                                                                          SHA1:A918AE15A0DF187C7789BE8599A80E279F039964
                                                                                                                                                                                                                                                          SHA-256:FD16B279F8CF69077F75E94D90C9C07A2AFFF3948A579E3789F5FFB5E5F4202D
                                                                                                                                                                                                                                                          SHA-512:88245F6FBAAF603A03D7EA2341411AE040791D47C9FF110C6D6CDD8165F0A8BA7A4A0DA5CD543BBE95A4E93FE3A81E95B3664E00C11791FBCB4923E3A80ABC60
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......es_ESB...(.(.....7.0T..../.5w... C.Uj......`.......a[....0..........t..............39..........&e.........B<s...D..M^..............J..%p.O5^...I..)^...1..o>.......J..%.......#....t.....8dz..$..D ......k.N.....k.N.......n.......I..............2>....................G...#...w............!.......%..,................^............$a......6.>..........#...K...........$C.W.b....._Xn......GN...|..~.......TH.."..!.....5.K.H..#f.........pN...j......'..P.~... .o........(....>....."<..~....c.s.>.....o.... ..z.q..........................u.h....!p.......*..e....Qi..'}......(.L.a. .r.a.z...n. .d.e. .e.s.t.o. .p.u.e.d.e. .s.e.r. .q.u.e. .l.a. .d.o.c.u.m.e.n.t.a.c.i...n. .a...n. .e.s.t... .s.i.e.n.d.o. .i.n.d.e.x.a.d.a...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......N.o.t.a.:..........Note:.....QCLuceneResultWidget.....2.R.e.s.u.l.t.a.d.o.s. .d.e. .l.a. .B...s.q.u.e.d.a..........Search Results.....QCLu
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10922
                                                                                                                                                                                                                                                          Entropy (8bit):4.459946393010639
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:w4BIn67/WsmoB3r6M/eYlSbyE7DnvE7pcn9nPJZe7nOFovzcNn7Uhmio+2/p53I/:w4N19fq3n2c9Bucuhmi52/X3Qpam
                                                                                                                                                                                                                                                          MD5:D520C7F85CC06C66715A2B6622BF0687
                                                                                                                                                                                                                                                          SHA1:47292D068172FBC9DC0D9BE2F479E890A37CE138
                                                                                                                                                                                                                                                          SHA-256:687E351C062F688AAFF6CF05218D6017B80B1A1B4238D1D30250A55EE41C5FED
                                                                                                                                                                                                                                                          SHA-512:736B50BB64751B127300BCAFE88888A9D9A2081CBF934EDCFFEF6CEF0575505AFDF714273A97671ABB598AE3D23C8E55F7DCD632FB0AA219ED5F763768576E04
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......fr_FRB...(.(.....y.0T....K.5w...!1.Uj....*.`.......a[............5..t..............39....m.....'W.......S.B<s...d..M^.. ...........J..&`.O5^...+..)^......o>.......J..&.......$....t.....8dz..%..D ......k.N.....k.N...D...n.......I...........c..2>..........M.........G...$...w....K..................,................^............$a......6.>...c......$...K....'......%M.W.b....._Xn...j..GN......~.......TH..#..!.......K.H..$Z......,..pN..........'..P.~.....o........(....h.....#4..~......s.>...M.o....!..z.q...........p......L.........h...."^.......b..e.....i..(W......(.I.l. .e.s.t. .p.o.s.s.i.b.l.e. .q.u.e. .c.e.l.a. .s.o.i.t. .d... .a.u. .f.a.i.t. .q.u.e. .l.a. .d.o.c.u.m.e.n.t.a.t.i.o.n. .e.s.t. .e.n. .c.o.u.r.s. .d.'.i.n.d.e.x.a.t.i.o.n...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......N.o.t.e. .:..........Note:.....QCLuceneResultWidget.....2.R...s.u.l.t.a.t.s. .d.e. .l.a. .r.e.c.h.e.r.c.h.e.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10891
                                                                                                                                                                                                                                                          Entropy (8bit):4.5087667371046205
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:Im7gBZHx4hCTNarW6EJDvoIR765f40wqNcMi/8F/Ihon:v0fHccarW6Eh61wqNcMi/Q/won
                                                                                                                                                                                                                                                          MD5:B62C74793741FC386332A59113E8D412
                                                                                                                                                                                                                                                          SHA1:589CE099F2C1D92581B5CF0E17BE49A2BF0014D4
                                                                                                                                                                                                                                                          SHA-256:7399A248609974773F60866C87B78EA7DFBC4F750313D692F7886CD763883C9F
                                                                                                                                                                                                                                                          SHA-512:D8E1A3B3732662BA572A1387651F2625742710834BEDB41809DA47B5D23020AA1B558B64A00C10C605D1844F0544483163F4A6227CAFFA5ECDABF3BBF4E12D9B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......gl_ESB...8.(.......0T......Uj......`.....`.a[....F..........t..............1"... S.39.......s...!.............'F.........B<s...8..MQ.. ...........J..&S.0.....x.O5Q......)Q...O..o>...{.......#...J..&.......$....t.....8dz..%..D ......k.A.....k.A.......n.......I.................."...21....................G...#...w............[...!...?...........Q...?........$a....v.6.>..........$...K...........%0._Xa......GA...n..........~.......TH..#..K.H..$M.........pA...Z......'..P.~...B.o........(..........#+..~......s.1.....o....!..z.q...e.............................. ..e....wi..((......(.A. .r.a.z...n. .d.i.s.t.o. .p.o.d.e. .s.e.r. .q.u.e. .a. .d.o.c.u.m.e.n.t.a.c.i...n. .a...n.d.a. .e.s.t.e.a. .a. .i.n.d.e.x.a.r.s.e...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......N.o.t.a.:..........Note:.....QCLuceneResultWidget.....*.R.e.s.u.l.t.a.d.o.s. .d.a. .p.r.o.c.u.r.a..........Search Results.....QCLucene
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10284
                                                                                                                                                                                                                                                          Entropy (8bit):4.674501432335502
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:RNY+rCG3e7LBqYqYseBb/FEWBgSn62TdJgDO9esYGY3DtgGh621XlZ/8kWvIMK:4+rheHYYZdBb/pgSn62T/FeVD3DGGh62
                                                                                                                                                                                                                                                          MD5:5A56E9E2ED6ECE3F249D1C2A7EB3B172
                                                                                                                                                                                                                                                          SHA1:D6F079F40FBB813B0293C1D2210BAE7084092FEC
                                                                                                                                                                                                                                                          SHA-256:70F33B569C2942F41C6D634EA6A61CB8D80EB2C7011BAD48EF6DBAE9677960D5
                                                                                                                                                                                                                                                          SHA-512:28947128FC51791CFDBFD3958FAF9B33979DB52C90AE0159EDB01FE6032284EB37BC05187162983A0435560BCEA864B008F499CDB4CE662792599FE20A37972A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......hu_HUB...(.(.......0T......5w......Uj......`.....4.a[....N..........t....".........39..........%..........B<s...8..M^...8..........J..$..O5^......)^...]..o>.......J..$......."N...t.....8dz..#g.D ......k.N...>.k.N.......n.......I..............2>..........a.........G...!...w.......................,................^............$a......6.>.........."...K....m......"..W.b...l._Xn...~..GN......~.......TH..!F.!.......K.H..!..........pN..........%..P.~...<.o........(.......... ...~......s.>...{.o.....c.z.q...K.......v......l.........h.... ........t..e....mi..%.....~.(.E.z. .a.m.i.a.t.t. .l.e.h.e.t.,. .h.o.g.y. .a. .d.o.k.u.m.e.n.t...c.i... .m...g. .i.n.d.e.x.e.l...s. .a.l.a.t.t. .v.a.n...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......M.e.g.j.e.g.y.z...s.:..........Note:.....QCLuceneResultWidget.....&.K.e.r.e.s...s.i. .e.r.e.d.m...n.y.e.k..........Search Results.....QCLuceneResultWidget.......A
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10612
                                                                                                                                                                                                                                                          Entropy (8bit):4.458970627057882
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:nRxcfy71b+myBN16cbc+w45rtlTnzo7uHp3JQJ9cVu4BJ1G82g33vOVrNL/7nEF1:RR4R/fJn9JizTgnqrNL/b0hH2K
                                                                                                                                                                                                                                                          MD5:3639B57B463987F6DB07629253ACD8BF
                                                                                                                                                                                                                                                          SHA1:65935A67C73F19FCF6023FB95030A5ACAF9DA21C
                                                                                                                                                                                                                                                          SHA-256:316FE8D0815E2B4B396895BEB38EF1A40431915B5E054DF80F4C0CD556F26E4B
                                                                                                                                                                                                                                                          SHA-512:AD7CA93D93A69F273CE80BE7F2F477543B9C5F9C7E4D7448223BFF084EA956B626D6837F22D83C5E282688B938F58C29073C4B5C6F26A797F716C14FABF9FFEE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......it_ITB...(.(.....g.0T....y.5w... ..Uj....2.`.......a[............'..t..............39..........&..........B<s...j..M^...h......K...J..%..O5^...K..)^......o>...u...J..%.......#....t.....8dz..$..D ......k.N.....k.N.......n.......I..............2>.................o..G..."...w............-......./..,................^...'........$a......6.>..........#...K...........$..W.b....._Xn......GN......~.......TH.."n.!.....5.K.H..#"......>..pN..........&..P.~.....o.....~..(....p.....!...~....A.s.>.....o.... ..z.q..........................q.h....!0.......*..e....;i..'!......(.L.a. .c.a.u.s.a. .d.i. .c.i... .p.o.t.r.e.b.b.e. .e.s.s.e.r.e. .c.h.e. .l.'.i.n.d.i.c.i.z.z.a.z.i.o.n.e. .d.e.l.l.a. .d.o.c.u.m.e.n.t.a.z.i.o.n.e. ... .a.n.c.o.r.a. .i.n. .c.o.r.s.o...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......N.o.t.a.:..........Note:.....QCLuceneResultWidget.......R.i.s.u.l.t.a.t.i. .d.e.l.l.a. .r.i.c.e.r.c.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7917
                                                                                                                                                                                                                                                          Entropy (8bit):5.680408580146589
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:mP6J37GcBzRjYEPEJJGTnwfJJxb7FTPjzzZBL3/q/I53:mSVqclR5s6Tnwfb7Pj/PL3/q/w3
                                                                                                                                                                                                                                                          MD5:1380A9352C476071BDA5A5D4FED0B6C5
                                                                                                                                                                                                                                                          SHA1:9B737ED05F80FE5D3CD8F588CCEC16BB11DD3560
                                                                                                                                                                                                                                                          SHA-256:AE603B2C0D434D40CDE433FFCBA65F9EE27978A9E19316007BE7FE782A5B8B47
                                                                                                                                                                                                                                                          SHA-512:EC3D68126488C3A163898BACAF7E783217868573635182CAF511ED046B4BE1F99A71FBB24DA607CCB50EDAF70893007AAEE9A6BAAE4C1CD33465A0915AA965DA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......jaB...(.(.....S.0T......5w....'.Uj......`.......a[............u..t............!.39.....................B<s......M^..............J...>.O5^...O..)^......o>.......J...............t...w.8dz.....D ......k.N.....k.N...H...n.......I...........i..2>...<......G......9..G....P..w............i..........,................^..........'.$a......6.>...5..........K............S.W.b...2._Xn......GN...@..~.......TH.....!.......K.H.............pN...........S.P.~.....o.....|..(..............~....o.s.>.....o.......z.q..................@.........h.....&....... ..e.....i........@.(0.0.0.0.0.0.0n}"_.0nO\b.0L}BN.0W0f0D0j0D0_0.0K0.0W0.0~0[0.0..).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget......l..:..........Note:.....QCLuceneResultWidget......i.}"}Pg...........Search Results.....QCLuceneResultWidget.....R0.0.0.0.0.0.0n}"_.0nO\b.0L}BN.0W0f0D0j0D0_0.0.i.}"}Pg.0LN.[.Qh0jS..`'0L0B0.0~0Y0..........VThe search results may
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5708
                                                                                                                                                                                                                                                          Entropy (8bit):5.698914195742074
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:elPQHJ6L4c7LaQaFQv2QEhBL+Ejma0W40U0BzlQlcrnUSaTIdspIc18CLRSM3LBY:dHI97W1BbNz1VqqzJpoj5y5uY7OGrWFE
                                                                                                                                                                                                                                                          MD5:CD15674A652C2BF435F7578E119182F8
                                                                                                                                                                                                                                                          SHA1:AEA22E4A0D21396733802C7AB738DDD03737B7D6
                                                                                                                                                                                                                                                          SHA-256:F11C64694E8E34E1D2C46C1A1D15D6BA9F2DB7B61DE4FDF54ECA5AB977C3E052
                                                                                                                                                                                                                                                          SHA-512:88BFA112F4DBC0BFB4013CE0937E5180B4AB4A217FC8A963798C7C86532E794E4A1AD88416AE42F26A1C0631B465A5D69BFE75366E048502F5E21F4115A12F19
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......koB............%.......0T......K:^...g.Uj......`........YJ...>.E.4...........z...>..........;.B<s...K.B\>...b........+.s.....zq....[..9....F..vR......@.......@.......:....c.8Z......g.N...7..F....|...........t.....D ......k.N.......I...m..^......`#....!..2.......G....@...N.................................X..K....{.......i..GN......NO.............K.H..........S..pN...z..V...............................>...........:.~.....i..%c.....z.q....i...s......D.0. .............Add Filter.....FilterNameDialogClass.......D.0. .t...:..........Filter Name:.....FilterNameDialogClass........... ...L..........Untitled.....QHelp.....(...L... ...|.D. .....`. ... ...L.:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....".....0...|. .... ... ...L.:. .%.1..........Cannot create directory: %1.....QHelpCollectionHandler.....2...|. .%.1... ...x. .L.t...D. .... ... .................&Cannot create index tables in file %1......QHelpCollectionHandler.....,.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9673
                                                                                                                                                                                                                                                          Entropy (8bit):4.622652249027856
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:TO/7kBL9wGu3wtCnlhLJUBB7oph+mZ18LgP:T8QnwcCnlhdvphpZ18LgP
                                                                                                                                                                                                                                                          MD5:2B68446B69D9AA40B273D75A581D2992
                                                                                                                                                                                                                                                          SHA1:8A09BD38998543B74E2673478EDD54FB4BBDD068
                                                                                                                                                                                                                                                          SHA-256:CC6CB4D8C54086224672F2E49E623C8CB7C0C1CD65B8D5ECD42FC9BA3A6065BD
                                                                                                                                                                                                                                                          SHA-512:F3A3D6A416B3411613B06FC3EE56625D4D4DE80087182AB0D0601E49314861ABEF97D11A15B4C0511911544A59FBC4A4A52F0CCF0FD43F763A76A8922D8E57B6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......plB.....(.......0T....T.5w......Uj... R.`.......a[...............t............2.39....H......6.......n.B<s.. ...M^..._......6.O5^...F..)^......o>...............t.....D ......k.N.....k.N.../...n.......I...W..........2>...w................G.......w............&.......:..,................^...(..... ..$a....?.6.>...$..........K......W.b....._Xn......GN...Y..~......!.....*.K.H...E....."...pN...-.........P.~...}.o........(....1..~......s.>......%c.."..o.....r.z.q............................h................e.....i..#.......N.i.e.n.a.z.w.a.n.y..........Untitled.....QHelp.....P.N.i.e. .m.o.|.n.a. .s.k.o.p.i.o.w.a... .p.l.i.k.u. .z. .k.o.l.e.k.c.j...:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....>.N.i.e. .m.o.|.n.a. .u.t.w.o.r.z.y... .k.a.t.a.l.o.g.u.:. .%.1..........Cannot create directory: %1.....QHelpCollectionHandler.....H.N.i.e. .m.o.|.n.a. .u.t.w.o.r.z.y... .t.a.b.e.l. .w. .p.l.i.k.u. .%.1........... Cannot create tables in file
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7288
                                                                                                                                                                                                                                                          Entropy (8bit):5.297177914619657
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:dBJjvfq7D6X68uBAzlp5W9+yBPZZZMM7vL0PXJL:JKrMEL0PXJL
                                                                                                                                                                                                                                                          MD5:794AF445A5D7082D51BD22683449F86D
                                                                                                                                                                                                                                                          SHA1:3A0C369872B112A1572AA17EEB814B168B225D98
                                                                                                                                                                                                                                                          SHA-256:557B644E6DA5F1EC720EF93965617087E4D1F40B2494CC5AA524CF3796108DE7
                                                                                                                                                                                                                                                          SHA-512:D42C870A16AEE7626BBE24886AD423895529A2F1A51AC2DBC303BC0E4EF9D3241FE894ECA3F7217AD408C8DCEE165CA4B89D84570357B0EB80340A3F72B0A846
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......ruB..........\.%.......0T......K:^.....Uj....L.`........YJ...X.E.4...............>............B<s.....B\>............+.s.....zq.......9....B..vR...L..@.......@....G..:......8Z......g.N......F....>...........t.....D ....R.k.N...E...I...W..^......`#....s..2.......G....^...N.........................K.......d..K............O..GN...b..NO.............K.H.............pN...P..V....................g..........>.............~........%c.....z.q....i........$...>.1.0.2.;.5.=.8.5. .D.8.;.L.B.@.0..........Add Filter.....FilterNameDialogClass.........<.O. .D.8.;.L.B.@.0.:..........Filter Name:.....FilterNameDialogClass.........5.7.K.<.O.=.=.K.9..........Untitled.....QHelp.....b...5. .C.4.0.;.>.A.L. .A.:.>.?.8.@.>.2.0.B.L. .D.0.9.;. .:.>.;.;.5.:.F.8.8. .A.?.@.0.2.:.8.:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....<...5. .C.4.0.;.>.A.L. .A.>.7.4.0.B.L. .:.0.B.0.;.>.3.:. .%.1..........Cannot create directory: %1.....QHelpCollectionHandler.....`
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10388
                                                                                                                                                                                                                                                          Entropy (8bit):4.70568613551943
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:uPq7iBWseXKkVu4+Qv9zEJ1xGMaLNmBgJqdC6/MxIMt:LWcseV04Xv9zEoLNDJqdX/MxRt
                                                                                                                                                                                                                                                          MD5:75C94E59F1FC5312AE25381C247AF992
                                                                                                                                                                                                                                                          SHA1:E3E5F4582CC5FAFE6DF43644D11484861023C084
                                                                                                                                                                                                                                                          SHA-256:F41E33E1D790BD0D3EB180F1F875BC191FE74773628F25C2CAD95E1402E66867
                                                                                                                                                                                                                                                          SHA-512:959B8F4D57FC9728DD4804322333D1792D45A0EE85615B559E0CA3BD2DEA22E2C8C68C6482AE9425D29C819B0ED27473EDDC82EF4B6ECFFB2E2E7B56E1509B63
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......sk_SKB...8.(.......0T......Uj......`.....0.a[....8..........t..............1"......39.......s........... .....%..........B<s...6..MQ..............J..$-.0.......O5Q......)Q...;..o>...........G...J..$......."....t.....8dz..#..D ......k.A...2.k.A.......n..._...I.................. ...21..........e.........G...!...w....Y...........!...........=...Q............$a......6.>.........."...K....i......# ._Xa..."..GA..............~.......TH..!{.K.H.."7.........pA..........%..P.~.....o........(..........!...~....u.s.1.....o.......z.q...c..............................f..e....9i..&-......(.D...v.o.d.o.m. .m...~.e. .b.y.e. .t.o.,. .~.e. .d.o.k.u.m.e.n.t...c.i.a. .s.t...l.e. .n.i.e. .j.e. .z.i.n.d.e.x.o.v.a.n.....).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......P.o.z.n...m.k.a.:..........Note:.....QCLuceneResultWidget.....".V...s.l.e.d.k.y. .h.>.a.d.a.n.i.a..........Search Results.....QCLuceneResultWidg
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10363
                                                                                                                                                                                                                                                          Entropy (8bit):4.613473842638716
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:vNBqTi7qBCVIQf54EslZ2Jy/L/BnmpP0bX3caK6q1B6/hgIlCCUb0:vjq2+UVT4ESZOYmpP0bX26q1I/yqCCUw
                                                                                                                                                                                                                                                          MD5:3B0AEE27B193A8A563C5CB5C7C4FE60F
                                                                                                                                                                                                                                                          SHA1:C94E832595EC765370553468F87C02DB7E7D138A
                                                                                                                                                                                                                                                          SHA-256:2EC955E662407EBCD8DCDAE5AAA21E4108E0B5B0AEE0E9DB712C27072943535F
                                                                                                                                                                                                                                                          SHA-512:EBC25C378126876F44279E23CA0CF06FC9E7D5F51AD7E3DBDABA7A50C81112EDC1C76F7FD0AF47E447A93C3593BB953A0C9C1FBBFC49494E6B29BF21655F690E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......slB...8.(.....E.0T......Uj......`.......a[............!..t..............1"....;.39.......s....^............$........i.B<s...,..MQ..........}...J..#..0.....Z.O5Q...[..)Q......o>...............J..$I......"W...t...C.8dz..#H.D ......k.A.....k.A.......n.......I.................. P..21....................G...!...w............?...!...3...........Q...+........$a....>.6.>.........."...K...........".._Xa......GA..............~....A..TH..!I.K.H..!..........pA...>......%..P.~...>.o........(....d..... ...~......s.1.....o.......z.q.....................................e....{i..&.....z.(.R.a.z.l.o.g. .j.e. .m.o.r.d.a. .t.o.,. .d.a. .s.e. .d.o.k.u.m.e.n.t.a.c.i.j.o. .a.e. .v.e.d.n.o. .i.n.d.e.k.s.i.r.a...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......O.p.o.m.b.a.:..........Note:.....QCLuceneResultWidget.....".R.e.z.u.l.t.a.t.i. .i.s.k.a.n.j.a..........Search Results.....QCLuceneResultWidget.......R.e.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4629
                                                                                                                                                                                                                                                          Entropy (8bit):4.68793836539357
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:BoiK0UD2wMLb7Lqlguotqbww5BLNwWjK0kHU9zuQlUVUfniqthweEIFwC18lLEGA:PXFf7pU75BWWOpcJcVqDFNz8brgyf76r
                                                                                                                                                                                                                                                          MD5:32D6EE3D8EE6408A03E568B972F93BCB
                                                                                                                                                                                                                                                          SHA1:582EE079DBD42000C378E0701D26405750524DBA
                                                                                                                                                                                                                                                          SHA-256:EBDECA0CFEE7A9441DEB800BABFD97C63BC4E421DA885C55B3BD49725EBACD25
                                                                                                                                                                                                                                                          SHA-512:24AAA30B9CB4DB82A57411FBA24A87D70D8B845AE48A6FDA633D0BE6B824B58FDD2F450C2B385F16F49E2F9C6FA0A3124FD0F28594726940F996C66F8F3216CC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......tr_TRB.....%.....[.0T......Uj......`.....$..............L.B<s.....B\>..........4.+.s...............t.....D ......k.N...5...I......2.......G....5...N..........a...............f..K....9..........GN...........@.K.H..........q..pN...t..........>...z.~...../..%c.....z.q....i..........B.a._.l.1.k.s.1.z..........Untitled.....QHelp.....J.K.o.l.e.k.s.i.y.o.n. .d.o.s.y.a.s.1. .k.o.p.y.a.l.a.n.a.m.1.y.o.r.:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....2.D.i.z.i.n. .o.l.u._.t.u.r.u.l.a.m.1.y.o.r.:. .%.1..........Cannot create directory: %1.....QHelpCollectionHandler.....\.%.1. .d.o.s.y.a.s.1.n.d.a. .d.i.z.i.n. .t.a.b.l.o.l.a.r.1. .o.l.u._.t.u.r.u.l.a.m.1.y.o.r...........&Cannot create index tables in file %1......QHelpCollectionHandler.....N.%.1. .d.o.s.y.a.s.1.n.d.a. .t.a.b.l.o.l.a.r. .o.l.u._.t.u.r.u.l.a.m.1.y.o.r........... Cannot create tables in file %1......QHelpCollectionHandler.....P.S.q.l.i.t.e. .v.e.r.i.t.a.b.a.n.1. .s...r...c...
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9750
                                                                                                                                                                                                                                                          Entropy (8bit):5.281035122342072
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:eMp79BCN+u8hhbHbny+HJouHgei50JBSfDvbetpP/RIkT:eIhgNgBbny+phiS3SfDDetpP/RRT
                                                                                                                                                                                                                                                          MD5:90A776917D534B65942063C319573CDC
                                                                                                                                                                                                                                                          SHA1:5DF3B213D985A3BBDB476B37B7780D7D7DF17E41
                                                                                                                                                                                                                                                          SHA-256:497CFC473684692EE44D7A3795E8FB2270C57069FD9EB98A615DD29AB9BE8A7C
                                                                                                                                                                                                                                                          SHA-512:B34A019716B50CE8E1E20AC32756B3B0D5802971F7A04F4BDDE2418DA551AFB9742B79E934979DB6FAB9DAC05D7D26A3B19ABA77158321F8D9AAB08AEBBD455A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......uk_UAB...(.(.....?.0T......5w......Uj......`.......a[...............t............K.39....u....."..........B<s...8..M^...j......y...J..!..O5^...Y..)^......o>...o...J..":...... <...t...E.8dz..!3.D ....".k.N.....k.N...d...n.......I..............2>...>......o.........G.......w............E.......e..,................^...S........$a......6.>...'...... y..K........... ..W.b....._Xn......GN...p..~.......TH...4.!.....9.K.H.............pN..........#].P.~...~.o.....N..(....b.........~......s.>.....o.....o.z.q..........................U.h.............D..e.....i..#.......(...@.8.G.8.=.>.N. .F.L.>.3.>. .<.>.6.5. .1.C.B.8. .B.5.,. .I.>. .4.>.:.C.<.5.=.B.0.F.V.O. .4.>.A.V. .V.=.4.5.:.A.C.T.B.L.A.O...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.........@.8.<.V.B.:.0.:..........Note:.....QCLuceneResultWidget.....". .5.7.C.;.L.B.0.B.8. .?.>.H.C.:.C..........Search Results.....QCLuceneResultWidget....... .5.7
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6441
                                                                                                                                                                                                                                                          Entropy (8bit):5.790303416386852
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:pB37nBD4H5PCyLDxLSzJPduYx9vja/FIgH9yIFqfs:rTZ4HUAD1S1JFe/F59PFqfs
                                                                                                                                                                                                                                                          MD5:9297A6905B8B1823BF7E318D9138A104
                                                                                                                                                                                                                                                          SHA1:3DB992A1B3BBCAF314B7EA4A000D6334D7492A52
                                                                                                                                                                                                                                                          SHA-256:C02AAA20923F18ADDAB520BE5CB84EFD4C723396BDC24B4C9A72D406F101C7B4
                                                                                                                                                                                                                                                          SHA-512:01F12CEE0AE456D78942A6049E1C77F94B406C8FFB4A5944DE15E54D1C760CDBA13279530A8F29B1443D1BBC647D3AF5436AAD8C43EB3944316C48300B3827E4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......zhB......I....L.0T......Uj......`.......a[...............t....P..@....Z.......<.........39.......s....2.................B<s......MQ..........9...J......31.....0.......O5Q......)Q...^..o>...........(...........J...V...........t.....8dz.....D ....Z.k.A.....k.A.......n.......I...........t..w................!...........o.......D...Q...E........$a......6.>...h...............%._Xa......GA..........._..TH...r.........pA.............P.~.....o.....].~.q.............~......o.....h.z.q...........H..0q....................i........2..S.u...y.`.Q.v.S.V.S..f/V.N:..e.hckcW(..}"_.0............M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget......l..............Note:.....QCLuceneResultWidget......d.}"~.g...........Search Results.....QCLuceneResultWidget.....,d.}"~.g.N_..^vN.[.et..V.N:..e.hckcW(..}"_............VThe search results may not be complete since the documentation is still being indexed!.....QCLuceneResultWidget..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9301
                                                                                                                                                                                                                                                          Entropy (8bit):5.80411750798786
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:4bgIXwsL78BQp4dRDP0ludqODa/wkB/tTWn5dJ6mO8IZiT9Dzz/wI3HyRWqUqS:lI/oS4dR5c/tTWn5/EZA9D/w+H8WqUqS
                                                                                                                                                                                                                                                          MD5:47C3328D3918CF627112BB6C50E30B86
                                                                                                                                                                                                                                                          SHA1:05705603AB3F28402A6C103E1C41DDFF21D140C0
                                                                                                                                                                                                                                                          SHA-256:3697F1660D7F2AC9B37AC33CD1C7ECAE08ADBD26710E7E0076497CCDDC8BC830
                                                                                                                                                                                                                                                          SHA-512:8DE1C3C5A48965CF6D8AA545DA9F0A5C00AE124F3E4153597915E7C0F4CAE1E26723270F58A47AA9FFA4AAF30E6EBA522D4EBAD27DECF17EF108E353E611980E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......zh_TWB......I....[.%.......0T......0T......Uj......Uj....R.`.....>.a[....................g..t....7..@......................39.......s................... .........B<s.....B<s.....B\>......MQ..........[...J...]..31.....+.s...c.0.....U.O5Q......)Q...C..o>.......................J...............t...3...t.....8dz.....D ....R.D ......k.A.....k.A.....k.N...'...n.......I.......I...........[..2....x..G........N......w................!...........:...........Q...&...............$a......6.>...I.......L.......$..K......................_Xa...y..GA...O..GN...........$..........TH...I.K.H................ Y..pA...K..pN.............P.~.....o.....D.~.q......>.............~......~........%c.. ..o.....!.z.q...........#..0q....................i..!Y....(..g.S..f/V.p.N.W(^.z.e.N.v.}"_.uvN-0............M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget......P..;............Note:.....QCLuceneResultWidget......d.\.}Pg...........Sea
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):146
                                                                                                                                                                                                                                                          Entropy (8bit):3.6255640074603277
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4C/IrLlAlHekfK/gp1MUXaMlI+rwtbWlMiayIPldkOgn:CwDrC+TYIUrIRt6HoiHn
                                                                                                                                                                                                                                                          MD5:5A46979B45C67DD6312F33CCEA2ED7BC
                                                                                                                                                                                                                                                          SHA1:4C56836B1FB10D9903B299CBCB925947D515B4C8
                                                                                                                                                                                                                                                          SHA-256:BB246AABD501E14CED8B1FFC1369E3D5D26567AAE62B3EAD4D94C22FB77C3471
                                                                                                                                                                                                                                                          SHA-512:BDBA4E1731CF254E95B0F1337410937C765E96FBB1D42F1D053033E1511FEE6F50C02705F781F4DAA0347E2299DC78A5A9942AC4EA343ED1F8F401F9ACD961E4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......hu....v.....q.t.b.a.s.e._.h.u.....q.t.s.c.r.i.p.t._.h.u.....q.t.m.u.l.t.i.m.e.d.i.a._.h.u... .q.t.x.m.l.p.a.t.t.e.r.n.s._.h.u
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):153
                                                                                                                                                                                                                                                          Entropy (8bit):3.5752972123113778
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4C/EbFlAlHeke5zOp1MUWLt7KlI+rwtbWlMj5FKIPldkOA9kk:CwDM+35aIUW5SIRt6Q50oi9Gk
                                                                                                                                                                                                                                                          MD5:2BB8C94D420D3BC344C79A01043BDC89
                                                                                                                                                                                                                                                          SHA1:3FBA773D58E6D3699C20AB41AEE6801E71E2DDAE
                                                                                                                                                                                                                                                          SHA-256:9117AAC2D07BC86DFA55A29B8825ED27C7093300FCC90E143E135E00E85F09D7
                                                                                                                                                                                                                                                          SHA-512:C6B13655AFB206B0056F5656B4A9BF33CC267FCC928F6973258131CFA6443970510226FE45A041E5AA988809E17D0B11C7458F4A241C71521EDED186596C6055
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......it....v.....q.t.b.a.s.e._.i.t.....q.t.s.c.r.i.p.t._.i.t.....q.t.m.u.l.t.i.m.e.d.i.a._.i.t... .q.t.x.m.l.p.a.t.t.e.r.n.s._.i.t.......
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):146
                                                                                                                                                                                                                                                          Entropy (8bit):3.599979504080125
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4C/il/lAlHekd6hY1MUV6JAlI+rwtbWlMgel3UlIPldkOG:Cwz4+pjUGAIRt6qVUloiB
                                                                                                                                                                                                                                                          MD5:8A1EE3433304838CCD0EBE0A825E84D8
                                                                                                                                                                                                                                                          SHA1:2B3476588350C5384E0F9A51FF2E3659E89B4846
                                                                                                                                                                                                                                                          SHA-256:23457CE8E44E233C6F85D56A4EE6A2CECD87C9C7BDDE6D8B8A925902EED1CD9C
                                                                                                                                                                                                                                                          SHA-512:2D8ACD668DF537E98B27161F9FA49828EB2EB6E9CF41DB38E7F5D31F610D150CD1B580A8AE9B472A4DFDE4D4BF983C24A56293BB911CF5879368664E4D4CF3D2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......ja....v.....q.t.b.a.s.e._.j.a.....q.t.s.c.r.i.p.t._.j.a.....q.t.m.u.l.t.i.m.e.d.i.a._.j.a... .q.t.x.m.l.p.a.t.t.e.r.n.s._.j.a
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):146
                                                                                                                                                                                                                                                          Entropy (8bit):3.652277257665055
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4C/rrr/lAlHekcQ/01MUUQMlI+rwtbWlMhQGlIPldkORn:CwCC+1Q/UUpIRt6SBloimn
                                                                                                                                                                                                                                                          MD5:7B2659AF52B824EAC6C169CDD9467EE9
                                                                                                                                                                                                                                                          SHA1:5727109218B222E3B654A8CC9933E970EB7C2118
                                                                                                                                                                                                                                                          SHA-256:4CC1AF37E771F0A43898849CFF2CD42A820451B8D2B2E88931031629D781DB05
                                                                                                                                                                                                                                                          SHA-512:E9475AC80BDBBEFF54F2724A2B6BA76992F18FD1913FD8EE1540A99FD7A112B79FED5A130B6AC6D7460E4420C06354FC6E4CF7770A7C6CBD3EAC1BDAF0082DE5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......ko....v.....q.t.b.a.s.e._.k.o.....q.t.s.c.r.i.p.t._.k.o.....q.t.m.u.l.t.i.m.e.d.i.a._.k.o... .q.t.x.m.l.p.a.t.t.e.r.n.s._.k.o
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):165383
                                                                                                                                                                                                                                                          Entropy (8bit):4.805977227348512
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:i5v3+zmayloj6yJjhnBAbnrKnGrhA7WgdXclIsooY9i:SvOzAloj6yJ9BA7riGr+7WKXc+s5ui
                                                                                                                                                                                                                                                          MD5:8992B652D1499F5D2F12674F3F875A35
                                                                                                                                                                                                                                                          SHA1:E22766A49612F79156C550D83C6C230345DDA433
                                                                                                                                                                                                                                                          SHA-256:47EB5F97467DF769261421D54A5BEA1131C9FB9B6388791D38BB6574335B64BF
                                                                                                                                                                                                                                                          SHA-512:9B8B6DBFF432F2A46C14BC183A6BAF84ACBF02BF2C5BB8C306C6538FBD9BE1C0A9015BD46728F2F652F9163AFC56B1E16D16EB95D8F7728F3C562AE9F4F1AE1E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......ltB..0X...*..)C...+...|......P....@..9....A..9....B..:....C..:....D..;....E..;....F..<6...G..<....H..=)...I..=....P..>q...Q..>....R..?....S..@f...T..@....U..A\...V..B....W..B....X..C....Y..Cy...]..k....t..........t>......th......t.......pd...;..J'...;.._h...;.......;...{...;..J....;...)...M..l....O...R...O...............}..l9...m..lo......^S..(5..P{..+;..4...+;......+;......+O..4...+O......1...^...E@..?p..F...C...H4......HY......H.......I...D...I@..s...IA..t...IC...2..J.......J....Y..J.......J.......K...9...LD...`..L.......PS......R.......T...q...Zr...`..[`......[`..&@..\....e..\....b.._......._....P..1........E..........5........L..1...O...1...PP......7......../...........$.......$.......,.......y.......y..........K^..............x......8................L...E.......E.......E..*....................%..:....%.........0U.....W......Zo.....^....5.......0..I....0...F...0...|...0.......0.......0..+\...5...}.......... D...g.. D......+....j..,.......,.......<U...+..<U
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):89
                                                                                                                                                                                                                                                          Entropy (8bit):4.156834975253888
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4C/HzllldQlHekbxplUp1MUTJ+b:Cwv+DIUEb
                                                                                                                                                                                                                                                          MD5:19F1B919BB531E9E12E7F707BEBD8497
                                                                                                                                                                                                                                                          SHA1:46E82683CEA28D877C73A5CE02F965BB1130FC62
                                                                                                                                                                                                                                                          SHA-256:03467738042A15676E504BA02CB326DCDB773B171FADA3CD62B7A0E0564314A0
                                                                                                                                                                                                                                                          SHA-512:901D7B26CAC7A4D0FFDB39A1D25767B5BC71BED4AFBE788D70BF19D4C58A8295167111675AB45E743FDF4768AF874D69417414C01CF23D5C525A3F6C8BF7D21F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......lv....0.....q.t.b.a.s.e._.l.v.....q.t.s.c.r.i.p.t._.l.v........)....
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):161
                                                                                                                                                                                                                                                          Entropy (8bit):3.8693516202048612
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4C/5J/p/lAlHekHp/7KlI+rwtbWlM6Tl/z21MUPp/FOlIPldkOjehB:Cwr+26IRt6nFURkloiT
                                                                                                                                                                                                                                                          MD5:D71EA9FEFD97464B178235150EC8759E
                                                                                                                                                                                                                                                          SHA1:61026FE602FD1B8B442A0D341C6BD759EEC75488
                                                                                                                                                                                                                                                          SHA-256:BD7DD0C2CAB119A973DC10C3BFF7499D9728B928B541F86056921B30C8DB78E6
                                                                                                                                                                                                                                                          SHA-512:ECD76A7D8B8D733E635B2BFEA90A4CD387B83D9D8A4EB6D299F59FF22AAA8D617A4C886A825A1CDDD901925C7839E2C18BDD4E0CD84152641922B66B62663F77
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......pl....v.....q.t.b.a.s.e._.p.l.....q.t.m.u.l.t.i.m.e.d.i.a._.p.l.....q.t.s.c.r.i.p.t._.p.l... .q.t.x.m.l.p.a.t.t.e.r.n.s._.p.l............,..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):70334
                                                                                                                                                                                                                                                          Entropy (8bit):4.732724622610353
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:OKGUuWW+WHjS0gMBd483+Y7bDPs4RHBloLUIltlzAJnx4nnliM1OPlOibLG:JGUuWPuSgm0Jn+n4Mhj
                                                                                                                                                                                                                                                          MD5:6656500F7A28EF820AE9F97FD47FB5BB
                                                                                                                                                                                                                                                          SHA1:CC112B9C9513BCF7497F3417168B4C8A9F7640A9
                                                                                                                                                                                                                                                          SHA-256:2C1E7BBF5168A64B43752DD4C547601C0BDE6D610F8671FA3E3AF38597E84783
                                                                                                                                                                                                                                                          SHA-512:5C3CBFCF86AF6B4D949C1D914CD379E512E73BA350AF661033A386EE7FB981FBFCB43D9A35FDE7656E17BB09F64F1469F84867A780573C3359D645269461D5A6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......pt_PTB...(...*...9...+...e...]..6....;.......;..-....;..;`...;..};...;.......M..6....O... ...O...w...........}..7....m..7B..........+;......+;..8S..+;..>...+O......+O..8#..H4......H.......J......K.......LD...)..L....}..PS...l..Zr...B..[`...;..[`.....\...kU.._......._.......1...?...............8...............E............,..................p........0...............v...........%...O...%..G........4...0.......0..:....0..y....0..|....0.......0...X...5.......5...... D..=... D..Kn..+....L..,...>...,......<U..z...<U......<.......F...>...F.......H5...4..H5..=...H5..K...H5......f....p..f...1...f...;...f...I...f...|H..f.......f.......l....................b......<...............>.......L ...........`......`..._.......A......2....e...g...e..>D...e..LW................y...,.*.y.....*.y..o..*.y.....*.T..L..*.0..'..*.0....+F...y..+F......+f......+f...C..+.z..0..+.....d.+....p0.+.....R.+.z..0U.+.....u.+....8..+....Ct.+....L..+....y..+.....Z.+......+...pc.+.....+....0..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):164
                                                                                                                                                                                                                                                          Entropy (8bit):3.984562388316898
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4C/oZlAlHekF8Op1MUNKJKlI+rwtbWlM4KKIPldkOSxRMugB:CwY+GIUgcIRt61oihM3
                                                                                                                                                                                                                                                          MD5:F7A8C75408B9A34A2B185E76F51B7B85
                                                                                                                                                                                                                                                          SHA1:065E987139C5FB809A6F9CDF3845BCD79707FDBB
                                                                                                                                                                                                                                                          SHA-256:6492B267608C6FB76907BD8FCFC8F1EF57E9F4EBBC2E81ACA81715A88388F94A
                                                                                                                                                                                                                                                          SHA-512:E768C5B438EC899801B22B1325F2244ACCC5E7C2EC5D270F510BC3CBC2D9A0536949C026DB7FB5862835E506A9F2020DEB2CC4001E7011FF974324542734F855
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......ru....v.....q.t.b.a.s.e._.r.u.....q.t.s.c.r.i.p.t._.r.u.....q.t.m.u.l.t.i.m.e.d.i.a._.r.u... .q.t.x.m.l.p.a.t.t.e.r.n.s._.r.u........)......,..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):157
                                                                                                                                                                                                                                                          Entropy (8bit):3.7731953311404336
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4C/3xRlAlHekE8lgp1MUM8lMlI+rwtbWlM5UllyIPldkOfll6kchn:CwS0+t8CIUM86IRt6KUlsoi2CVh
                                                                                                                                                                                                                                                          MD5:24C179481B5EF574F33E983A62A34D53
                                                                                                                                                                                                                                                          SHA1:0A67F1ED8CA4A5182F504806F8D47D499789F2D2
                                                                                                                                                                                                                                                          SHA-256:B6ADFFD889FF96BF195CB997327E7D7005A815CAD67823FA6915A19C2D9BB668
                                                                                                                                                                                                                                                          SHA-512:4757F3693120DAB2FBB7BCF1734EA20B3E3D9056B4B4E934A3129D660CFDC6C58B230459DB55912AF24AD5692BD221830BE0FF91E41D3EECD9439E79AC23FFE6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......sk....v.....q.t.b.a.s.e._.s.k.....q.t.s.c.r.i.p.t._.s.k.....q.t.m.u.l.t.i.m.e.d.i.a._.s.k... .q.t.x.m.l.p.a.t.t.e.r.n.s._.s.k...........
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):228428
                                                                                                                                                                                                                                                          Entropy (8bit):4.726953418955661
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:9zQH0hOtgmiAZu0eeAEv+v49JnnSmICgr3n7jhCQUeinqyU5UggtRLGrQ2LZO+Y1:RpUsSpGr36wsR
                                                                                                                                                                                                                                                          MD5:D35A0FE35476BE8BD149CEE46E42B5E9
                                                                                                                                                                                                                                                          SHA1:9F3C85C115A283E5230D1EEAD84C8CB73A71FA03
                                                                                                                                                                                                                                                          SHA-256:C44E0313A9414CC0E490B65B0C036FA11BCA959353B228886547BC2C8492034F
                                                                                                                                                                                                                                                          SHA-512:BEEB1751882AF081E80BE93F7464D4C6322B724EFA2CBD3E1CBE709181D380C1C57E770FA962BB706D6FCF4A8CB393E3F6E187C1F604F8CEEFB201CA3200BD1C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......slB..<....*.......+.......@...C...A.......B...<...C.......D...2...E.......F...d...G.......H...W...I.......P.......Q.......R.......S...x...T.......U...n...V...%...W.......X.......Y.......]..g~...t...V.......f..................................;..G....;..[....;...q...;..ia...;... ...M..g....O.......O.......[..,e...........}..g....m..h........Q..(5......+;..2...+;...b..+;...i..+O..2...+O...4..1......E@......F.......H4......HY...%..H.......I.......I@......IA...9..IC......J...6...J.......J.......J...^...K...7...LD......L....n..PS...U..R.......T....=..Zr......[`...V..[`......\...!,..\...8U.._..."b.._.../h..1.......E...9......4...............5........e...................$...<...$..Z....[.......,.......y...L...y..].......H.......@.......J.......6........~..........E...O...E..+....E...~..............,1...%..8r...%...........^..............................5.......0..Gx...0.......0..P....0..h....0.......0.......5...^.......... D...... D......+....`..,.......,...-...<U
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):65851
                                                                                                                                                                                                                                                          Entropy (8bit):4.7906769989650515
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:4u6DkpgyKmRmG15mGM6iFPi6Q/qTlOQZY2dKN8gKw:4u6DotUG1sGMZPi6Q/qTlO2Y2YKw
                                                                                                                                                                                                                                                          MD5:0E85E0E0E7DDFE3D4BDE302F27047F9C
                                                                                                                                                                                                                                                          SHA1:AE59348E0C2E4F86F99DA6CF5DAB3B7E92504B7C
                                                                                                                                                                                                                                                          SHA-256:4B4B6FF7FD237C9DA0301B4946132E68653D15EB5FAF38E4C5FBFEBB12DD97F7
                                                                                                                                                                                                                                                          SHA-512:8CAAB6C61E9FA26A3A289A9E4DC515D157B3092D6D4ED43861220261BD2B7CC79B35B52F9ADE4EF558B5385B37EAC14575420DD55C475F435BB95B6C1E2561B6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`...B.......*.......+...i...]..6....;.......;..-f...;..:;...;..t....;.......M..64...O.......O...........q...}..6\...m..6........(..+;......+;..7...+;..=...+O......+O..7c..H4......H.......J.......K....F..LD...+..L.......PS...N..Zr......[`...7..[`...N..\...h4.._....J.._....k..1...>...............7........}......D............,...........*......i....................................%.......%..Fc.......6...0.......0..9....0..q....0..t....0.......0.......5.......5...... D..<}.. D..I...+.......,...=X..,.......<U..r...<U...n..<.......F...=...F....F..H5......H5..<...H5..J4..H5......f.......f...1V..f...:f..f...H;..f...t&..f.......f.......l..................8......;z..............<.......Je.......6...`...&...`...!.......9......1....e.......e..=....e..J..............g...y.....*.y.../.*.y..h..*.y.....*.T..J..*.0..'[.*.0...K.+F...q..+F.....+f......+f...A..+.z../..+.......+....i`.+.....X.+.z../..+.....S.+....7..+....Bi.+....K..+....q..+.......+......+...i..+.....+....0..F0i.....G.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):110
                                                                                                                                                                                                                                                          Entropy (8bit):3.630483009136986
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4C/7zl9lAlHekDN/01MULV4LlI+rwtbWlM+N:Cw5+wUGRIRt6n
                                                                                                                                                                                                                                                          MD5:16CDF5B9D48B0F795D532A0D07F5C3A0
                                                                                                                                                                                                                                                          SHA1:6E403C9096B3051973E2B681DFEBBC8DD024830D
                                                                                                                                                                                                                                                          SHA-256:F574A2CFD4715885C3DBDF5AE60995252673BD94FDAA9586F7E0586F6C1AC0EE
                                                                                                                                                                                                                                                          SHA-512:36A0431368010157EA8A45DCB00458076CCFFC08B37E443DEBD1AAD4A30C6080803337725A7A3DCBF2B410DC7BE89CEAF6C07C46F876E4EF5B08159E3BF38E6D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......tr....R.....q.t.b.a.s.e._.t.r.....q.t.s.c.r.i.p.t._.t.r.....q.t.m.u.l.t.i.m.e.d.i.a._.t.r
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):164
                                                                                                                                                                                                                                                          Entropy (8bit):4.021402900389864
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4C/ZlRlAlHekCczOp1MUKUt7KlI+rwtbWlM/cFKIPldkONRMugB:CwUl0+rjIUKUcIRt6M/oioM3
                                                                                                                                                                                                                                                          MD5:9B101363343847FE42167183320C03F0
                                                                                                                                                                                                                                                          SHA1:F0DF2CFF913E588B7CADFDABBF69F4F632B2F96A
                                                                                                                                                                                                                                                          SHA-256:F1621E680E1642F9463E4B07E7E78B50F9A7BDB7C321D7302039CB3405CBDEA4
                                                                                                                                                                                                                                                          SHA-512:DA14FDF8DB514902733CAAC492293873351C595EBBE0ACB0849BECE24AB822602EE64D01051F1426CD1FC13A95D8607302CF9B515D9806FDD3BD047087DE447C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......uk....v.....q.t.b.a.s.e._.u.k.....q.t.s.c.r.i.p.t._.u.k.....q.t.m.u.l.t.i.m.e.d.i.a._.u.k... .q.t.x.m.l.p.a.t.t.e.r.n.s._.u.k........)......,..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117347
                                                                                                                                                                                                                                                          Entropy (8bit):5.8593733369029195
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:51dXW89nqEFu54aekvRzHHSVuf8j2+/xc3lhnbsfdAoz/w:v9qEFeLekvRznSVHJG3lhn+djY
                                                                                                                                                                                                                                                          MD5:0D02F0DE5A12BCB338B7042DFBDAACF3
                                                                                                                                                                                                                                                          SHA1:B7C10D249D8986AD8C6939B370407D07227A39F5
                                                                                                                                                                                                                                                          SHA-256:28CDE75D7B32C81FEF1D4630C37B79A61DEC24B357632FF00D6365A57D8BE43B
                                                                                                                                                                                                                                                          SHA-512:21F02EBA36B4411921EA3C70310B8E454E8FC2B8F09957FD6A63B71689DC381F7A5E2C3BDF2810734D659AB43D8A7BD46EF6436ECC52F75C71B5F5C313365444
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......zhB..+....*.......+.......@.......A...8...B.......C.......D.......E...V...F.......G...L...H.......I...9...P.......Q...e...R...^...S.......T...T...U.......V...|...W.......X...o...Y.......]..4 ...;...2...;..,....;..8....;.......;.......M..4H...O.......O...........#...}..4p...m..4........N..(5......+;...f..+;..6Y..+;..<...+O...8..+O..6'..1......E@......F....Y..H4..."..HY..J...H.......I.......J.......J.......K....5..LD..._..L......PS...V..Q....6..R...N...W..../..Zr.....[`.....[`......\...lU.._......._....L..1...<........j......6...............B........I...$..K....$.......,...g...y...3.......A......r...........................9..L7......;w...E..5b...E...G.......5...%.......%..D........`......*........................0.......0..8W...0..}y...0...6...0.......0.......5.......5...... D..:... D..J...+....R..,...;...,......<U..~...<U......<......F...;...F......H5...i..H5..:...H5..Jk..H5...w..VE...[..f....u..f...0X..f...9...f...E...f.......f.......f....j..g....A..l.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):141
                                                                                                                                                                                                                                                          Entropy (8bit):3.7198292994386235
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4C/0N6xg/Rl/gl+kNXDelHrwtbWlMwTolIPldkOfDn:CwOO2+g6Mt63oloiUn
                                                                                                                                                                                                                                                          MD5:ED4135D705AEF3D97F8BF6B8FF11F09C
                                                                                                                                                                                                                                                          SHA1:308E2B8F74B863A61AD0B68F4A18ED06965EBEAA
                                                                                                                                                                                                                                                          SHA-256:751ECDA0C33E061D91241268357FBD2F6B7F70A1116E714F28D22EFD61EC7A1A
                                                                                                                                                                                                                                                          SHA-512:B6E6D00553A9C427130129B9D30E862028E549F372A832F0F05747C8E2A79E443F4932EC3AE177537C8BA00D26B5B6CB97D5B35426AB5229F6A468CA485BE0B1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......zh_TW....n.....q.t.b.a.s.e._.z.h._.T.W...$.q.t.m.u.l.t.i.m.e.d.i.a._.z.h._.T.W...&.q.t.x.m.l.p.a.t.t.e.r.n.s._.z.h._.T.W
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):160017
                                                                                                                                                                                                                                                          Entropy (8bit):5.35627970915292
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:XGlAMfkX1M0RdaCkR8lfv8vtc8EFrVYA2I4AJZWEWgHg1C8COvzHKHC6Jp9NV0V7:XUr0RACkIwDEpV1Lgf1ubtw3Bb
                                                                                                                                                                                                                                                          MD5:A7E4D0BA0FC5DF07F62CC66EC9878979
                                                                                                                                                                                                                                                          SHA1:21FD131B23BDD1BBA7BBB86F3ED5C83876F45638
                                                                                                                                                                                                                                                          SHA-256:E03FE68D83201543698FD7FE267DD5DFC5BFD195147E74FF2F19AC3491401263
                                                                                                                                                                                                                                                          SHA-512:D9E6B10506FCF20B5B783F011908083D9DF6C5DF88E21B10D07F53A01AD6506A4B921C85335A25BAE54E27BAD7D01B6E240D58FDEEAABC7FF32014EC120C2ECF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......arB..2....*.......+.......@.......A.......B..._...C......D.......E......F.......G... ...H...D...I...h...P...C...Q...g...R......S.......T.......U.......V...x...W......X.......Y.......]..'=...s......t...........]...........;..'....;..(....;.......;.......M..'e...O.......O...9...........}..'........C...=......m..'....t..........!o..(5...Z..+;..5u..+;..c...+O......1...!...D@...8..E@.....H4...,..HY..QI..H.......IC......J....1..J.......J.......LD......L.......PS......QR...R..R...V2..T.......U....]..X.......Zr.....[`......\....t..]x......_......._.......yg......1...6....E..8V..............C............................$..RN...[...0...,.......y.......y...................K...........9..R....E.."............z.......................%..F;...D...[..................................!....5.......0...I...0.......0...5...0..#....5.......5...p..............W}.. D..(... D..P=..+.......<U......<U......<.......H5..(...H5..P...L.......VE......VE......V....B..f...JJ..f.......f.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):165337
                                                                                                                                                                                                                                                          Entropy (8bit):5.332219158085151
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:9ULiyUxPoT6qx+J7FJlaaMJnxjqxq+0Uiff0mbVeb7wiEwYuYqDKBkKHMXHCIMll:9ULpIVFnpwUiEujw27ncUQUz
                                                                                                                                                                                                                                                          MD5:660413AD666A6B31A1ACF8F216781D6E
                                                                                                                                                                                                                                                          SHA1:654409CDF3F551555957D3DBCF8D6A0D8F03A6C5
                                                                                                                                                                                                                                                          SHA-256:E448AC9E3F16C29EB27AF3012EFE21052DAA78FABFB34CD6DFF2F69EE3BD3CDB
                                                                                                                                                                                                                                                          SHA-512:C6AE4B784C3D302D7EC6B9CE7B27DDAF00713ADF233F1246CD0475697A59C84D6A86BAA1005283B1F89FCC0835FD131E5CF07B3534B66A0A0AA6AC6356006B8F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......bg_BGB../....*..,....+..."...@...]...A.......B.......C.......D...P...E...!...F.......G.......H.......I.......P.......Q.......R...A...S...e...T.......U.......V.......W...1...X...U...Y...y...]..,....s...,...t...................P...;..+....;..-E...;..!....;..+....M..,Y...O...,...O...........*...}..,............=...Q...m..,....t...|......>...(5..1...+;..<...+;..o...+O...r..1...>...D@......E@......H4......HY..[...H.......IC......J....E..J....X..J.......LD......L....L..PS......QR.."...R...`...T....X..U.......X.......Zr...q..[`...`..\.......]x......_......._....T..yg.....1...=....E..?...............L(.......(...............'...$..\....[.......,...I...y...!...y...................S...........9..]%...E..5p...........z..!q...................%..O....D..................D.....8......:......?....5...&...0.......0.. ....0...c...0..5....5.......5..................b:.. D..-... D..Z...+.......<U......<U...0..<.......H5..-...H5..[...L.......VE..#a..VE..;...V.......f...T...f...!..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):210159
                                                                                                                                                                                                                                                          Entropy (8bit):4.666388181115542
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:P/DVhdlafzvZfeW+6kXEVjSVPzC3ceKdP2:xYf7UW+WjwP2
                                                                                                                                                                                                                                                          MD5:B383F6D4B9EEA51C065E73ECB95BBD23
                                                                                                                                                                                                                                                          SHA1:DD6C2C4B4888B0D14CEBFC86F471D0FC9B07FE42
                                                                                                                                                                                                                                                          SHA-256:52E94FCC9490889B55812C5433D009B44BDC2DC3170EB55B1AF444EF4AAE1D7F
                                                                                                                                                                                                                                                          SHA-512:9401940A170E22CE6515E3C1453C563D93869A3C3686C859491A1F8795520B61BF3F0BFE4687A7380C0CC0C75E25559354FDB5CEF916AF4C5B6CD9661464A54A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......caB..7....*.......+.../...@..:P...A..:t...B..:....C..:....D..;=...E..<....F..<Z...G..<~...H..<....I..<....P..>....Q..>....R..?....S..?R...T..?v...U..?....V..?....W..@....X..@<...Y..@`...]../....s..1....t..........2s......#p...;.......;../....;..W....;..e+...M../3...O.......O..9.......J....}../]......8....=..9....m../....t..9Y.......S..(5..lB..+;.._...+;...=..+O..U...1.......D@..:...E@..?...H4...J..HY..~...H..."...IC...0..J....W..J....0..J.......LD..!...L...!f..PS..)...QR.."...R.......T...9~..U...9...U...z...X...>...Zr..E...[`...e..\...LD..]x..7U.._......._...M...yg..f...1...a....E..c....7.........U.......p........b.......4.......K...$.......[.......,.......y.......y...................^...........9...:...E...s...... (...z..":.......d......!....%..tQ...D.."......."......2......ve.....y...........5..#H...0...\...0..W+...0..';...0.......5..(....5..........)s.......... D..0w.. D..}...+...1...<?..5x..<U......<U..5...<...6@..H5..0...H5..~...L...9...VE..$...V...SV..f.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):174701
                                                                                                                                                                                                                                                          Entropy (8bit):4.87192387061682
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:5WjuhX0CVRaakGjW9E8SSOQfX/JlwVOMxrboRPqWxXfQvO7zjBf:5iFGj1QfXr8Gd
                                                                                                                                                                                                                                                          MD5:C57D0DE9D8458A5BEB2114E47B0FDE47
                                                                                                                                                                                                                                                          SHA1:3A0E777539C51BB65EE76B8E1D8DCE4386CBC886
                                                                                                                                                                                                                                                          SHA-256:03028B42DF5479270371E4C3BDC7DF2F56CBBE6DDA956A2864AC6F6415861FE8
                                                                                                                                                                                                                                                          SHA-512:F7970C132064407752C3D42705376FE04FACAFD2CFE1021E615182555F7BA82E7970EDF5D14359F9D5CA69D4D570AA9DDC46D48CE787CFF13D305341A3E4AF79
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......cs_CZB..3p...*..F....+.......@..!....@..Ef...A..!....A..E....B.."1...B..E....C.."U...C..E....D.."....D..F....E..#p...E..F)...F..#....F..FP...G..#....G..Fw...H..$....H..F....I..$6...I..F....P..&%...P..Gr...Q..&I...Q..G....R..&....R..G....S..&....S..H....T..&....T..H8...U..'....U..H_...V..'Z...V..H....W..'~...W..H....X..'....X..H....Y..'....Y..H....]..,....]..,....s.......t...9...............*...;.......;..+....;..1B...;......;..?x...;..N....;..iY...;..s3...M..,B...M..,....O.......O...w...O..rr...........}..,j...}..-....... 5...=.. ....m..,....m..-8...t.. .......ay..(5..TT..+;...A..+;..B...+;..u...+O......+O..=a..1...a...D@.."...E@..&m..E@..G...F...J...H4...=..HY..`...H.......I...J...IC......J....-..J.......J.......LD......L....(..PS.....QR.."S..R...e...T.... ..U......X.......Zr...g..[`......\......]x......_......._......._...v...yg......1...C....E..E...............=.......Q........................s...$..a....[.......,.......y.......y...y..............G..........
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):181387
                                                                                                                                                                                                                                                          Entropy (8bit):4.755193800761075
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:XzswP2UvZ5aZ9jFTkmq/gnBNW/+PcWrqm2Vliz0DGdaS4KSLZjwTTgwUR0toT:j3m27AjCT
                                                                                                                                                                                                                                                          MD5:859CE522A233AF31ED8D32822DA7755B
                                                                                                                                                                                                                                                          SHA1:70B19B2A6914DA7D629F577F8987553713CD5D3F
                                                                                                                                                                                                                                                          SHA-256:7D1E5CA3310B54D104C19BF2ABD402B38E584E87039A70E153C4A9AF74B25C22
                                                                                                                                                                                                                                                          SHA-512:F9FAA5A19C2FD99CCD03151B7BE5DDA613E9C69678C028CDF678ADB176C23C7DE9EB846CF915BC3CC67ABD5D62D9CD483A5F47A57D5E6BB2F2053563D62E1EF5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......daB..4....*..h....+......@...f...A.......B.......C.......D...U...E.......F...v...G.......H.......I.......P.......Q.......R...6...S...Z...T...~...U.......V.......W..."...X...F...Y...j...]..+....s.......t..................-...;..+....;..,....;../....;..;....M..+....O.......O...r...........}..,............=...8...m..,0...t...c......T...(5..B...+;..NH..+;..~H..+O..,...1...UP..D@......E@......H4...E..HY..j...H.......IC...#..J....J..J.......J.......LD......L....1..PS...B..QR......R...o...T.......U.......X.......Zr......[`...W..\....}..]x...[.._....-.._.......yg...e..1...O....E..R....7..........-!......]............................$..k....[...7...,.......y...c...y.................j4...........9..l8...E..p............z...;..................%..a....D...~.............-.....L......OH.....Uz...5.......0.......0...U...0.......0..p....5...7...5..L$..............p... D..-... D..i...+....@..<U.....<U.....<....S..H5..-2..H5..j$..L....B..VE.. ...VE..P...V...*...f...e...f.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):220467
                                                                                                                                                                                                                                                          Entropy (8bit):4.626295310482312
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:7w8go8+ph6JVB8XVXYWpSNEeg8+vaD+p4N8DDiEKugwGZulh15ce4M+4NsPYXCZW:88h8Sj286tTiDD
                                                                                                                                                                                                                                                          MD5:40760A3456C9C8ABE6EA90336AF5DA01
                                                                                                                                                                                                                                                          SHA1:B249AA1CBF8C2636CE57EB4932D53492E4CE36AC
                                                                                                                                                                                                                                                          SHA-256:553C046835DB9ADEF15954FA9A576625366BA8BFD16637038C4BCD28E5EBACE1
                                                                                                                                                                                                                                                          SHA-512:068E55F39B5250CC937E4B2BD627873132D201D351B9351BE703CD9B95D3BAFB4BD649CB4DF120A976D7C156DA679758D952CAC5E0523107244E517D323BC0C5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......de_DEB..7....*.......+..3....@..R....A..R....B..S....C..S@...D..S....E..T]...F..T....G..T....H..T....I..U#...P..W....Q..W6...R..W....S..W....T..W....U..W....V..XG...W..Xk...X..X....Y..X....]..2%...s..J$...t..9R......J.......B....;..1....;..3....;..q....;.......M..2O...O.......O..X@......ia...}..2y......Q....=..Q....m..2....t..Q...........(5......+;..ev..+;......+O..oh..1....4..D@..R...E@..WZ..H4..4...HY...[..H...AY..IC..>o..J...>...J.......J...>6..LD..@A..L...@...PS..I...QR..#...R....h..T...W...U...Xh..U....~..X...]...Zr..e(..[`..)...\...j...]x..O..._....K.._...lI..yg...U..1...f....E..i....7..........o.......wG......6.......6.......8....$...n...[..8....,..9....y.......y..=................3......>....9.......E..."......?_...z..#d.......0......A%...%..z....D..A.......B......KP......2.............^...5..B....0.......0..p....0..F....0...}...5..G....5..........H........... D..3}.. D...O..+...Q...<?..Ti..<U......<U..T...<...U)..H5..3...H5......L...X...VE..%j..V...l..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):16
                                                                                                                                                                                                                                                          Entropy (8bit):4.0
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:j2wZC4n:CwZ
                                                                                                                                                                                                                                                          MD5:BCEBCF42735C6849BDECBB77451021DD
                                                                                                                                                                                                                                                          SHA1:4884FD9AF6890647B7AF1AEFA57F38CCA49AD899
                                                                                                                                                                                                                                                          SHA-256:9959B510B15D18937848AD13007E30459D2E993C67E564BADBFC18F935695C85
                                                                                                                                                                                                                                                          SHA-512:F951B511FFB1A6B94B1BCAE9DF26B41B2FF829560583D7C83E70279D1B5304BDE299B3679D863CAD6BB79D0BEDA524FC195B7F054ECF11D2090037526B451B78
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`...
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):165170
                                                                                                                                                                                                                                                          Entropy (8bit):4.679910767547088
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:JVwzuvb+Ta64KQd84arHX5pxiVhA8QlOD/BnFNa8NsvsfFsfcoZtIx6F:JVwSTG4KqVaLX5pEVK7OJFczstgRtIx8
                                                                                                                                                                                                                                                          MD5:C7C58A6D683797BFDD3EF676A37E2A40
                                                                                                                                                                                                                                                          SHA1:809E580CDBF2FFDA10C77F8BE9BAC081978C102B
                                                                                                                                                                                                                                                          SHA-256:4FFDA56BA3BB5414AB0482D1DDE64A6F226E3488F6B7F3F11A150E01F53FA4C8
                                                                                                                                                                                                                                                          SHA-512:C5AED1A1AA13B8E794C83739B7FDDEAFD96785655C287993469F39607C8B9B0D2D8D222ECD1C13CF8445E623B195192F64DE373A8FB6FE43743BAF50E153CDA5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......es_ESB../....*..*,...+...y...@.......A.......B.......C.......D...v...E...=...F.......G.......H.......I.......P.......Q... ...R...k...S.......T.......U.......V...1...W...U...X...y...Y.......]..+....s.......t...................c...;..+....;..,....;...%...;..#....;..-....M..+....O.......O...............}..,............=...]...m..,/...t..........A...(5..3...+;..<...+;..o...+O..!b..1...Ap..D@......E@...D..H4...-..HY..[F..H.......IC...%..J....L..J.......J.......LD......L....O..PS......QR..!...R...`K..T.......U....&..X.......Zr.....[`...h..\......]x...|.._....Y.._....A..yg......1...=....E..?a......!.......K........G...............R...$..\Q...[.......,...z...y.......y..................+............9..\....E..2............z.. ....................%..ON...D........................:......=B.....A....5...7...0.......0......0.."....0...,...0..3....5...}...5...Y..............a... D..-!.. D..Z6..+....0..<U...h..<U......<.......H5..-M..H5..Z...L.......VE.."...VE..>...V......
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):179941
                                                                                                                                                                                                                                                          Entropy (8bit):4.720938209922096
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:lvdTgO2Yl97ZWnbgTLt/Tf9IlqAeiy5uWkYGM0wNCdRjSK2YUlUs:lvdkA9vh5uWkY0MK2YXs
                                                                                                                                                                                                                                                          MD5:8472CF0BF6C659177AD45AA9E3A3247C
                                                                                                                                                                                                                                                          SHA1:7B5313CDA126BB7863001499FB66FB1B56C255FC
                                                                                                                                                                                                                                                          SHA-256:E47FE13713E184D07FA4495DDE0C589B0E8F562E91574A3558A9363443A4FA72
                                                                                                                                                                                                                                                          SHA-512:DE36A1F033BD7A4D6475681EDC93CC7B0B5DCB6A7051831F2EE6F397C971B843E1C10B66C4FB2EFF2A23DC07433E80FBF7B95E62C5B93E121AB5AD88354D9CB8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......fiB..38...*..ct...+......@.......A.......B.......C...@...D.......E...]...F.......G.......H.......I...#...P.......Q...6...R.......S.......T.......U.......V...G...W...k...X.......Y.......]..*....s...T...t.......................;..*....;..+....;..&....;..3....M..+!...O.......O...e...........}..+K...........=.......m..+w...t..........J...(5..9...+;..:y..+;..mW..+O..$...1...KY..D@......E@...Z..H4...l..HY..X&..H.......IC......J.......J...."..J......LD.....L.......PS...'..QR.. L..R...]...T.......U.......X.......Zr......[`......\.......]x......_....k.._....>..yg.. /..1...;....E..>....7..{(......%.......J........T.......&.......U...$..Y[...[......,...s...y.......y...a.......}......d...........9..Y....E..k'...........z...........V..........%..M....D...Q.......{......d.....A......E......K....5.......0.......0..&J...0.......0..k....5...*...5..I9.............._:.. D..,O.. D..W...+....9..<U...G..<U...*..<.......H5..,y..H5..W...H5......L....5..VE..!u..VE..E...V..."{..f.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):166167
                                                                                                                                                                                                                                                          Entropy (8bit):4.685212271435657
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:CLZ1w8McowCppcPwL5pYFw+G00QsbLckCiWxvq+sjs06oFm:C91wxcowspc4L5pUw+cz39CiQ7tloFm
                                                                                                                                                                                                                                                          MD5:1F41FF5D3A781908A481C07B35998729
                                                                                                                                                                                                                                                          SHA1:ECF3B3156FFE14569ECDF805CF3BE12F29681261
                                                                                                                                                                                                                                                          SHA-256:EDB32A933CEF376A2636634E14E2977CED6284E4AA9A4AC7E2292F9CA54C384A
                                                                                                                                                                                                                                                          SHA-512:A492E8AC88095A38A13549C18C68E1F61C7054AB9362C2B04C65B93E48E4A07941C8DA6950BAE79041094623E0ED330CA975110FDE8248B4D9380B9F729AD891
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......fr_FRB../....*..-....+.......@.......A.......B.......C...?...D.......E...\...F.......G.......H.......I..."...P.......Q...5...R.......S.......T.......U.......V...F...W...j...X.......Y.......]..+....s...=...t.......................;..+....;..,....;.......;..$b...;.......M..,....O.......O...5...........}..,3...........=.......m..,]...t..........A...(5..5j..+;..<T..+;..o...+O.."+..1...B\..D@......E@...Y..H4...8..HY..[{..H.......IC......J.......J.......J.......LD...|..L.......PS...?..QR..!...R...`j..T.......U....[..X.......Zr.....[`...)..\......]x......_....7.._.......yg...i..1...=Q...E..?@......"Y......K............................$..\....[...^...,...'...y.......y...+.......o....../c.......Y...9..\....E..6(...........z..!................j...%..OC...D...+.......[......a.....;......>......B....5.......0.......0...m...0..#....0.......0..6....5.......5..................a... D..-Y.. D..Ze..+....]..<U...;..<U......<.......H5..-...H5..Z...L.......VE.."...VE..?...V......
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189580
                                                                                                                                                                                                                                                          Entropy (8bit):4.630160941635514
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:SiaI3C87jhakhR0VGkw7ys7CskUH6y4e6IFB4xyMuhvDnJGhFaCo527arBbm07LZ:S2yGjh17yGqxTXhvQoejJd8FUjVgk
                                                                                                                                                                                                                                                          MD5:EB1FB93B0BE51C2AD78FC7BA2F8B9F42
                                                                                                                                                                                                                                                          SHA1:24F7FF809E2F11C579CD388FEA5A4C552FF8D4D0
                                                                                                                                                                                                                                                          SHA-256:63B439DD44139AA3AED54C2EBE03FA9BC77F22C14ED8FBA8EFF2608445BB233D
                                                                                                                                                                                                                                                          SHA-512:E13770AEF33B6666ED7D54E03EE20CA291D4167D673BA6C61D8E64CDD5F7FFE0A9521B95AF67BE719BF263932ECF16E2B2D0B5F3404F9BCD7879114FCC6FC474
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......gd_GBB..2....*...u...+......@.......A...B...B.......C.......D.. ....E.. ....F..!&...G..!J...H..!n...I..!....P..#m...Q..#....R..#....S..$....T..$$...U..$H...V..$....W..$....X..$....Y..%....]../....s...'...t...................F...;.......;../....;..=V...;..G....M../G...O.......O...k......$....}../o.......i...=.......m../....t..........[...(5..M...+;..@...+;..x...+O..:...1...\7..D@...f..E@..#...H4...p..HY..be..H.......IC......J.......J....R..J.......LD......L.......PS......QR..#l..R...g...T.......U.......X....\..Zr......[`......\...&...]x......_....C.._...'t..yg..?...1...BM...E..D.......;.......R'.......t.......@.......?...$..c....[......,...i...y.......y...Y.......f.......+...........9..c....E...............z.."....................%..U....D..................G.....UB.....W......\]...5.......0.......0..<....0...;...0.......5.......5..ij..............h... D..0... D..aC..+....K..<U.....<U...~..<.......H5..0...H5..a...L....1..VE..$...VE..X...V...8|..f...Z...f...=..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Qt Translation file
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):138690
                                                                                                                                                                                                                                                          Entropy (8bit):5.515748942553918
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:XSue8Z7T3iJsqBejt/zNHSLzdetY2ZISfC/S:XSueK3w7Ijt8zUtYAISfC/S
                                                                                                                                                                                                                                                          MD5:DEAF87D45EE87794AB2DC821F250A87A
                                                                                                                                                                                                                                                          SHA1:DB39C6BAA443AA9BB208043EF7FB7E3403C12D90
                                                                                                                                                                                                                                                          SHA-256:E1EBCA16AFE8994356F81CA007FBDB9DDF865842010FE908923D873B687CAD3F
                                                                                                                                                                                                                                                          SHA-512:276FCE81249EFFE19E95607C39F9ACB3A4AFA3F90745DA21B737A03FEA956B079BCA958039978223FD03F75AC270EC16E46095D0C6DDA327366C948EC2D05B9C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<.d....!..`.......he_ILB../....*......+..Sw...@......A......B.......C.......D...X...E.......F.../...G...O...H...o...I......P.......Q.......R...I...S...i...T......U......V.......W.......X.../...Y...O...]..$....s......t..X:.......4......`Y...;..$....;..%....;.......;...5...;.......M..$....O...6...O..s............}..%-...........=...m...m..%k...t..........^..(5......+;..2...+;..^...+O...N..1.......D@......E@...(..H4..T...HY..L...H..._...IC..\...J...\...J.......J...\j..LD..^...L...^o..PS..fl..QR......R...Q...T...su..U...s...X...x3..Zr..~...[`..L\..\.......]x....._......._....o..yg...(..1...3....E..5C.......z......?V......U.......U.......W....$..M....[..W....,..X....y.......y..\........a..............\@...9..NO...E...?......]s...z...G.......(......^....%..B^...D.._......._.................... ..........5..`/...0.......0...L...0......0..d(...0......5..ek...5..........fB......R... D..&O.. D..K...+...l...<U......<U..p)..<...p...H5..&w..H5..La..L...s...VE......VE......V.....
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1110
                                                                                                                                                                                                                                                          Entropy (8bit):3.5573268031592717
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:CdMHVBUlJvRj7SOVbusZhAMiZyi77q36AqE18wDyV8mK:iMMlBVnrAMiwMmq3E1LmK
                                                                                                                                                                                                                                                          MD5:9B4D1B95B20BD67555517DCC3007B22A
                                                                                                                                                                                                                                                          SHA1:2C0D6121DB49CDAB6FBAA81398BE2E44BE4E1110
                                                                                                                                                                                                                                                          SHA-256:6C15CB256B1C22170292589C6F589E64E164EB36EC7E84F0BD48149BABB7C5FC
                                                                                                                                                                                                                                                          SHA-512:34C3E401364D579E8AC7A4E1F1F7A29A84C62E1D5146D7664832639EA3997227DC4BAF1B64DC605E6574D680E61B55D0C69C329E35B1BEC41501FC68C5B634B7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: cp862, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..05D005D105D205D305D405D505D605D705D805D905DA05DB05DC05DD05DE05DF..05E005E105E205E305E405E505E605E705E805E905EA00A200A300A520A70192..00E100ED00F300FA00F100D100AA00BA00BF231000AC00BD00BC00A100AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1110
                                                                                                                                                                                                                                                          Entropy (8bit):3.518080906819747
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:CXHVBUlJvRj7SOVbusZhAMiZyi77qwGuXVFq5EC18wDyV8mK:eMlBVnrAMiwMmw3VFu1LmK
                                                                                                                                                                                                                                                          MD5:C93CCDF65F7F349F22855745660F02AE
                                                                                                                                                                                                                                                          SHA1:604888B1FB3C57DF47277CDD1153597BA89E8C36
                                                                                                                                                                                                                                                          SHA-256:232D6FE34D7151920232EAAE9C515F36400AB64136DCC5B802D6245AC6F5D56B
                                                                                                                                                                                                                                                          SHA-512:D5B65AE7353F694A37AF29177BF1A95477918FC5A002C2FE199624BD5B391698807BAECF54225BC40F62B3CA7912C7066A4AAF01B9E3E399133831CAA342BF4F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: cp863, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200C200E000B600E700EA00EB00E800EF00EE201700C000A7..00C900C800CA00F400CB00CF00FB00F900A400D400DC00A200A300D900DB0192..00A600B400F300FA00A800B800B300AF00CE231000AC00BD00BC00BE00AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1110
                                                                                                                                                                                                                                                          Entropy (8bit):3.72017408907567
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:CwHVBUlJvRj7YOVbusZhAMiZyi77qcHj92OibcDQAyUjSG:5MlrVnrAMiwMmSsNcDQvcSG
                                                                                                                                                                                                                                                          MD5:146E0D1779D50E070E0EF875E8374DF8
                                                                                                                                                                                                                                                          SHA1:B51E5598712598BC387DD79AE80BD879F139140D
                                                                                                                                                                                                                                                          SHA-256:81BEBFD9A61E9F17495763B68D57742FAB2A1A43871015699A2C8E5FDED4EC19
                                                                                                                                                                                                                                                          SHA-512:1F0DAD8E77712C5A018894332BE72FF5C546C92F481421CCB8553AD6F1E9A18617765C8CEE4187265CCCB1AB073E221289D34C9AB1F0501231D52C81FC1C932B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: cp864, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..00200021002200230024066A0026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00B000B72219221A259225002502253C2524252C251C25342510250C25142518..03B2221E03C600B100BD00BC224800AB00BBFEF7FEF8009B009CFEFBFEFC009F..00A000ADFE8200A300A4FE8400000000FE8EFE8FFE95FE99060CFE9DFEA1FEA5..0660066106620663066406650666066706680669FED1061BFEB1FEB5FEB9061F..00A2FE80FE81FE83FE85FECAFE8BFE8DFE91FE93FE97FE9BFE9FFEA3FEA7FEA9..FEABFEADFEAFFEB3FEB7FEBBFEBFFEC1FEC5FECBFECF00A600AC00F700D7FEC9..0640FED3FED7FEDBFEDFFE
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1110
                                                                                                                                                                                                                                                          Entropy (8bit):3.5193842128126676
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:CsKHVBUlJvRj7SOVbusZhAMiZyi77qZpuHVBnAFj18wDyV8mK:gMlBVnrAMiwMm+VRAFj1LmK
                                                                                                                                                                                                                                                          MD5:150B2E00B3F84F8075F3653ED7A4C8E0
                                                                                                                                                                                                                                                          SHA1:7131DC656EFE1F2277B19DA72F0EEB46B4EC54A0
                                                                                                                                                                                                                                                          SHA-256:ADA1A52064EE93EBE6F8A5D101D01F8776038E12F21A5CA1C006EE833577C705
                                                                                                                                                                                                                                                          SHA-512:AC56EEB0220826BF8FF6CA52768DB63961AAC46095A2F3EEBA11B5973CC92AF52DFBBE9E85A0DD04CAB8998212FA2599EDD83BAAA7FB2D394E330FF2F7C015DB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: cp865, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E400E000E500E700EA00EB00E800EF00EE00EC00C400C5..00C900E600C600F400F600F200FB00F900FF00D600DC00F800A300D820A70192..00E100ED00F300FA00F100D100AA00BA00BF231000AC00BD00BC00A100AB00A4..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1110
                                                                                                                                                                                                                                                          Entropy (8bit):3.5038992968715266
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:CCHVBUlJvRj7SOVbusZhAMiZyi77qb+SAJlz9aRme3cB18wDyVNZkR:bMlBVnrAMiwMm8YnsB1wZy
                                                                                                                                                                                                                                                          MD5:FC33B5F773E87696A69E8798446E9772
                                                                                                                                                                                                                                                          SHA1:4FC5589C1DD88BB8171758BC173A63B3A5687AE5
                                                                                                                                                                                                                                                          SHA-256:32A45DEBA933C7ED99141535087A4C99BA79802175E3F762ACA6EB941157F85A
                                                                                                                                                                                                                                                          SHA-512:332D2FEC532192F58F792441E61D675A8692C36BECF768D07F64B8C31561CC1A2DF402625A4719E758A9B59DE4228FFE9F94F067E7DC0D82F9DA2D6500E50304
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: cp866, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0410041104120413041404150416041704180419041A041B041C041D041E041F..0420042104220423042404250426042704280429042A042B042C042D042E042F..0430043104320433043404350436043704380439043A043B043C043D043E043F..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..0440044104420443044404
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1110
                                                                                                                                                                                                                                                          Entropy (8bit):3.5261138894265507
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:CtHVBUlJvRj7SOVbusZhAMiZyi77qii+lh2o5+hdVMQFhWgCDrKE:EMlBVnrAMiwMmXY2o5+hdVMQFhWf3f
                                                                                                                                                                                                                                                          MD5:4A2C66AA630D4AE2BF1E7546DCE2DAE5
                                                                                                                                                                                                                                                          SHA1:FABB672957D21CA2B4E0EACA5FCE6093BAACF77A
                                                                                                                                                                                                                                                          SHA-256:AFE6ED6EB5D07C45B6B928A48BC5EF57EFCF61602D36FF9FBDE4A8EA3FA6DF75
                                                                                                                                                                                                                                                          SHA-512:A548002EB7AF8735DBBBCC9883B44B326F261C02A3C7CE65C373755DD92212A66740112EAE0FC556CAD5B86911709C6DF12167DC5B6AD1E01C6F1EB5AB16DB37
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: cp869, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850386008700B700AC00A620182019038820150389..038A03AA038C00930094038E03AB00A9038F00B200B303AC00A303AD03AE03AF..03CA039003CC03CD039103920393039403950396039700BD0398039900AB00BB..25912592259325022524039A039B039C039D256325512557255D039E039F2510..25142534252C251C2500253C03A003A1255A25542569256625602550256C03A3..03A403A503A603A703A803A903B103B203B32518250C2588258403B403B52580..03B603B703B803B903BA03
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1110
                                                                                                                                                                                                                                                          Entropy (8bit):3.33737382140564
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:CSyHVBUlJvRj7SOVbusZhAMiZyi77qVQEHmEU4AyqU+TWwdd:CMlBVnrAMiwMmWr4AyqUSd
                                                                                                                                                                                                                                                          MD5:FC8C876B4738236FC71A1AF96E4566D0
                                                                                                                                                                                                                                                          SHA1:DDFDC3F62D99A6BD705CF0719B50F66449C8808A
                                                                                                                                                                                                                                                          SHA-256:4F05F31CA026BBFEEEE49ED86504CB060784137A9CFAE0E5954D276E837AB5DE
                                                                                                                                                                                                                                                          SHA-512:5BF58A810E029840825FFF3318E90415E6F2B7E46032FD428B4971923D41A64C127A6F438E4894E80EC9604CD34F1D47B4F9A02ABAB3E7D6351611811DC1F2B9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: cp874, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC008100820083008420260086008700880089008A008B008C008D008E008F..009020182019201C201D20222013201400980099009A009B009C009D009E009F..00A00E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F..0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F..0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F..0E300E310E320E330E340E350E360E370E380E390E3A00000000000000000E3F..0E400E410E420E430E440E
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):49008
                                                                                                                                                                                                                                                          Entropy (8bit):3.5144574650895364
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:R/RPrUHiJrKWkyY/W2wHiwWnwWOORY+gutSY83+JRS:RVUidzJCurDGSYvW
                                                                                                                                                                                                                                                          MD5:EF4508C84A025095B183E6BAD67B1ECD
                                                                                                                                                                                                                                                          SHA1:D12D5381D50D578AA8687671DC542C462A7F490D
                                                                                                                                                                                                                                                          SHA-256:6D1B512110BEAF2CD1296AC878F51D567848AB4A1CED4F18C72806BB136B3D23
                                                                                                                                                                                                                                                          SHA-512:E695E7E6F4A11D5E8D62982E26B69B87DB2F1F3D6B6DCCD5F1DF51879F5C4533265CBD7B785E1F2652D8CA3FC913D4F862E7575F67C636314A6E6956FD96E023
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: cp932, multi-byte..M..003F 0 46..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080000000000000000000850086000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..0000000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):134671
                                                                                                                                                                                                                                                          Entropy (8bit):3.5217328918779645
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:+CwDua7D90Jz1aDJmnMfEGniOQdH6prJs3inqlW6/t9Qwf+zCt5:j1WVRpe3rpt9hf+Gt5
                                                                                                                                                                                                                                                          MD5:CF9CFD6329A4FB6C402052B9417DAC3A
                                                                                                                                                                                                                                                          SHA1:75CE13FE1E5898D47B67F951C0C228851F1CC04D
                                                                                                                                                                                                                                                          SHA-256:B6EC2BE0504CA62B9D1B6857F6BAA13FFAC5A567D4432F4EAB98ADC830F5D9C3
                                                                                                                                                                                                                                                          SHA-512:7E19607EEA5342ECFE92D56DAAE82827DE147AE5AFDA8E9D67FD0970F528902CDE20A8A07CF2F341B926E59BB4FF792872976F1C7C5CD351959A71A8B6A1924A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: cp936, multi-byte..M..003F 0 127..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):132551
                                                                                                                                                                                                                                                          Entropy (8bit):3.100976362851161
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:2UO8ecy5KnSMsDlOmNpkQ4oQHnTApv+ngLbiyEY:2U/etc/sBRZp//r
                                                                                                                                                                                                                                                          MD5:03E19A4DE3490A7DC50D04EC1F558835
                                                                                                                                                                                                                                                          SHA1:9DFECAE08C98109EAA358F5920AED647888F722B
                                                                                                                                                                                                                                                          SHA-256:477F8B79B67F4A22C963EE65B9B387DBD8E4B8F62D800B0A51D2276580C6ADBB
                                                                                                                                                                                                                                                          SHA-512:7D6AD30AF75A3AA6332A860C6ABF87BF725EB6B4AF3B37699043A10EF3235471C63D0ECB4D437D5AD9438DF5DA646EB55117A9BB8B55EF6868F71E49035C18B7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: cp949, multi-byte..M..003F 0 125..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):93330
                                                                                                                                                                                                                                                          Entropy (8bit):3.319807723045599
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:aAHU3LIkZlmXrd/uQ0ao98ggKSTEvZPHb6qRL5NpiadDp0ZBFR6YR/fW:aVduBGf9PgFMT6q95GDRBfW
                                                                                                                                                                                                                                                          MD5:1D84B025DAB127F2073947D764D307B6
                                                                                                                                                                                                                                                          SHA1:4E3D3CBD96D084836F1FE6F2AA497E3FAA463B9B
                                                                                                                                                                                                                                                          SHA-256:F80E05533D1A1494C32F9412E9AD2D9C11FAF9AE0668A6F9D1FA5CEEDC6870E2
                                                                                                                                                                                                                                                          SHA-512:188D649F9717F20524AFF47F85C3B23AEC3E7825BF54975285D06C17587D581DC24A3F6A7CAB1703DE7AD5521FE2FE2572DE627A81E6A48049A47BB219ED4AF8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: cp950, multi-byte..M..003F 0 88..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1113
                                                                                                                                                                                                                                                          Entropy (8bit):3.7780987266961663
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:vJMHkUlJvRjmf9RCsUBOdXsCbbNviANpk3m1XFAoE4xSF5HrBPkdn:vKvlA9RCs6CXrViAN51XFA9eSvdPKn
                                                                                                                                                                                                                                                          MD5:90FE0C57BBC6C2D8A3324DEB7FD45F3D
                                                                                                                                                                                                                                                          SHA1:06B95BE43E4C859A0F1B01384EDD26500C6C1F9E
                                                                                                                                                                                                                                                          SHA-256:EB9B262E4D179268E6F017C0D4EF0E7034E31A5B4893595D150640CA1F6A1C45
                                                                                                                                                                                                                                                          SHA-512:6A5E67D9F3EC6046C42793E1437B8A6E50EBD72D8EC67FEFEB6DAD6FAB6A5B5C74F939363587D5A6529E217AF54FB8A9CF0F768E114DD931C57887451CACE56E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: dingbats, single-byte..S..003F 1 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..00202701270227032704260E2706270727082709261B261E270C270D270E270F..2710271127122713271427152716271727182719271A271B271C271D271E271F..2720272127222723272427252726272726052729272A272B272C272D272E272F..2730273127322733273427352736273727382739273A273B273C273D273E273F..2740274127422743274427452746274727482749274A274B25CF274D25A0274F..27502751275225B225BC25C6275625D727582759275A275B275C275D275E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000276127622763276427652766276726632666266526602460246124622463..2464246524662467246824692776277727782779277A277B277C277D277E277F..2780278127822783278427852786278727882789278A278B278C278D278E278F..2790279127922793279421922194219527982799279A279B279C279D279E279F..27A027A127A227A327A
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1073
                                                                                                                                                                                                                                                          Entropy (8bit):3.0039861897954805
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:XXBcIhJZDgEoQkNCGz0Jyh9lZk3Vmd2QhZLXPiALV3d:dTcNCJEhfZk3Vzox/iqVN
                                                                                                                                                                                                                                                          MD5:F7B3771D43BDE6AFF897683BED2FE6AD
                                                                                                                                                                                                                                                          SHA1:E70C2C0902413536CB6163752D70F3AE4AF6A967
                                                                                                                                                                                                                                                          SHA-256:165BE658AB7D61FFC3DF1E2F1438C2F9FCEE6808A756316302157F44E6D3ACD7
                                                                                                                                                                                                                                                          SHA-512:F87DC718EB2DD95237B144FDA090BB636121B9479E492AC94E4F7EBDD88171F070B9E9F6165BDA7B7E2BA2A3E6188B1108D8F91AA5F142CCCFDAD317628DD941
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:S..006F 0 1..00..0000000100020003008500090086007F0087008D008E000B000C000D000E000F..0010001100120013008F000A0008009700180019009C009D001C001D001E001F..0080008100820083008400920017001B00880089008A008B008C000500060007..0090009100160093009400950096000400980099009A009B00140015009E001A..002000A000E200E400E000E100E300E500E700F10060002E003C0028002B007C..002600E900EA00EB00E800ED00EE00EF00EC00DF00210024002A0029003B009F..002D002F00C200C400C000C100C300C500C700D1005E002C0025005F003E003F..00F800C900CA00CB00C800CD00CE00CF00CC00A8003A002300400027003D0022..00D800610062006300640065006600670068006900AB00BB00F000FD00FE00B1..00B0006A006B006C006D006E006F00700071007200AA00BA00E600B800C600A4..00B500AF0073007400750076007700780079007A00A100BF00D000DD00DE00AE..00A200A300A500B700A900A700B600BC00BD00BE00AC005B005C005D00B400D7..00F900410042004300440045004600470048004900AD00F400F600F200F300F5..00A6004A004B004C004D004E004F00500051005200B900FB00FC00DB00FA00FF..00D900F70053005400550056005700580059005A00B200D400D600D200D
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):86971
                                                                                                                                                                                                                                                          Entropy (8bit):2.3925661740847697
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:UHivP+bFFScXEBFhHeUrUFESCeYjN7GC0nYX:I7FFX2nHeUr8ESCDlX
                                                                                                                                                                                                                                                          MD5:C5AA0D11439E0F7682DAE39445F5DAB4
                                                                                                                                                                                                                                                          SHA1:73A6D55B894E89A7D4CB1CD3CCFF82665C303D5C
                                                                                                                                                                                                                                                          SHA-256:1700AF47DC012A48CEC89CF1DFAE6D1D0D2F40ED731EFF6CA55296A055A11C00
                                                                                                                                                                                                                                                          SHA-512:EEE6058BD214C59BCC11E6DE7265DA2721C119CC9261CFD755A98E270FF74D2D73E3E711AA01A0E3414C46D82E291EF0DF2AD6C65CA477C888426D5A1D2A3BC5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: euc-cn, multi-byte..M..003F 0 82..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):83890
                                                                                                                                                                                                                                                          Entropy (8bit):2.350315390677456
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2GhX8nuQ635vlHptHzh0abNQPQA0OMS2HhFV3:2GikvRpMuNQ4P73
                                                                                                                                                                                                                                                          MD5:F2DE0AE66A4E5DD51CC64B08D3709AAB
                                                                                                                                                                                                                                                          SHA1:97558A51A6DD6C56FC7A42A4204141A5639021FD
                                                                                                                                                                                                                                                          SHA-256:A3C916BA16BCAC9FAA5A1CCC62ACA61452D581CD8BA3EE07EC39122C697274C9
                                                                                                                                                                                                                                                          SHA-512:0EAA90100527FF150D2653D7BB57647D69E592BE53B714DDD867114CFCC71E3A76882772F4FAECE040DF09FA8971D1C22DECC497E589B4CA827A6890497A48D9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: euc-jp, multi-byte..M..003F 0 79..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D0000008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):95451
                                                                                                                                                                                                                                                          Entropy (8bit):2.4080588863614136
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:4/vO7UlClqAd8XfpUqv+mCoKRuLbtMjnIxz0DY:4nO4N9fpv+ngLbiyEY
                                                                                                                                                                                                                                                          MD5:103843B3A57168BD574F6CACC550D439
                                                                                                                                                                                                                                                          SHA1:982652EA2B0DCFBB55970E019A4EDFBFCFAF9C24
                                                                                                                                                                                                                                                          SHA-256:5448643398685456A11CBB93AF2321F70B8659E2FFF3CCC534B4D53BD2F38C89
                                                                                                                                                                                                                                                          SHA-512:27A8DE6F97DB4A96E5D0132692A32A99DAB8A6C98973A0C4E50A219F2D2F364E63D657E5E8478B2706CA33C45C376F55B5BFCC9459E06AEA88BFCD4F0E32525C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: euc-kr, multi-byte..M..003F 0 90..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):88033
                                                                                                                                                                                                                                                          Entropy (8bit):2.3790651802316996
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:o4Is/C+0IwpRK1CkinIKUyNiNBzxOC4T/:LIsR0/RKckiIgNiDtOxT
                                                                                                                                                                                                                                                          MD5:1A8E55DEA98B6D5EAC731ED233D3AD7C
                                                                                                                                                                                                                                                          SHA1:1335FC0FC2AAE7E7F5EC42AC17A4168368B4A64D
                                                                                                                                                                                                                                                          SHA-256:B4894AEDD2D5B5AE54B6D2840F7C89A88E9308EFD288F179E65936E172EF4B0D
                                                                                                                                                                                                                                                          SHA-512:9DDCE366BA1196EB9FB913ACFDE8516BC9BB8D51894866D2E7E8CB313DC4D6C6D33C5A9E78142E83594DC423D10DA6F8DE211E69844B939198BC7DB9AED808F0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: gb12345, double-byte..D..233F 0 83..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000030003001300230FB02C902C700A8300330052015FF5E2225202620182019..201C201D3014301530083009300A300B300C300D300E300F3016301730103011..00B100D700F72236222722282211220F222A222922082237221A22A522252220..23122299222B222E2261224C2248223D221D2260226E226F22642265221E2235..22342642264000B0203220332103FF0400A4FFE0FFE1203000A7211626062605..25CB25CF25CE25C725C625A125A025B325B2203B219221902191219330130000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1111
                                                                                                                                                                                                                                                          Entropy (8bit):3.270324851474969
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:qrmHVBUlJvRj76OVbusZhAMiZyi77qN8VmKfkiJt0RMFS:qSMlZVnrAMiwMmNPYPFS
                                                                                                                                                                                                                                                          MD5:D06664ACAA478BDEB42B63941109A4E3
                                                                                                                                                                                                                                                          SHA1:4A6196FCC1BDE988C1A23EAA69745A9979F1AEFF
                                                                                                                                                                                                                                                          SHA-256:ACD50951F81566C8D823670F9957B2479102EB5AE4CF558453E1D8436A9E31FF
                                                                                                                                                                                                                                                          SHA-512:CB51A36B851FFDB5C6F9B9D0333EEA6A14CEF3796E0A60530198C16999D64E638047E873333630360299C9126F79CEDDA2D9F169028CED1FC04B1D3C55FFFC5B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: gb1988, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..002000210022002300A500250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D203E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..000000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):85912
                                                                                                                                                                                                                                                          Entropy (8bit):2.3945751552930936
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:D47/S+i8vdx3Tz+hpHcBrQqKtrebjMIGCx8jE:0c873T6DHcBrbKtrVlE
                                                                                                                                                                                                                                                          MD5:9357E05C74D6A124825F46A42B280C14
                                                                                                                                                                                                                                                          SHA1:E5106ABE12D991AFE514F41E3B9E239202A4ADFE
                                                                                                                                                                                                                                                          SHA-256:C445E4C9F676AE997D2DDA2BBC107B746F3547D85F39479951C56F46275EE355
                                                                                                                                                                                                                                                          SHA-512:B2187D70A92FB38572BA46F3C3443233BEED1A4ABBFBA1B860F4BBAE6B3D8C16B8C9F52A20DAA12B2B8B40972E52F816860427B743530177E4CF0D8BA34EF381
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: gb2312, double-byte..D..233F 0 81..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000030003001300230FB02C902C700A8300330052015FF5E2225202620182019..201C201D3014301530083009300A300B300C300D300E300F3016301730103011..00B100D700F72236222722282211220F222A222922082237221A22A522252220..23122299222B222E2261224C2248223D221D2260226E226F22642265221E2235..22342642264000B0203220332103FF0400A4FFE0FFE1203000A7211626062605..25CB25CF25CE25C725C625A125A025B325B2203B219221902191219330130000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):86971
                                                                                                                                                                                                                                                          Entropy (8bit):2.3925661740847697
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:UHivP+bFFScXEBFhHeUrUFESCeYjN7GC0nYX:I7FFX2nHeUr8ESCDlX
                                                                                                                                                                                                                                                          MD5:C5AA0D11439E0F7682DAE39445F5DAB4
                                                                                                                                                                                                                                                          SHA1:73A6D55B894E89A7D4CB1CD3CCFF82665C303D5C
                                                                                                                                                                                                                                                          SHA-256:1700AF47DC012A48CEC89CF1DFAE6D1D0D2F40ED731EFF6CA55296A055A11C00
                                                                                                                                                                                                                                                          SHA-512:EEE6058BD214C59BCC11E6DE7265DA2721C119CC9261CFD755A98E270FF74D2D73E3E711AA01A0E3414C46D82E291EF0DF2AD6C65CA477C888426D5A1D2A3BC5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: euc-cn, multi-byte..M..003F 0 82..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):204
                                                                                                                                                                                                                                                          Entropy (8bit):4.949409835601965
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SOd5MNXVSVLqRIBXS4ovLE9sDXMVyXK9ow1Deq9Ts5dRPMSXcRA0kcR4X9cL+TXI:SVNFS0oyisLMsXK9okTw/BDSVKNw
                                                                                                                                                                                                                                                          MD5:D3AC33390D31705FA4486D0B455247DF
                                                                                                                                                                                                                                                          SHA1:2EE8613DC04A6FA84AB38FD5F3A2AA3FE330625B
                                                                                                                                                                                                                                                          SHA-256:98074C85650A420A095ADA9138DA3A8A0AA4027BE47EA1E97A596F319EB084E9
                                                                                                                                                                                                                                                          SHA-512:CB265B753C84968E2D1D6E706906DA9A7BB796D08F626290BCCA8F089771AFD176A9DC912773E8BA390D2AEC08592AD535C7D254E1DF92CF04848601481D4EFE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso2022-jp, escape-driven..E..name..iso2022-jp..init..{}..final..{}..ascii..\x1b(B..jis0201..\x1b(J..jis0208..\x1b$B..jis0208..\x1b$@..jis0212..\x1b$(D..gb2312..\x1b$A..ksc5601..\x1b$(C..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):122
                                                                                                                                                                                                                                                          Entropy (8bit):4.978693690727393
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SOd5MNXVTEXIBXS4ovLE9sDXNvdwUHEQwqc6XWxVUNOov:SVNFSoyisL/Zzc6mYNHv
                                                                                                                                                                                                                                                          MD5:057CB0AA9872AC3910184F67AC6621BC
                                                                                                                                                                                                                                                          SHA1:BBA47F9D76B6690C282724C3423BD94E2C320A04
                                                                                                                                                                                                                                                          SHA-256:234811FC8B0F8FF2B847D9CC3982F1699DF1D21A43C74DCE45BA855D22520007
                                                                                                                                                                                                                                                          SHA-512:019F187D2D16FB51BF627ACB7E67778857E56D4C160E0E5ACA6ABC05EC5FDB624CE2715CB9E0DAD73BFF9D697982BE0D539BC55BCCD368FC7C8EE0FFC04E9F61
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso2022-kr, escape-driven..E..name..iso2022-kr..init..\x1b$)C..final..{}..iso8859-1.\x0f..ksc5601..\x0e..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):240
                                                                                                                                                                                                                                                          Entropy (8bit):4.95909788984399
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SVNFUXoyisLNcs9ozc6W4Twk0sRBDSVKN6tWIHRy:oUYcLNcTzczbwRYRy
                                                                                                                                                                                                                                                          MD5:BB186D4BE3FA67DD3E2DEE82DD8BD628
                                                                                                                                                                                                                                                          SHA1:93CE8627038780CFFF8C06E746DD5FB2B041115C
                                                                                                                                                                                                                                                          SHA-256:741B4C842557EED2952936204D0AE9C35FA3A0F02F826D94C50C46976291797C
                                                                                                                                                                                                                                                          SHA-512:4921E7AA3DB8E33609603FE129B97275DFF80CFB06648D2068FA7950246C67B9B530B74827638F69F4DFB8F55CDD4AA952EA72EAEB6ABB527D52F20C6B46FB51
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso2022, escape-driven..E..name..iso2022..init..{}..final..{}..iso8859-1.\x1b(B..jis0201..\x1b(J..gb1988..\x1b(T..jis0208..\x1b$B..jis0208..\x1b$@..jis0212..\x1b$(D..gb2312..\x1b$A..ksc5601..\x1b$(C..jis0208..\x1b&@\x1b$B..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1114
                                                                                                                                                                                                                                                          Entropy (8bit):3.236046263464657
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:iyHVBUlJvRj7SOVbusZhAMiZyi77qimmvGNNlkL+rSMH+tKv:iyMlBVnrAMiwMmTmokLz0
                                                                                                                                                                                                                                                          MD5:3538A970CD098BF5CE59005FE87B6626
                                                                                                                                                                                                                                                          SHA1:285A96CC40D7CCE104FB4B407C7F0C400AA8F9CB
                                                                                                                                                                                                                                                          SHA-256:A9CB4F4CA111608F882729BC5EB1C2F15530C515EF02DD2CA62F2D8DC5A210CF
                                                                                                                                                                                                                                                          SHA-512:A6A6F2D8B5C22E240D195D168A604887062508FF3340D24E13BFCBD6C2E687347F2CFE724FA2ED12F36915B55EE2CFD901EC3F08E2B0A2FFD3BC2A98BBD12A50
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-1, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..00D000D100D200D300D400D500D600D700D800D900DA00DB00DC00DD00DE00DF..00E000E100E200E300
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1115
                                                                                                                                                                                                                                                          Entropy (8bit):3.319750415373386
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:jHVBUlJvRj7SOVbusZhAMiZyi77qimXG2yM6q7KytC:jMlBVnrAMiwMmTXG2gytC
                                                                                                                                                                                                                                                          MD5:CBDE40170FECD2496A9DA3CF770FAB7B
                                                                                                                                                                                                                                                          SHA1:3E1D74DF6AFEB6CDE8ECBDAC8F81F2F9C64150DE
                                                                                                                                                                                                                                                          SHA-256:48F4A239C25354F0E9F83A39F15D4632BB18A9C33E60C671C67307159917ECED
                                                                                                                                                                                                                                                          SHA-512:A26B56A4CFE29E5A0A0B3A55283A7767397693388E2DEEC342C69B6F718FAE2407EB8D5ADE538FAE6947CBB8B052943C3A52F2D046ABAC7A3DAA86D730DC293F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-10, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0010401120122012A0128013600A7013B011001600166017D00AD016A014A..00B0010501130123012B0129013700B7013C011101610167017E2015016B014B..010000C100C200C300C400C500C6012E010C00C9011800CB011600CD00CE00CF..00D00145014C00D300D400D500D6016800D8017200DA00DB00DC00DD00DE00DF..010100E100E200E30
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1115
                                                                                                                                                                                                                                                          Entropy (8bit):3.3206399689840476
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:6HVBUlJvRj7SOVbusZhAMiZyi77qimwHmEU4AyqU+TWwdd:6MlBVnrAMiwMmTf4AyqUSd
                                                                                                                                                                                                                                                          MD5:E2A0BCB83BFC3F435CDCFC20D5CF2E0C
                                                                                                                                                                                                                                                          SHA1:CFD18B5B5DB4EE46E63D912B8FD66D513C4C8D39
                                                                                                                                                                                                                                                          SHA-256:21E769C5A66E4D12D6E7DB24022E92AF1EC0D0331FE3C8C605654F239C0F3640
                                                                                                                                                                                                                                                          SHA-512:C86F9180F2F4A177F1EA10E26B0903ABEAFDDE0317C332A48F8D1BB586DAC91C68800E2E4FA2CD739C435419B106CBA4BEFC049F2BCD720E9FC2C0AE8436CFAC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-11, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A00E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F..0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F..0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F..0E300E310E320E330E340E350E360E370E380E390E3A00000000000000000E3F..0E400E410E420E430
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1115
                                                                                                                                                                                                                                                          Entropy (8bit):3.338879965076632
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:olHVBUlJvRj7SOVbusZhAMiZyi77qim2w4kBUioGnd2:olMlBVnrAMiwMmT/WNI2
                                                                                                                                                                                                                                                          MD5:21CEBB723D47B1450A7FB21A82470B97
                                                                                                                                                                                                                                                          SHA1:A40FD3AFE1ECE89E3F682D527D281BC563DB3892
                                                                                                                                                                                                                                                          SHA-256:3271D39D7B4DCD841E8E5D5153D1B8837718B88FEFEC73DC37D314816EEFE5E5
                                                                                                                                                                                                                                                          SHA-512:3A0E033A4D93C679215F672C6C4FE425D63E1DE157AA671E7400639165EC3EB498E4EEB030D6FB8FF8BE2FD8C986D341036A8CED9FA094D092CF2822D5DC065B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-13, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0201D00A200A300A4201E00A600A700D800A9015600AB00AC00AD00AE00C6..00B000B100B200B3201C00B500B600B700F800B9015700BB00BC00BD00BE00E6..0104012E0100010600C400C501180112010C00C90179011601220136012A013B..01600143014500D3014C00D500D600D701720141015A016A00DC017B017D00DF..0105012F010101070
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1115
                                                                                                                                                                                                                                                          Entropy (8bit):3.3670559016263915
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:vHVBUlJvRj7SOVbusZhAMiZyi77qimhw6COlk1fKMH+tiH:vMlBVnrAMiwMmT/tlkQz0
                                                                                                                                                                                                                                                          MD5:FDAA88946DE4EB4E6D37F2B6AFCF6CAF
                                                                                                                                                                                                                                                          SHA1:56FC4773941E7457EA04EDA92C883642DE45D100
                                                                                                                                                                                                                                                          SHA-256:F0A5675027FB1CA34B4E4128D24C2968CD275890569A32A86AFA4994CE4983E0
                                                                                                                                                                                                                                                          SHA-512:92658A6FEB42A41B3CFFC377C4A9A3F6780A79FC596D3FEDBA6D3B3D75A9F40E859A2CE8DC579A278BAEEDEEFA2408E2B7853D99D5C2D14AACF63C521FE2BB86
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-14, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A01E021E0300A3010A010B1E0A00A71E8000A91E821E0B1EF200AD00AE0178..1E1E1E1F012001211E401E4100B61E561E811E571E831E601EF31E841E851E61..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..017400D100D200D300D400D500D61E6A00D800D900DA00DB00DC00DD017600DF..00E000E100E200E30
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1115
                                                                                                                                                                                                                                                          Entropy (8bit):3.260398494526282
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:mHVBUlJvRj7SOVbusZhAMiZyi77qimmRf4kL+rSMH+tKv:mMlBVnrAMiwMmTmCkLz0
                                                                                                                                                                                                                                                          MD5:D779D5E2A0083C616A226B2D82ABF0EB
                                                                                                                                                                                                                                                          SHA1:D1657DB5E2989EBA80BAB98A1E1217CFFFBB19DB
                                                                                                                                                                                                                                                          SHA-256:C74E8E23A0FF0D5DEA7C318CA20DC817DA4E57B0DD61B3361FC0D5098A9316FE
                                                                                                                                                                                                                                                          SHA-512:26E62BE8AE793ED3B725BF0D1BABF4D6ED63A6F3772ABD48955FC4394BDE5A47614D1FF89A21A828676BF1302F3C9361B557B0FBF0DF8561FB7E66542FE94CDC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-15, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A000A100A200A320AC00A5016000A7016100A900AA00AB00AC00AD00AE00AF..00B000B100B200B3017D00B500B600B7017E00B900BA00BB01520153017800BF..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..00D000D100D200D300D400D500D600D700D800D900DA00DB00DC00DD00DE00DF..00E000E100E200E30
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1115
                                                                                                                                                                                                                                                          Entropy (8bit):3.3065938185320918
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:dHVBUlJvRj7SOVbusZhAMiZyi77qim0SmmPkYTtyL:dMlBVnrAMiwMmTttPkYpyL
                                                                                                                                                                                                                                                          MD5:74FDEDDAF670023DA7751FB321E345A0
                                                                                                                                                                                                                                                          SHA1:0677FED67C1333A9A74D50642E5214701A57E2AF
                                                                                                                                                                                                                                                          SHA-256:640D977EC1D22B555C5075798DA009E3523E8F55F29BE22A3050CD1B4EF7B80E
                                                                                                                                                                                                                                                          SHA-512:AC02FD95159A856A9DDEF4E6A8216B958DC07311B553FF39403DC5B77E1AFF2A2C4C03F5F26A2BB7AD5DB6800BEE03E895554556DBBFBE89426286796ADE55AC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-16, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A001040105014120AC201E016000A7016100A9021800AB017900AD017A017B..00B000B1010C0142017D201D00B600B7017E010D021900BB015201530178017C..00C000C100C2010200C4010600C600C700C800C900CA00CB00CC00CD00CE00CF..0110014300D200D300D4015000D6015A017000D900DA00DB00DC0118021A00DF..00E000E100E201030
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1114
                                                                                                                                                                                                                                                          Entropy (8bit):3.340505173539446
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:UHVBUlJvRj7SOVbusZhAMiZyi77qim/ssm5VO6ys2K:UMlBVnrAMiwMmT/ssYTys2K
                                                                                                                                                                                                                                                          MD5:9B87850646FFE79F3C8001CBCB5BB3A1
                                                                                                                                                                                                                                                          SHA1:8F97576F3FB3B5DBEF71DC2C9314AB5E530974D6
                                                                                                                                                                                                                                                          SHA-256:76949B03F57041B07F41902BD7505AB3594D79AA8F7BDEED5F0481004B10CBC3
                                                                                                                                                                                                                                                          SHA-512:101A28AF0799E7E0A5723E5DD76D5EF0FEEF584AC479A88F499CB3B7D2AA93767D72F8E51C76F7547F08FF8DD3CBBA7FF444BD07F99A92755526E75C596109EF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-2, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0010402D8014100A4013D015A00A700A80160015E0164017900AD017D017B..00B0010502DB014200B4013E015B02C700B80161015F0165017A02DD017E017C..015400C100C2010200C40139010600C7010C00C9011800CB011A00CD00CE010E..01100143014700D300D4015000D600D70158016E00DA017000DC00DD016200DF..015500E100E2010300
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1114
                                                                                                                                                                                                                                                          Entropy (8bit):3.2507537230559977
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:tHVBUlJvRj7SOVbusZhAMiZyi77qimw2g0kgTJMkFtoD:tMlBVnrAMiwMmTo0kgTJDoD
                                                                                                                                                                                                                                                          MD5:CBD0B9CDCD9BC3D5F2429A760CF98D2F
                                                                                                                                                                                                                                                          SHA1:6DEF0343E0357E0671002A5D2F0BFC2E00C8BCF9
                                                                                                                                                                                                                                                          SHA-256:1F51E7BDA64D466C16FEE9A120BBE3353A10CEB9DAB119FFA326779BA78D8C5D
                                                                                                                                                                                                                                                          SHA-512:88DB6D23B53F4A78133C794ED42FA3F29A4ABAD35DE4B022040FA187AA59B00664CC13F47AFF4507D72F4CB2166F026144213EE760AB0FD67CDD2FA5906F434A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-3, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0012602D800A300A40000012400A700A80130015E011E013400AD0000017B..00B0012700B200B300B400B5012500B700B80131015F011F013500BD0000017C..00C000C100C2000000C4010A010800C700C800C900CA00CB00CC00CD00CE00CF..000000D100D200D300D4012000D600D7011C00D900DA00DB00DC016C015C00DF..00E000E100E2000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1114
                                                                                                                                                                                                                                                          Entropy (8bit):3.3413832766873073
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:KHVBUlJvRj7SOVbusZhAMiZyi77qimX4AsD/njR7Ky8hA:KMlBVnrAMiwMmTXBs3EyuA
                                                                                                                                                                                                                                                          MD5:8B620EDECAC2DF15A024C2CE15FB64A5
                                                                                                                                                                                                                                                          SHA1:65C5EE5D08964E37393E6A78ABA0DB16D51240E2
                                                                                                                                                                                                                                                          SHA-256:66B3CF994F0B5E0103D13E812958320AFB555C91E3F81B579D4CBF231E6A0805
                                                                                                                                                                                                                                                          SHA-512:93391325405D3AEA0A913F5EA8EA0391920D10F234C26AB1DA70992702889A3AF7B85E11A1FCA554690942B238CE313DD460798E59C5B1F4069036E7B0F24F44
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-4, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A001040138015600A40128013B00A700A8016001120122016600AD017D00AF..00B0010502DB015700B40129013C02C700B80161011301230167014A017E014B..010000C100C200C300C400C500C6012E010C00C9011800CB011600CD00CE012A..01100145014C013600D400D500D600D700D8017200DA00DB00DC0168016A00DF..010100E100E200E300
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1114
                                                                                                                                                                                                                                                          Entropy (8bit):3.342721205983665
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:zHVBUlJvRj7SOVbusZhAMiZyi77qimq5+SAJlz9aRme3cJbx:zMlBVnrAMiwMmTqeYnsJbx
                                                                                                                                                                                                                                                          MD5:6FBEFDC3DEC612B7B2CC903D8C53F45B
                                                                                                                                                                                                                                                          SHA1:14EC3C166DC411149C32C262DBE8E327F6186669
                                                                                                                                                                                                                                                          SHA-256:3130BF26DA0C840C1E02203A90C3B1C38966FB203130E2FBB3DD7CB3865A3539
                                                                                                                                                                                                                                                          SHA-512:F3F15AD8B6C9D9B4C9C994FE3235B4463E59BE7DCE79CF3F7AA77905D6F4DC2C4AABB79B440767DB13D357B13F09EA34983FCA7BC92D0AFA15FB6CBEDDD04E38
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-5, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0040104020403040404050406040704080409040A040B040C00AD040E040F..0410041104120413041404150416041704180419041A041B041C041D041E041F..0420042104220423042404250426042704280429042A042B042C042D042E042F..0430043104320433043404350436043704380439043A043B043C043D043E043F..044004410442044304
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1114
                                                                                                                                                                                                                                                          Entropy (8bit):2.992219341429816
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:YHVBUlJvRj7SOVbusZhAMiZyi77qimEZjyG/KE:YMlBVnrAMiwMmTEs6KE
                                                                                                                                                                                                                                                          MD5:52F025D943A45EE840D9C3DFD06E4D79
                                                                                                                                                                                                                                                          SHA1:571EA14B49FA6150BFD2ABA79E52799955D9FA10
                                                                                                                                                                                                                                                          SHA-256:CB71909BF01A3A7A4C7396359DA06D206B58A42AD68192CE37169D6640D46E13
                                                                                                                                                                                                                                                          SHA-512:77FF9DC785A63CA59A7D58BB25C7D2C16F364E525F9B939177385EF80F7DE37734C8774F1BC829CF0270FD66257A4D31689654C8037DB0A86A0291FFDE637B90
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-6, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A000000000000000A40000000000000000000000000000060C00AD00000000..00000000000000000000000000000000000000000000061B000000000000061F..0000062106220623062406250626062706280629062A062B062C062D062E062F..0630063106320633063406350636063706380639063A00000000000000000000..064006410642064306
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1114
                                                                                                                                                                                                                                                          Entropy (8bit):3.393893260854861
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:TMyHVBUlJvRj7SOVbusZhAMiZyi77qim2OBHK9QQSqiWeIDDdn:TlMlBVnrAMiwMmT1hKyQSqiWeIVn
                                                                                                                                                                                                                                                          MD5:4BFB0A35D971A9D4C5EA8D8099E93C37
                                                                                                                                                                                                                                                          SHA1:8FED2CBB1343E5B4442748242B5F89A76110592D
                                                                                                                                                                                                                                                          SHA-256:76F6BC85FC9CB89BC3F94D36275AB23C740BA17FD36EC8907479DA3A885415EA
                                                                                                                                                                                                                                                          SHA-512:C9CE1E9EA57A1DEF62BBC60A115C06325C6EE8F92021695459E1ADAF1193A559BC5F0229191BFC2E344296DC137583ED4A9A61A65890F99F4CF97B3864C7AF0F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-7, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A02018201900A320AC20AF00A600A700A800A9037A00AB00AC00AD00002015..00B000B100B200B303840385038600B703880389038A00BB038C00BD038E038F..0390039103920393039403950396039703980399039A039B039C039D039E039F..03A003A1000003A303A403A503A603A703A803A903AA03AB03AC03AD03AE03AF..03B003B103B203B303
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1114
                                                                                                                                                                                                                                                          Entropy (8bit):3.0494739426493567
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:uHVBUlJvRj7SOVbusZhAMiZyi77qimieGlnvs26Kcv:uMlBVnrAMiwMmTirv87
                                                                                                                                                                                                                                                          MD5:5F69EAF54E7A1E8AC81C9E734DBE90D8
                                                                                                                                                                                                                                                          SHA1:BA509C88A4FC03922EF5CDC887FAA7B594A9BC5A
                                                                                                                                                                                                                                                          SHA-256:865E3665743B5FABA3E1AD6AA55515A666BD05DA6266879D9B66C98905DAFF3C
                                                                                                                                                                                                                                                          SHA-512:D9924FBE59CB571AF721CA602DBE58CAD0D9310610EDF544F8FC0FBF3D1CE4E99597D0198E4E7C802107012786346FE4C1B9C6C3A76D5F60B9A83981B0EDA24D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-8, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A0000000A200A300A400A500A600A700A800A900D700AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900F700BB00BC00BD00BE0000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000002017..05D005D105D205D305
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1114
                                                                                                                                                                                                                                                          Entropy (8bit):3.2591070910715714
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:XHVBUlJvRj7SOVbusZhAMiZyi77qimmvGNNlkBSMH+tA/b:XMlBVnrAMiwMmTmokgzAD
                                                                                                                                                                                                                                                          MD5:0B99E605E73B7D8DEFD8D643F5729748
                                                                                                                                                                                                                                                          SHA1:F30E7CCBCD9C539126E8D6CA0886E4B2BD54E05D
                                                                                                                                                                                                                                                          SHA-256:CF51E867DDE2F19553D98FEEC45A075C4B4F480FB1EDADB3D8DAD1EBEA9299F3
                                                                                                                                                                                                                                                          SHA-512:DA0487CD7F2143195E80697C17FFDB61AFD464C888DDF84813B2B5D1BAB24D96466DA7A7F77C8E4A9D0D53F34D72928923380AFC1B92A96C0A3BFF46006A4E19
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: iso8859-9, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..011E00D100D200D300D400D500D600D700D800D900DA00DB00DC0130015E00DF..00E000E100E200E300
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1112
                                                                                                                                                                                                                                                          Entropy (8bit):3.2708615484795676
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:zBHVBUlJvRj7SOVbusZhAMiZyi77qN8VmKfkiJt0RMFS:zBMlBVnrAMiwMmNPYPFS
                                                                                                                                                                                                                                                          MD5:4E21F24F8D9CC5DF16B29CACD997AC69
                                                                                                                                                                                                                                                          SHA1:064E723EFB82EF1C303E5267496304288821E404
                                                                                                                                                                                                                                                          SHA-256:61B14A7C312366F79BB45F02C6B7EE362E6F51CBAD5E479E563C7F7E785DB654
                                                                                                                                                                                                                                                          SHA-512:AF8FAEB47EFB51F2537139F7C4254ABED119E477FD2B5E83B90B7A903B43C4E02DDF43A7DDB044A0A9601E9F9ADE91B02EE7C0EC87FF5DDCF9951B9601A90435
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: jis0201, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D203E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..00000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):81772
                                                                                                                                                                                                                                                          Entropy (8bit):2.3571626869060776
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:AigXM6CwL/9pV7Hl6+Yko9gZxErA3/MS/8xqg8:AZ/tp1Hl2KZxUfr8
                                                                                                                                                                                                                                                          MD5:F0661E22C7455994AA1F6EC1EDA401B4
                                                                                                                                                                                                                                                          SHA1:928B2AC46A9FDE61A81F56BE225E6138B40C22E5
                                                                                                                                                                                                                                                          SHA-256:F6B1C6AC5F5FC4E990A7A1AAC16A406012040936431BEFE7D2B6CD1DA9E422C4
                                                                                                                                                                                                                                                          SHA-512:917CC58678A9E9F5CBE860D30828846ABA4EA8CDFAB7DD1AE6A66C47ECBB85CF67DD97BC3E6F95341DD30F4E757B2CEA571708D5B4CED18A29F19904C3138AE0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: jis0208, double-byte..D..2129 0 77..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000300030013002FF0CFF0E30FBFF1AFF1BFF1FFF01309B309C00B4FF4000A8..FF3EFFE3FF3F30FD30FE309D309E30034EDD30053006300730FC20152010FF0F..FF3C301C2016FF5C2026202520182019201C201DFF08FF0930143015FF3BFF3D..FF5BFF5D30083009300A300B300C300D300E300F30103011FF0B221200B100D7..00F7FF1D2260FF1CFF1E22662267221E22342642264000B0203220332103FFE5..FF0400A200A3FF05FF03FF06FF0AFF2000A72606260525CB25CF25CE25C70000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):72133
                                                                                                                                                                                                                                                          Entropy (8bit):2.3455261548208055
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:9F/D7CH2puD5CdzU3nAkP5dHn7s391fmOarFaVQ:H/D7CHbozU3nAk3H7sXm3FgQ
                                                                                                                                                                                                                                                          MD5:07CE2C135BE17DBAFA558AA5949A53DB
                                                                                                                                                                                                                                                          SHA1:5D9DBEFCCB44E76C1A4E61360C6FCED8DCC8EF4D
                                                                                                                                                                                                                                                          SHA-256:785CFC5F5D9CB06DB8061730AB0016A0F70D0B59F6787D2A3CBB8D5779C99706
                                                                                                                                                                                                                                                          SHA-512:E954D7198D58ACEDEB4C8E5F466107767C3DA43763A5F6CDDFCF567226F9B22B4C2DE27564F28CD125D7F1BA7CB9C6DE6DEC4065EC2676572C793BE458FDDD9D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: jis0212, double-byte..D..2244 0 68..22..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00000000000000000000000000000000000000000000000000000000000002D8..02C700B802D902DD00AF02DB02DA007E03840385000000000000000000000000..0000000000A100A600BF00000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000BA00AA00A900AE2122..00A4211600000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1111
                                                                                                                                                                                                                                                          Entropy (8bit):3.531149521168141
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:KcJ5mHVBUlJvRj7SOVbusZhAMiZyi77qpSzIa9qVRS3YcEchJh3MAxSl:KmmMlBVnrAMiwMmAzIxVgBE6cAxQ
                                                                                                                                                                                                                                                          MD5:96F54CC639ACA8E466FB8058144C9350
                                                                                                                                                                                                                                                          SHA1:0B9530D6080F2BAACABD5AA0D48BFF316FCCEF64
                                                                                                                                                                                                                                                          SHA-256:0E43244BFC4F33FACB844B9E00270A1A4C24DC59B8A9B95104E2D788BB2F59FD
                                                                                                                                                                                                                                                          SHA-512:5B7859325E5E34C9D4558B1198795BB9C6A8EF783EB97193EA80BA76C38AFE9BDD1B526B77401DF5456B7A0E85E942191FFD4B4F2B9F0C8168A7093EE452802E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: koi8-r, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..25002502250C251025142518251C2524252C2534253C258025842588258C2590..259125922593232025A02219221A22482264226500A0232100B000B200B700F7..25502551255204512553255425552556255725582559255A255B255C255D255E..255F25602561040125622563256425652566256725682569256A256B256C00A9..044E0430043104460434043504440433044504380439043A043B043C043D043E..043F044F044004410442044304360432044C044B04370448044D04490447044A..042E04100411042604140
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1111
                                                                                                                                                                                                                                                          Entropy (8bit):3.5076564572101714
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:K+HVBUlJvRj7SOVbusZhAMiZyi77qpSzIaU3dmVRS3YcEchJh3MAxSl:K+MlBVnrAMiwMmAzI/EVgBE6cAxQ
                                                                                                                                                                                                                                                          MD5:4B755EF2288DFC4009759F8935479D68
                                                                                                                                                                                                                                                          SHA1:C3BDF0D9DF316DE8919DAA4329275C5AA81D61B4
                                                                                                                                                                                                                                                          SHA-256:ED04D5B977B8C8944D8760B713FF061292DA5634BCBB67CDFB1C3A6FF5378C81
                                                                                                                                                                                                                                                          SHA-512:3F1E1CC47327054FB9C54157ED10514230F10BFCD4BD9FDAFA02D7B238137DC7442CA2661B0739D8EEA3181E187D3B639A2C8118A0DE272C96000908121B6CFB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: koi8-u, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..25002502250C251025142518251C2524252C2534253C258025842588258C2590..259125922593232025A02219221A22482264226500A0232100B000B200B700F7..25502551255204510454255404560457255725582559255A255B0491255D255E..255F25602561040104032563040604072566256725682569256A0490256C00A9..044E0430043104460434043504440433044504380439043A043B043C043D043E..043F044F044004410442044304360432044C044B04370448044D04490447044A..042E04100411042604140
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):94393
                                                                                                                                                                                                                                                          Entropy (8bit):2.4104200953565513
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:XbjO7Uw6uKdosXRxps9a+ut/BmZPwkpT9A0T03o:XfO4ZBRxpV+4wPwKloo
                                                                                                                                                                                                                                                          MD5:366C09E4A4CC10006E593F5B3F3461D7
                                                                                                                                                                                                                                                          SHA1:A0DABFBEEB66E26FB342844EA41772D7A1D19C24
                                                                                                                                                                                                                                                          SHA-256:9B27FE7E7054F36E279993F19E52E18AC03360D117AE80C42B4E984A97C590AA
                                                                                                                                                                                                                                                          SHA-512:670F32D698C7992038E736D3AD40098D8589C0C5A1379E32A0F02A02FAF251B1312CAD131DDADC3F80B23A3821A91689F2E310309028BDDDF227D532EB505A20
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: ksc5601, double-byte..D..233F 0 89..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000030003001300200B72025202600A8300300AD20152225FF3C223C20182019..201C201D3014301530083009300A300B300C300D300E300F3010301100B100D7..00F7226022642265221E223400B0203220332103212BFFE0FFE1FFE526422640..222022A52312220222072261225200A7203B2606260525CB25CF25CE25C725C6..25A125A025B325B225BD25BC219221902191219321943013226A226B221A223D..221D2235222B222C2208220B2286228722822283222A222922272228FFE20000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1116
                                                                                                                                                                                                                                                          Entropy (8bit):3.4295694929963667
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:8jHVBUlJvRj7SOVbusZhAMiZyi77qHVPJSf2FcVDu1LEe4qPPMl2J89:8jMlBVnrAMiwMmHEmJ4IMgi9
                                                                                                                                                                                                                                                          MD5:10850BCFB943318284D6191494EBD7D5
                                                                                                                                                                                                                                                          SHA1:237D5DDF7969A422991F17021244D13A2BB0DE92
                                                                                                                                                                                                                                                          SHA-256:81ECA6840B87F2DEF9FCDD171A55C2D71A49386D88401CE927AE57D7DDD7AAAA
                                                                                                                                                                                                                                                          SHA-512:D797781C228B70D2D83DB8ABA08F840CE49846C9473CC89A2E316900D9E08A63142E68AD9ABBB2EF67BF9F1D392772FAB36CCC09632022A1437AE27C11F2284F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macCentEuro, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C40100010100C9010400D600DC00E10105010C00E4010D0106010700E90179..017A010E00ED010F01120113011600F3011700F400F600F500FA011A011B00FC..202000B0011800A300A7202200B600DF00AE00A92122011900A822600123012E..012F012A22642265012B0136220222110142013B013C013D013E0139013A0145..0146014300AC221A01440147220600AB00BB202600A00148015000D50151014C..20132014201C201D2018201900F725CA014D0154015501582039203A01590156..01570160201A201E
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1116
                                                                                                                                                                                                                                                          Entropy (8bit):3.3992482002374516
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:8ULyHVBUlJvRj7SOVbusZhAMiZyi77qsTMdKxOZwwL+KR5D/jlJy6QWky:8ULyMlBVnrAMiwMmOsL+KR5DblE85
                                                                                                                                                                                                                                                          MD5:A60FBDE33D13C732095713D1AB6713AB
                                                                                                                                                                                                                                                          SHA1:4B0EB443F2D0E4B8DB7D0435F9311E5F9A625123
                                                                                                                                                                                                                                                          SHA-256:BBE6F5EBB5EAB08C91DF7D524FAF39B03AA8B9F84C67ABA0553A84EC56668CB9
                                                                                                                                                                                                                                                          SHA-512:3EEBA6BA3FCD875AFBD5DF41EDC21E872416A48D03343232904CC99CAF913045DAF7B1A1ACD0949EF794AD7B6C9AE8F93808423FFC4B67718E732B2FF5D9B6D7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macCroatian, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8..00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC..202000B000A200A300A7202200B600DF00AE0160212200B400A82260017D00D8..221E00B122642265220600B522022211220F0161222B00AA00BA03A9017E00F8..00BF00A100AC221A01922248010600AB010C202600A000C000C300D501520153..01102014201C201D2018201900F725CAF8FF00A9204420AC2039203A00C600BB..201300B7201A201E
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1116
                                                                                                                                                                                                                                                          Entropy (8bit):3.4178221849964903
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:8dHVBUlJvRj7SOVbusZhAMiZyi77qb+SAJlz9a4piS1yk+5yye3cJY:8dMlBVnrAMiwMm8Y6zUk+UVsJY
                                                                                                                                                                                                                                                          MD5:C390D66441AC61CCF0A685CA5EE0BC1C
                                                                                                                                                                                                                                                          SHA1:FCAE825B54400B9D736EF22A613E359E3F0FA6C2
                                                                                                                                                                                                                                                          SHA-256:76EFE571ADDA7AED467F146CB0BD3A2351F2A720508EA0642C419F5347789CAA
                                                                                                                                                                                                                                                          SHA-512:C891DB15E0F600965885DE6745EDD2A4E3A6A20CA30A9AAE89CBD8C429F8455C4AF7F2FC053FB3D730D8544AB6A6E78E769DB93DAD7B29868B746FA10373F021
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macCyrillic, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0410041104120413041404150416041704180419041A041B041C041D041E041F..0420042104220423042404250426042704280429042A042B042C042D042E042F..202000B0049000A300A7202200B6040600AE00A9212204020452226004030453..221E00B122642265045600B504910408040404540407045704090459040A045A..0458040500AC221A01922248220600AB00BB202600A0040B045B040C045C0455..20132014201C201D2018201900F7201E040E045E040F045F211604010451044F..0430043104320433
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1116
                                                                                                                                                                                                                                                          Entropy (8bit):3.870022681111701
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:87JMHkUlJvRjmf9RCsUBOdXsCbbNviANpkDP1XFAoE4xSF5HrBPkdn:87KvlA9RCs6CXrViANUP1XFA9eSvdPKn
                                                                                                                                                                                                                                                          MD5:DCE78527E3A7B7CB1DE9EE5FAF12AFC6
                                                                                                                                                                                                                                                          SHA1:20F4A3F4DB6B3422C04EBB6B21A568E4C173F9C1
                                                                                                                                                                                                                                                          SHA-256:062E31D48DC33160999074E49205E08C3655DFF91C2C87F254522E6EBCE2DD96
                                                                                                                                                                                                                                                          SHA-512:627F5FD2F12B341F2D7EE9032946FE057C4AC74D99687178CEA98B3E150307BB6AA2495B0FA46400760D467E2BF589BE31E998E25CE1D1E8465DA61F22047345
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macDingbats, single-byte..S..003F 1 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..00202701270227032704260E2706270727082709261B261E270C270D270E270F..2710271127122713271427152716271727182719271A271B271C271D271E271F..2720272127222723272427252726272726052729272A272B272C272D272E272F..2730273127322733273427352736273727382739273A273B273C273D273E273F..2740274127422743274427452746274727482749274A274B25CF274D25A0274F..27502751275225B225BC25C6275625D727582759275A275B275C275D275E007F..F8D7F8D8F8D9F8DAF8DBF8DCF8DDF8DEF8DFF8E0F8E1F8E2F8E3F8E4008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000276127622763276427652766276726632666266526602460246124622463..2464246524662467246824692776277727782779277A277B277C277D277E277F..2780278127822783278427852786278727882789278A278B278C278D278E278F..2790279127922793279421922194219527982799279A279B279C279D279E279F..27A027A127A227A3
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1113
                                                                                                                                                                                                                                                          Entropy (8bit):3.4954458011071323
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:8dOHVBUlJvRj7SOVbusZhAMiZyi77qJlbaBMD2aSY5us36Ekp1ysOSU2imR:8kMlBVnrAMiwMm7aKPVusqx1ysOJjmR
                                                                                                                                                                                                                                                          MD5:0CC92F685A4132BE4B030006670D81CE
                                                                                                                                                                                                                                                          SHA1:13B1074A90055E9EA061A6206A9C004DA29967A9
                                                                                                                                                                                                                                                          SHA-256:1AABE561B5C944ABD11C293D4ACAC0F3A4A5A9E84A0342D066F4E3E992348895
                                                                                                                                                                                                                                                          SHA-512:E1AF3D47D681CD68B6063DEC1241631CABE86FE835232FA73D855AC74D0175540D46511282BE7198A67A37970A5D05CDECF55C10424ED9C1413C108F116094D9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macGreek, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400B900B200C900B300D600DC038500E000E200E4038400A800E700E900E8..00EA00EB00A3212200EE00EF202200BD203000F400F600A600AD00F900FB00FC..2020039303940398039B039E03A000DF00AE00A903A303AA00A7226000B000B7..039100B12264226500A503920395039603970399039A039C03A603AB03A803A9..03AC039D00AC039F03A1224803A400AB00BB202600A003A503A7038603880153..20132015201C201D2018201900F70389038A038C038E03AD03AE03AF03CC038F..03CD03B103B203C803B
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1115
                                                                                                                                                                                                                                                          Entropy (8bit):3.3991839018654573
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:8KHVBUlJvRj7SOVbusZhAMiZyi77qscqMVmOZmk/LYRldjY/g4JyMWG:8KMlBVnrAMiwMmzqi/LYRlYBEXG
                                                                                                                                                                                                                                                          MD5:747ADBE54D6992467415E322326FA1B9
                                                                                                                                                                                                                                                          SHA1:5E3967B5DDF3A6DBF07E90ED6B9B9C2F3F3F35FE
                                                                                                                                                                                                                                                          SHA-256:6FD08CE6FBA521D51E8058DE5C2DBD6583B80306A8BE7D015361F76314E70A35
                                                                                                                                                                                                                                                          SHA-512:A04B946993985BF1F8FBA3A7A9AD3838F43F8F27F69B1FB1015D9DC8612AAFCE24E30CBC1FCABBDFB359FD487D51F70F18DA0CDA4A87749A2C82309CEB054849
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macIceland, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8..00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC..00DD00B000A200A300A7202200B600DF00AE00A9212200B400A8226000C600D8..221E00B12264226500A500B522022211220F03C0222B00AA00BA03A900E600F8..00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153..20132014201C201D2018201900F725CA00FF0178204420AC00D000F000DE00FE..00FD00B7201A201E2
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48813
                                                                                                                                                                                                                                                          Entropy (8bit):3.3767502114972077
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:K/RPrUHiJrKWkyY/W2wHiwWnwWOORY+gutSJi:KVUidzJCurDGSk
                                                                                                                                                                                                                                                          MD5:3DCD22325E0194AAD4959C939B1DE24D
                                                                                                                                                                                                                                                          SHA1:ABEF1372FBDA83714CE29E015D9A198D4B37B21C
                                                                                                                                                                                                                                                          SHA-256:47007D9EBF4D34C6CE3599E50AFC7C1CF8129B88994DE2C2A857C09003F9CD2B
                                                                                                                                                                                                                                                          SHA-512:B8ADFD2315EA38E5F7D4DED219759380069AAB539F1B5AAA5626CE32428CBBEB5E8215AD8351E023BCF72FA4DC30AB40CF59D6D45E33B6D1A6B41BEBFD4BD4C2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macJapan, multi-byte..M..003F 0 46..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00A0FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..0000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1113
                                                                                                                                                                                                                                                          Entropy (8bit):3.4060725247347516
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:8THVBUlJvRj7SOVbusZhAMiZyi77qsTMVmOZmk/LYRldjBpmg4JyMWG:8TMlBVnrAMiwMmOi/LYRlTsBEXG
                                                                                                                                                                                                                                                          MD5:34691FADC788B85D98F63159640C7DD0
                                                                                                                                                                                                                                                          SHA1:C8B3D084D3E831EFF6ECEF71B2029545F214C3D4
                                                                                                                                                                                                                                                          SHA-256:C83D971D6BC0284EF323C197896E38C57A5FF44784E451EC2997EDA70C0DD85C
                                                                                                                                                                                                                                                          SHA-512:77D5676F9B7AF7FD1D612A1C426889D8F2C0191887E180B78C4AA42202928A1B3078B76BD3C5F5ABB2A5CE1AE913E3CA6EFDE0483D2A2B0EFC173EF25EAE1D67
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macRoman, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8..00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC..202000B000A200A300A7202200B600DF00AE00A9212200B400A8226000C600D8..221E00B12264226500A500B522022211220F03C0222B00AA00BA03A900E600F8..00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153..20132014201C201D2018201900F725CA00FF0178204420AC2039203AFB01FB02..202100B7201A201E203
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1115
                                                                                                                                                                                                                                                          Entropy (8bit):3.412326247178521
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:8tHVBUlJvRj7SOVbusZhAMiZyi77qsTMVZ5OZwYRldj/T9g4JyMWG:8tMlBVnrAMiwMmOA7YRlFT9BEXG
                                                                                                                                                                                                                                                          MD5:04E25073BFB0019D8381B72F7B433F00
                                                                                                                                                                                                                                                          SHA1:B63B0AD9F10A44B0DDD12A3BDBCDEB2992D6D385
                                                                                                                                                                                                                                                          SHA-256:0B805DAF21D37D702617A8C72C7345F857695108D905FF378791F291CEA150F0
                                                                                                                                                                                                                                                          SHA-512:0514EC054676C15C65B01B02747CDBAD79BC89FD1A24A17797A8729752FB748FEDBE920E7BBFF41A6DA4BA99002E3B8DB674D53E30485DC36F6BF737EAF11702
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macRomania, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8..00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC..202000B000A200A300A7202200B600DF00AE00A9212200B400A822600102015E..221E00B12264226500A500B522022211220F03C0222B00AA00BA21260103015F..00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153..20132014201C201D2018201900F725CA00FF0178204400A42039203A01620163..202100B7201A201E2
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1112
                                                                                                                                                                                                                                                          Entropy (8bit):3.6062142626989004
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:88HVBUlJvRj7SOVbusZhAMiZyi77qqJipJwHmEU4AyqU+TpH:88MlBVnrAMiwMmqJ8Jf4AyqUe
                                                                                                                                                                                                                                                          MD5:06DC6BA6E4A75CD7FF2D7A4248912C61
                                                                                                                                                                                                                                                          SHA1:23FB16763A8F11EF48E805E4F453C2F812D48FC4
                                                                                                                                                                                                                                                          SHA-256:A1802A2FEB01B255EC7C17425EEE4525372DF8CE226F4047D149172EB438F913
                                                                                                                                                                                                                                                          SHA-512:41A487EC5C36C17B2746C5DC770882A836E6E75CF6A14C31595EB211022F0476BD3B953497C447F21554769F127C3A56E5B6EF8FB3C20A8AFF8C67E0CC94359D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macThai, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00AB00BB2026F88CF88FF892F895F898F88BF88EF891F894F897201C201DF899..FFFD2022F884F889F885F886F887F888F88AF88DF890F893F89620182019FFFD..00A00E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F..0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F..0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F..0E300E310E320E330E340E350E360E370E380E390E3AFEFF200B201320140E3F..0E400E410E420E430E44
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1115
                                                                                                                                                                                                                                                          Entropy (8bit):3.422718883614008
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:8QjHVBUlJvRj7SOVbusZhAMiZyi77qsTMVmOZmk/LYRldD8g4JyS:88MlBVnrAMiwMmOi/LYRlWBES
                                                                                                                                                                                                                                                          MD5:4EA94A0DB35BED2081A2CC9D627A8180
                                                                                                                                                                                                                                                          SHA1:AB2AC3ADA19F3F656780FF876D5B536A8DCE92C6
                                                                                                                                                                                                                                                          SHA-256:AFB66138EBE9B87D8B070FE3B6E7D1A05ED508571E9E5B166C3314069D59B4E4
                                                                                                                                                                                                                                                          SHA-512:7888F560D3728732BE1B7DCE49ECB61F3399CEF11191F4116C891E1D147B2A90ED8FB4A5E7B51904A001C47750BD9EB1B15EA5BA5B4EC5D69CDE7704B69529AD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macTurkish, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8..00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC..202000B000A200A300A7202200B600DF00AE00A9212200B400A8226000C600D8..221E00B12264226500A500B522022211220F03C0222B00AA00BA03A900E600F8..00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153..20132014201C201D2018201900F725CA00FF0178011E011F01300131015E015F..202100B7201A201E2
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1115
                                                                                                                                                                                                                                                          Entropy (8bit):3.4157626428238723
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:8TzHVBUlJvRj7SOVbusZhAMiZyi77qb+SAJlz9a4piS1yk+5yye3cJd:8PMlBVnrAMiwMm8Y6zUk+UVsJd
                                                                                                                                                                                                                                                          MD5:A5B48D6F2678579CBE6EA094A4655071
                                                                                                                                                                                                                                                          SHA1:A13A41D530B21CE8443AFD7E811286537C5BA9C7
                                                                                                                                                                                                                                                          SHA-256:F7E11736C9FF30102B31EC72272754110193B347433F4B364921E8F131C92BF0
                                                                                                                                                                                                                                                          SHA-512:612F9D528CE940B5CA9E67CB127013A104655207511F4CF39C8696A127E6A8F4867F5603DCFB78C25A55668C6EE70F2997A8D1626F6F1DD44B19260967F17097
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: macUkraine, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0410041104120413041404150416041704180419041A041B041C041D041E041F..0420042104220423042404250426042704280429042A042B042C042D042E042F..202000B0049000A300A7202200B6040600AE00A9212204020452226004030453..221E00B122642265045600B504910408040404540407045704090459040A045A..0458040500AC221A01922248220600AB00BB202600A0040B045B040C045C0455..20132014201C201D2018201900F7201E040E045E040F045F211604010451044F..04300431043204330
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42552
                                                                                                                                                                                                                                                          Entropy (8bit):3.5565924983274857
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:w/RPrUHiJrwWkyY/W2wHiwWnwWOORY+gutSX:wVUid5JCurDGSX
                                                                                                                                                                                                                                                          MD5:EEB45AF9D7104872FE290D1EC18AB169
                                                                                                                                                                                                                                                          SHA1:A80CF4EA46301F0B8B4F0BC306270D7103753871
                                                                                                                                                                                                                                                          SHA-256:4A15ED210126BCDAE32543F60EB1A0677F985F32D49FCE923B9FAE8C5BCF3DA4
                                                                                                                                                                                                                                                          SHA-512:C359042B04441AA50E536B23EEA0C6C7B2C1893DFB9CDB5459D3B46945D3BB50FD7A32A4F4E26A83622E76D3D2BB0DBBC3D1F3FB87AAF40520A243165B82AB34
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: shiftjis, multi-byte..M..003F 0 40..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080000000000000000000850086008700000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..0000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1111
                                                                                                                                                                                                                                                          Entropy (8bit):3.73983895892791
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:SdHkUlJvRjvRV7ZQsoRmSds2AsSemxUs+Jw1Viv6ObTXyn:avlJV7ZQsoRmosGSPxU/JOm6wTXyn
                                                                                                                                                                                                                                                          MD5:D59E748D863A5FAEF0CEEC2564E041A3
                                                                                                                                                                                                                                                          SHA1:4FFF3BE37F50C090FFC581F1C7769E20281E90C3
                                                                                                                                                                                                                                                          SHA-256:9660537A7B62996478555C6F57C1962C78FB3972F19370B2E395C44842818A1F
                                                                                                                                                                                                                                                          SHA-512:BF8FD0CF1CC55564C46976F53F441B26819ADBA7AB7BB04FF3FF5A313366FC3049DF29A839CCCB05EDEF4A7ECBB49FFCA62518EDA90AF2D7781874A8435073AE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: symbol, single-byte..S..003F 1 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002122000023220300250026220D002800292217002B002C2212002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..22450391039203A70394039503A603930397039903D1039A039B039C039D039F..03A0039803A103A303A403A503C203A9039E03A80396005B2234005D22A5005F..F8E503B103B203C703B403B503C603B303B703B903D503BA03BB03BC03BD03BF..03C003B803C103C303C403C503D603C903BE03C803B6007B007C007D223C007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..000003D2203222642044221E0192266326662665266021942190219121922193..00B000B12033226500D7221D2202202200F72260226122482026F8E6F8E721B5..21352111211C21182297229522052229222A2283228722842282228622082209..2220220700AE00A92122220F221A22C500AC2227222821D421D021D121D221D3..22C42329F8E8F8E9F8EA2
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1112
                                                                                                                                                                                                                                                          Entropy (8bit):3.0553142874336943
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:ZlHVBUlJvRj7SOVbusZhAMiZyi77qsDHmEU4AyqU+TWwdd:PMlBVnrAMiwMmss4AyqUSd
                                                                                                                                                                                                                                                          MD5:467A67DE6809B796B914F5BFF98EF46D
                                                                                                                                                                                                                                                          SHA1:C62418071A6C9CB0DCE3F67E130BFD2FB7AB0B58
                                                                                                                                                                                                                                                          SHA-256:50B62381D6EDD4219F4292BFDC365954491B23360DE7C08033E7218A3D29C970
                                                                                                                                                                                                                                                          SHA-512:BF98305AA7D759A087B9EABDC404714D8DC6B4F1BEED4ED0E1FFE646641E1AECA307673D64CF95FD09546D977B3409D6C04F56DCCA1D6332B0D9B6DD460B77A9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Encoding file: tis-620, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E0000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00000E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F..0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F..0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F..0E300E310E320E330E340E350E360E370E380E390E3A00000000000000000E3F..0E400E410E420E430E44
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8243
                                                                                                                                                                                                                                                          Entropy (8bit):4.856326023245708
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:Hf8PxPu7qUHBpqyzmY5rEk/fvs+AokFlTGHts1Z/tsEGZPBtsLIVn++G:H6Pu71LJTtylikOzz+L
                                                                                                                                                                                                                                                          MD5:CB5ED49B3ED4E982E24B2D087DA9F8F6
                                                                                                                                                                                                                                                          SHA1:DE113C96FBA7888B890B42AB0036F6771C08953A
                                                                                                                                                                                                                                                          SHA-256:7EF1C11F6A5A9246C8A62917FFF90EEAA2D5F29CCDAAE9734E46B8385465012D
                                                                                                                                                                                                                                                          SHA-512:0683A4339827D47A4E0544D88733CD8D48EADE7BFBFDFF58FFFDDAB83017569E6D203B058AC23D9DE2A0EADAA24C0A11C7B1823CADF153BCFA6339B9D1E77D13
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# history.tcl --..#..# Implementation of the history command...#..# Copyright (c) 1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES...#.....# The tcl::history array holds the history list and some additional..# bookkeeping variables...#..# nextid.the index used for the next history list item...# keep..the max size of the history list..# oldest.the index of the oldest item in the history.....namespace eval ::tcl {.. variable history.. if {![info exists history]} {...array set history {... nextid.0... keep.20... oldest.-20...}.. }.... namespace ensemble create -command ::tcl::history -map {...add.::tcl::HistAdd...change.::tcl::HistChange...clear.::tcl::HistClear...event.::tcl::HistEvent...info.::tcl::HistInfo...keep.::tcl::HistKeep...nextid.::tcl::HistNextID...redo.::tcl::HistRedo.. }..}.....# history --..#..#.This is the main history command. See the
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10066
                                                                                                                                                                                                                                                          Entropy (8bit):4.806771544139381
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:kipkqA3KsZMAikGJ4kIWPa95KTBoF7dg/8YNkgQ4id:TkqWKsZ8kGJ4kIWPaDFzTd
                                                                                                                                                                                                                                                          MD5:C2092F8CA2D761DFA8C461076D956374
                                                                                                                                                                                                                                                          SHA1:90B4648B3BC81C30465B0BE83A5DB4127A1392FB
                                                                                                                                                                                                                                                          SHA-256:8C474095A3ABA7DF5B488F3D35240D6DE729E57153980C2A898728B8C407A727
                                                                                                                                                                                                                                                          SHA-512:09CE408886E2CEADDF70786A15D63AF9A930E70CAC4286AC9DDD2094C8EDCF97A2ADC2D3D2659B123F88719340D3B00D9F96E9BC7C8B55192735C290E7D24683
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# http.tcl..# Client-side HTTP for GET, POST, and HEAD commands...# These routines can be used in untrusted code that uses the Safesock..# security policy...# These procedures use a callback interface to avoid using vwait,..# which is not defined in the safe base...#..# See the http.n man page for documentation....package provide http 1.0....array set http {.. -accept */*.. -proxyhost {}.. -proxyport {}.. -useragent {Tcl http client package 1.0}.. -proxyfilter httpProxyRequired..}..proc http_config {args} {.. global http.. set options [lsort [array names http -*]].. set usage [join $options ", "].. if {[llength $args] == 0} {...set result {}...foreach name $options {... lappend result $name $http($name)...}...return $result.. }.. regsub -all -- - $options {} options.. set pat ^-([join $options |])$.. if {[llength $args] == 1} {...set flag [lindex $args 0]...if {[regexp -- $pat $flag]} {... return $http($flag)...} else {... return -code er
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):746
                                                                                                                                                                                                                                                          Entropy (8bit):4.711041943572035
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:jHx5XRsLzhjJS42wbGlTULuUAZb3KykszLl7+HkuRz20JSv6C3l5kMn:bHRsRJS42wbGlTUcZ+yk2Lli1z2jxXkM
                                                                                                                                                                                                                                                          MD5:A387908E2FE9D84704C2E47A7F6E9BC5
                                                                                                                                                                                                                                                          SHA1:F3C08B3540033A54A59CB3B207E351303C9E29C6
                                                                                                                                                                                                                                                          SHA-256:77265723959C092897C2449C5B7768CA72D0EFCD8C505BDDBB7A84F6AA401339
                                                                                                                                                                                                                                                          SHA-512:7AC804D23E72E40E7B5532332B4A8D8446C6447BB79B4FE32402B13836079D348998EA0659802AB0065896D4F3C06F5866C6B0D90BF448F53E803D8C243BBC63
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Tcl package index file, version 1.0..# This file is generated by the "pkg_mkIndex" command..# and sourced either when an application starts up or..# by a "package unknown" script. It invokes the..# "package ifneeded" command to set up package-related..# information so that packages will be loaded automatically..# in response to "package require" commands. When this..# script is sourced, the variable $dir must contain the..# full path name of this file's directory.....package ifneeded http 1.0 [list tclPkgSetup $dir http 1.0 {{http.tcl source {httpCopyDone httpCopyStart httpEof httpEvent httpFinish httpMapReply httpProxyRequired http_code http_config http_data http_formatQuery http_get http_reset http_size http_status http_wait}}}]..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):25653
                                                                                                                                                                                                                                                          Entropy (8bit):4.885073965331145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:BXugPHudKlE7BG6Xg3Qomm6ofRRECLSQDjr5vkhzx/i:ogGdKlK4aomm6offLzehNi
                                                                                                                                                                                                                                                          MD5:06CFF726F594EDDC36F5152824139625
                                                                                                                                                                                                                                                          SHA1:B102300C147B1D664F87ECF29343FDCD18B66BC5
                                                                                                                                                                                                                                                          SHA-256:798732AEE4E838670B9A4E37E3D6C4884019A1B101F9AB26344DD2E9BD179872
                                                                                                                                                                                                                                                          SHA-512:BE272DE405740C5A0CCD09732DFBBFC5982506BCE3A6FD1CC4FB37BE1D9C787674F41265F8C1F6D8998F2B52CD09BF5EE10103446B9A6EF76A8A1D538B3C39BA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# init.tcl --..#..# Default system startup file for Tcl-based applications. Defines..# "unknown" procedure and auto-load facilities...#..# Copyright (c) 1991-1993 The Regents of the University of California...# Copyright (c) 1994-1996 Sun Microsystems, Inc...# Copyright (c) 1998-1999 Scriptics Corporation...# Copyright (c) 2004 Kevin B. Kenny. All rights reserved...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# This test intentionally written in pre-7.5 Tcl..if {[info commands package] == ""} {.. error "version mismatch: library\nscripts expect Tcl version 7.5b1 or later but the loaded version is\nonly [info patchlevel]"..}..package require -exact Tcl 8.6.14....# Compute the auto path to use in this interpreter...# The values on the path come from several locations:..#..# The environment variable TCLLIBPATH..#..# tcl_library, which is the directory containing this init.tcl script...# [t
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1038
                                                                                                                                                                                                                                                          Entropy (8bit):4.10054496357204
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:4EnLB383Hcm0hH9BncmtR7tK9dUVxMmALfpKIdzVJLd3xfjTuLM+vzkHWZ6tH9H0:4aR838HH9ekCkMmEfpK2xx2jiWZ0VbY
                                                                                                                                                                                                                                                          MD5:DA8BA1C3041998F5644382A329C3C867
                                                                                                                                                                                                                                                          SHA1:CA0BD787A51AD9EDC02EDD679EEEEB3A2932E189
                                                                                                                                                                                                                                                          SHA-256:A1EACA556BC0CFBD219376287C72D9DBBFAB76ECF9BF204FD02D40D341BAF7DA
                                                                                                                                                                                                                                                          SHA-512:4F086396405FDFE7FBDA7614D143DE9DB41F75BDBD3DB18B1EE9517C3DCCED238DD240B4B64829FD04E50F602DBF371D42A321D04C4C48E4B8B2A067CA1BAF2E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset af DAYS_OF_WEEK_ABBREV [list \.. "So"\.. "Ma"\.. "Di"\.. "Wo"\.. "Do"\.. "Vr"\.. "Sa"].. ::msgcat::mcset af DAYS_OF_WEEK_FULL [list \.. "Sondag"\.. "Maandag"\.. "Dinsdag"\.. "Woensdag"\.. "Donderdag"\.. "Vrydag"\.. "Saterdag"].. ::msgcat::mcset af MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Mei"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Des"\.. ""].. ::msgcat::mcset af MONTHS_FULL [list \.. "Januarie"\.. "Februarie"\.. "Maart"\.. "April"\.. "Mei"\.. "Junie"\.. "Julie"\.. "Augustus"\.. "September"\.. "Oktober"\.. "November"\.. "Desember"\.. ""].. ::msgcat::mcset af AM "VM
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.925537696653838
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xouFygMouFqF3v6ay/5ouFy9+3vR6HyFvn:4EnLB383RAgeYF3v6ay/RAI3voSVn
                                                                                                                                                                                                                                                          MD5:1B9DCD1C6FCDDC95AE820EA8DA5E15B8
                                                                                                                                                                                                                                                          SHA1:E8160353FD415BAB9FD5ACCA14E087C5E6AE836E
                                                                                                                                                                                                                                                          SHA-256:1548988458BBF0DFCCC23B7487CEC0E9C64E4CC8E045723E50BEC37C454A8C81
                                                                                                                                                                                                                                                          SHA-512:532AF060B95AED5E381B161BE56BC88D91A8F3DF2ACFD835491991F99FE752ADB4A3F93AB6D4E68F7042C28A3C1DD87A6312DFD9FFFAFD6ECE3F1B76837C5B7F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset af_ZA DATE_FORMAT "%d %B %Y".. ::msgcat::mcset af_ZA TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset af_ZA DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2018
                                                                                                                                                                                                                                                          Entropy (8bit):4.477377447232708
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83gr/fsS/Sm8p4M/n1KsPktE30AiJcAxi9CEzdEvSCHvMSV:43UkiSm8p3nX0EzdCSCPV
                                                                                                                                                                                                                                                          MD5:D264D01B46D96455715114CAEDF9F05E
                                                                                                                                                                                                                                                          SHA1:A3F68A4C6E69433BD53E52B73041575F3B3AC3F2
                                                                                                                                                                                                                                                          SHA-256:B69D0061A728D59F89FF8621312789CD9F540BF2E2ED297804D22F6278561D85
                                                                                                                                                                                                                                                          SHA-512:A4163DAA6821B293EADD5D499E0641A8B7C93180C710D6B364AE8681A8FF6F35EC948C8DDBE960A8466AF1ACABC15B0D465A08B084617E8005D708459F7E74D3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar DAYS_OF_WEEK_ABBREV [list \.. "\u062d"\.. "\u0646"\.. "\u062b"\.. "\u0631"\.. "\u062e"\.. "\u062c"\.. "\u0633"].. ::msgcat::mcset ar DAYS_OF_WEEK_FULL [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar MONTHS_ABBREV [list \.. "\u064a\u0646\u0627"\.. "\u0641\u0628\u0631"\.. "\u0645\u0627\u0631"\.. "\u0623\u0628\u0631"\.. "\u0645\u0627\u064a"\.. "\u064a\u0648\u0646"\.. "\u064a\u0648\u0644"\.. "\u0623\u063a\u0633"\.. "\u0633\u0628\u062a"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):265
                                                                                                                                                                                                                                                          Entropy (8bit):4.872222510420193
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoKNvfcoKU3v6xyFjoKNo+3vfXM68vn:4EnLB3831vfD3v6g9F3vfc6+n
                                                                                                                                                                                                                                                          MD5:430498B4AB1E77C86BC1311A49747581
                                                                                                                                                                                                                                                          SHA1:684EAD965D9010C2A6E73DCACB2224FDE585F9FF
                                                                                                                                                                                                                                                          SHA-256:2E04B96DA002519D28125918A22FF2BB9659A668A7BCAD34D85DDDECEC8DC0B4
                                                                                                                                                                                                                                                          SHA-512:9F85A88A383DCFC54DAA6253D94C307A14B1CC91D5C97AF817B8122AF98025AB2430D0B2D656EBED09E78FB854D1F9CF99F3B791A6ECB7834112012739140126
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_IN DATE_FORMAT "%A %d %B %Y".. ::msgcat::mcset ar_IN TIME_FORMAT_12 "%I:%M:%S %z".. ::msgcat::mcset ar_IN DATE_TIME_FORMAT "%A %d %B %Y %I:%M:%S %z %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1851
                                                                                                                                                                                                                                                          Entropy (8bit):4.08645484776227
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83sxS/Sm819+es/Ii/R91bpH0+U0c+es/Ii/R91bpH0+UO:43wiSm815MbJbHgMbJbp
                                                                                                                                                                                                                                                          MD5:5C62D606F4F14BC8994B28F9622D70DD
                                                                                                                                                                                                                                                          SHA1:E99F8CC5D330085545B05B69213E9D011D436990
                                                                                                                                                                                                                                                          SHA-256:5ADBB3D37C3369E5FC80D6A462C82598D5A22FAEF0E8DF6B3148231D2C6A7F73
                                                                                                                                                                                                                                                          SHA-512:81AC9200459B0896E27A028BD089A174F7F921B0367BC8FF1AB33D3E561417B6F8EC23DAB750ECB408AC8A11CDFDBFA4F890F9E723BB8607B017C9FEE00928A0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_JO DAYS_OF_WEEK_ABBREV [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar_JO MONTHS_ABBREV [list \.. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\.. "\u0634\u0628\u0627\u0637"\.. "\u0622\u0630\u0627\u0631"\.. "\u0646\u064a\u0633\u0627\u0646"\.. "\u0646\u0648\u0627\u0631"\.. "\u062d\u0632\u064a\u0631\u0627\u0646"\.. "\u062a\u0645\u0648\u0632"\.. "\u0622\u0628"\.. "\u0623\u064a\u0644\u0648\u0644"\.. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u064
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1851
                                                                                                                                                                                                                                                          Entropy (8bit):4.083347689510237
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83LxS/Sm8S9+es/Ii/R91bpH0+U/c+es/Ii/R91bpH0+UO:431iSm8S5MbJbQgMbJbp
                                                                                                                                                                                                                                                          MD5:6FC1CC738207E2F8E0871103841BC0D4
                                                                                                                                                                                                                                                          SHA1:D2C62C7F6DA1EF399FCBE2BA91C9562C87E6152F
                                                                                                                                                                                                                                                          SHA-256:1FC13070CF661488E90FECE84274C46B1F4CC7E1565EAB8F829CCAA65108DFCA
                                                                                                                                                                                                                                                          SHA-512:E547D5CBB746654051AFDA21942075BC2224C2FF75D440C6C34C642AD24CF622E520FF919B8BD4AFC0116D9CE69B3ABA4E81EE247C1388F3C5741150201F5C60
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_LB DAYS_OF_WEEK_ABBREV [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar_LB MONTHS_ABBREV [list \.. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\.. "\u0634\u0628\u0627\u0637"\.. "\u0622\u0630\u0627\u0631"\.. "\u0646\u064a\u0633\u0627\u0646"\.. "\u0646\u0648\u0627\u0631"\.. "\u062d\u0632\u064a\u0631\u0627\u0646"\.. "\u062a\u0645\u0648\u0632"\.. "\u0622\u0628"\.. "\u0623\u064a\u0644\u0648\u0644"\.. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u064
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1851
                                                                                                                                                                                                                                                          Entropy (8bit):4.084701680556524
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83lxS/Sm8M9+es/Ii/R91bpH0+UBc+es/Iv/I91bpH0+UO:43LiSm8M5MbJbSgMo0bp
                                                                                                                                                                                                                                                          MD5:8188C37CA44FEFFF8D895AAD503AD4F6
                                                                                                                                                                                                                                                          SHA1:C48F2E3B9FC055704D2DAFDC67E9D08EE6897D45
                                                                                                                                                                                                                                                          SHA-256:294F3E46C55453EDAD44567E1330F9B43E69A07FA0655B24DD2780A4490C1194
                                                                                                                                                                                                                                                          SHA-512:F86FCFC7C460473D46C472041AB2E1F9388CF34BCA9050295D1DAE454E35A2A0320D0C61D5E8CBB832AF74FFDD1A7511AF32EA2A53B481F39A1CBCF5F086D514
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_SY DAYS_OF_WEEK_ABBREV [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar_SY MONTHS_ABBREV [list \.. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\.. "\u0634\u0628\u0627\u0637"\.. "\u0622\u0630\u0627\u0631"\.. "\u0646\u064a\u0633\u0627\u0646"\.. "\u0646\u0648\u0627\u0631"\.. "\u062d\u0632\u064a\u0631\u0627\u0646"\.. "\u062a\u0645\u0648\u0632"\.. "\u0622\u0628"\.. "\u0623\u064a\u0644\u0648\u0644"\.. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u064
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2157
                                                                                                                                                                                                                                                          Entropy (8bit):4.27810535662921
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:43PI8IKQGQ8mA/XxQJxQnA9QJlPyI/tbCaQICMIcQ8InVI5tNIzQFIQQLtChjsI4:2PItK5BSb9ajfycCW5IzdQNxK
                                                                                                                                                                                                                                                          MD5:6334BDDFC1E0EAE4DBB2C90F85818FD8
                                                                                                                                                                                                                                                          SHA1:085EDC3D027D6B5A6A6A2561717EA89C8F8B8B39
                                                                                                                                                                                                                                                          SHA-256:A636A82C7D00CCDC0AF2496043FFA320F17B0D48A1232708810D3BB1453E881E
                                                                                                                                                                                                                                                          SHA-512:18ADB77314FCFD534E55B234B3A53A0BC572AB60B80D099D2F3B20E0C5FE66179FDC076AA43200DB3CA123BC6216989EC41448FA624D3BA9633413AD8AD6034C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset be DAYS_OF_WEEK_ABBREV [list \.. "\u043d\u0434"\.. "\u043f\u043d"\.. "\u0430\u0442"\.. "\u0441\u0440"\.. "\u0447\u0446"\.. "\u043f\u0442"\.. "\u0441\u0431"].. ::msgcat::mcset be DAYS_OF_WEEK_FULL [list \.. "\u043d\u044f\u0434\u0437\u0435\u043b\u044f"\.. "\u043f\u0430\u043d\u044f\u0434\u0437\u0435\u043b\u0430\u043a"\.. "\u0430\u045e\u0442\u043e\u0440\u0430\u043a"\.. "\u0441\u0435\u0440\u0430\u0434\u0430"\.. "\u0447\u0430\u0446\u0432\u0435\u0440"\.. "\u043f\u044f\u0442\u043d\u0456\u0446\u0430"\.. "\u0441\u0443\u0431\u043e\u0442\u0430"].. ::msgcat::mcset be MONTHS_ABBREV [list \.. "\u0441\u0442\u0434"\.. "\u043b\u044e\u0442"\.. "\u0441\u043a\u0432"\.. "\u043a\u0440\u0441"\.. "\u043c\u0430\u0439"\.. "\u0447\u0440\u0432"\.. "\u043b\u043f\u043d"
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1871
                                                                                                                                                                                                                                                          Entropy (8bit):4.4251657008559935
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:43EUAIlnQf/QVdQ81mnEZqEavWQEQ3QvQrQL0QjQTtQDCQSY4tqP:27xMk+nEZqE3biIYbUi+C9y
                                                                                                                                                                                                                                                          MD5:E5225D6478C60E2502D18698BB917677
                                                                                                                                                                                                                                                          SHA1:52D611CB5351FB873D2535246B3A3C1A37094023
                                                                                                                                                                                                                                                          SHA-256:CFE4E44A3A751F113847667EC9EA741E762BBDE0D4284822CB337DF0F92C1ACA
                                                                                                                                                                                                                                                          SHA-512:59AB167177101088057BF4EE0F70262987A2177ECB72C613CCAAE2F3E8D8B77F07D15DA5BE3B8728E23C31A1C9736030AA4036A8CD00A24791751A298B3A88B3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset bg DAYS_OF_WEEK_ABBREV [list \.. "\u041d\u0434"\.. "\u041f\u043d"\.. "\u0412\u0442"\.. "\u0421\u0440"\.. "\u0427\u0442"\.. "\u041f\u0442"\.. "\u0421\u0431"].. ::msgcat::mcset bg DAYS_OF_WEEK_FULL [list \.. "\u041d\u0435\u0434\u0435\u043b\u044f"\.. "\u041f\u043e\u043d\u0435\u0434\u0435\u043b\u043d\u0438\u043a"\.. "\u0412\u0442\u043e\u0440\u043d\u0438\u043a"\.. "\u0421\u0440\u044f\u0434\u0430"\.. "\u0427\u0435\u0442\u0432\u044a\u0440\u0442\u044a\u043a"\.. "\u041f\u0435\u0442\u044a\u043a"\.. "\u0421\u044a\u0431\u043e\u0442\u0430"].. ::msgcat::mcset bg MONTHS_ABBREV [list \.. "I"\.. "II"\.. "III"\.. "IV"\.. "V"\.. "VI"\.. "VII"\.. "VIII"\.. "IX"\.. "X"\.. "XI"\.. "XII"\.. ""].. ::msgcat::mcset bg MO
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2335
                                                                                                                                                                                                                                                          Entropy (8bit):4.107102006297273
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR835e/MWrD//6HFEVcVVcCVcTUTVckVEVcT7VcEEVcby/Vcn0VcMr/0VcM8VcQ:43ktX++QalMObalMZ6IE6V
                                                                                                                                                                                                                                                          MD5:5D25E7FC65824AC987535FEA14A4045C
                                                                                                                                                                                                                                                          SHA1:85C10F05823CD3263FC7B3EC38796BEC261B3716
                                                                                                                                                                                                                                                          SHA-256:890EA6521DEB1B3C3913CCD92562F6360E064DAEE2E2B0356A6DD97A46264A1F
                                                                                                                                                                                                                                                          SHA-512:5D8A88ACAEBBF3CD721F288FA0F1FEE517EE568CA5482E30CFA1E36CD37DF011C449090E2D9041F1D046A191F13D4C5C4B6F9E2F16FD259E63CE46ECC4E4F81F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset bn DAYS_OF_WEEK_ABBREV [list \.. "\u09b0\u09ac\u09bf"\.. "\u09b8\u09cb\u09ae"\.. "\u09ae\u0999\u0997\u09b2"\.. "\u09ac\u09c1\u09a7"\.. "\u09ac\u09c3\u09b9\u09b8\u09cd\u09aa\u09a4\u09bf"\.. "\u09b6\u09c1\u0995\u09cd\u09b0"\.. "\u09b6\u09a8\u09bf"].. ::msgcat::mcset bn DAYS_OF_WEEK_FULL [list \.. "\u09b0\u09ac\u09bf\u09ac\u09be\u09b0"\.. "\u09b8\u09cb\u09ae\u09ac\u09be\u09b0"\.. "\u09ae\u0999\u0997\u09b2\u09ac\u09be\u09b0"\.. "\u09ac\u09c1\u09a7\u09ac\u09be\u09b0"\.. "\u09ac\u09c3\u09b9\u09b8\u09cd\u09aa\u09a4\u09bf\u09ac\u09be\u09b0"\.. "\u09b6\u09c1\u0995\u09cd\u09b0\u09ac\u09be\u09b0"\.. "\u09b6\u09a8\u09bf\u09ac\u09be\u09b0"].. ::msgcat::mcset bn MONTHS_ABBREV [list \.. "\u099c\u09be\u09a8\u09c1\u09df\u09be\u09b0\u09c0"\.. "\u09ab\u09c7\u09ac\u09cd\u09b0\u09c1\u09df\u09be
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):265
                                                                                                                                                                                                                                                          Entropy (8bit):4.868201122972066
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xovtvfluo/E3v6xyFjovto+3vflm68vn:4EnLB383UtvfltE3v6g8tF3vflm6+n
                                                                                                                                                                                                                                                          MD5:B91BB2ABC23B90962D2070B9588F2AB5
                                                                                                                                                                                                                                                          SHA1:CBB4E9CD600773792C6E9F3E6B27E99C1846B44F
                                                                                                                                                                                                                                                          SHA-256:B3D8A4632290B0F3DA690E47C1FDF06A8B9E171A96E938AFDB0DD52CF806CE54
                                                                                                                                                                                                                                                          SHA-512:932FC4B8C3CA72731187D56012AD7DD7777C4D447F16EEB17B9D68235C9590DF99992FD22B8D7C85A843A610F93CD36FAFA993C34C441255A1C0A93C73BC5FE4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset bn_IN DATE_FORMAT "%A %d %b %Y".. ::msgcat::mcset bn_IN TIME_FORMAT_12 "%I:%M:%S %z".. ::msgcat::mcset bn_IN DATE_TIME_FORMAT "%A %d %b %Y %I:%M:%S %z %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1152
                                                                                                                                                                                                                                                          Entropy (8bit):4.2880653012847985
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83FMVBNfPg+g+RjMu5+C6MB4zdiwvWvn:432g6jh65zd3gn
                                                                                                                                                                                                                                                          MD5:72DDD60C907DD235BCE4AB0A5AEE902C
                                                                                                                                                                                                                                                          SHA1:06150F793251687E6FBC3FDA3BC81BCBFC7DE763
                                                                                                                                                                                                                                                          SHA-256:3BE295DCC8FCDC767FED0C68E3867359C18E7E57D7DB6C07236B5BC572AD328E
                                                                                                                                                                                                                                                          SHA-512:3B0A85003692F1E46185D5CC09236D2DA5E6D29166C9812D07A7D6BF6AC6C3B0708F91C6899768D4DBA3528081B8B43E09F49622B70F1CF991AFAC5352B6BA37
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ca DAYS_OF_WEEK_ABBREV [list \.. "dg."\.. "dl."\.. "dt."\.. "dc."\.. "dj."\.. "dv."\.. "ds."].. ::msgcat::mcset ca DAYS_OF_WEEK_FULL [list \.. "diumenge"\.. "dilluns"\.. "dimarts"\.. "dimecres"\.. "dijous"\.. "divendres"\.. "dissabte"].. ::msgcat::mcset ca MONTHS_ABBREV [list \.. "gen."\.. "feb."\.. "mar\u00e7"\.. "abr."\.. "maig"\.. "juny"\.. "jul."\.. "ag."\.. "set."\.. "oct."\.. "nov."\.. "des."\.. ""].. ::msgcat::mcset ca MONTHS_FULL [list \.. "gener"\.. "febrer"\.. "mar\u00e7"\.. "abril"\.. "maig"\.. "juny"\.. "juliol"\.. "agost"\.. "setembre"\.. "octubre"\.. "novembre"\.. "desembre"\.. ""].. ::msg
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1354
                                                                                                                                                                                                                                                          Entropy (8bit):4.466447248030554
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83U4nZ4yJTkkG3mYWEZqO1R3DNBEVG+PYhxrU4UF3ecCvt7/v3e6:43TJTGmnEZqE5/EVEDOGtDp
                                                                                                                                                                                                                                                          MD5:F32EAD82CC26754C5A8E092873A28DB3
                                                                                                                                                                                                                                                          SHA1:325124660F62242B24623B4B737CB4616F86CFF3
                                                                                                                                                                                                                                                          SHA-256:AFEA12A16A6FA750EA610245133B90F178BA714848F89AEC37429A3E7B06BE1A
                                                                                                                                                                                                                                                          SHA-512:04E335AAFBF4D169983635FC87BCFFE86FBA570A3E1820D20240EF7B47E7A3CD94AE3598543DCE92A1F82B5146CAAD982EFE9490EFD9E581D58515CFC3930581
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset cs DAYS_OF_WEEK_ABBREV [list \.. "Ne"\.. "Po"\.. "\u00dat"\.. "St"\.. "\u010ct"\.. "P\u00e1"\.. "So"].. ::msgcat::mcset cs DAYS_OF_WEEK_FULL [list \.. "Ned\u011ble"\.. "Pond\u011bl\u00ed"\.. "\u00dater\u00fd"\.. "St\u0159eda"\.. "\u010ctvrtek"\.. "P\u00e1tek"\.. "Sobota"].. ::msgcat::mcset cs MONTHS_ABBREV [list \.. "I"\.. "II"\.. "III"\.. "IV"\.. "V"\.. "VI"\.. "VII"\.. "VIII"\.. "IX"\.. "X"\.. "XI"\.. "XII"\.. ""].. ::msgcat::mcset cs MONTHS_FULL [list \.. "leden"\.. "\u00fanor"\.. "b\u0159ezen"\.. "duben"\.. "kv\u011bten"\.. "\u010derven"\.. "\u010dervenec"\.. "srpen"\.. "z\u00e1\u0159\u00ed"\.. "\u0159\u00edjen"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1208
                                                                                                                                                                                                                                                          Entropy (8bit):4.315504392809956
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83wV0tBVYuorIsmZ5meAxyISjTHU92WFVwpwvbvT:43w+DiuorreAY0zw8rT
                                                                                                                                                                                                                                                          MD5:27A6A8BE8903AEF9D0BE956906A89583
                                                                                                                                                                                                                                                          SHA1:EE29FDF67CB3AE150DF6BBBE603C1C3F5DA28641
                                                                                                                                                                                                                                                          SHA-256:0D422A991BCA13FE9033118691CFEDAB0F372222EBB0BC92BAF8E914EE816B84
                                                                                                                                                                                                                                                          SHA-512:0E702A679AD94BF479226B7DE32077562F3F95210F6453AE564138386DBB179941BA5359AEE9AC532F4A6E5BE745D6962D6B638A21DD48B865716F2FD2A0CB01
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset da DAYS_OF_WEEK_ABBREV [list \.. "s\u00f8"\.. "ma"\.. "ti"\.. "on"\.. "to"\.. "fr"\.. "l\u00f8"].. ::msgcat::mcset da DAYS_OF_WEEK_FULL [list \.. "s\u00f8ndag"\.. "mandag"\.. "tirsdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "l\u00f8rdag"].. ::msgcat::mcset da MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset da MONTHS_FULL [list \.. "januar"\.. "februar"\.. "marts"\.. "april"\.. "maj"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat::mcset da B
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1276
                                                                                                                                                                                                                                                          Entropy (8bit):4.349293509679722
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83cFNSsZKKgXum47fpK2OaSIui7dHqWZ0ZIBFJWJvvvWIn:43InZKKgXoOqx1W67W9XWIn
                                                                                                                                                                                                                                                          MD5:EE3963A5F7E29C05C9617BE3FD897114
                                                                                                                                                                                                                                                          SHA1:0F978CA174DF596817F872B5EF1B447B9DFE651C
                                                                                                                                                                                                                                                          SHA-256:4C27733502066E8391654D1D372F92BF0484C5A3821E121AE8AA5B99378C99AE
                                                                                                                                                                                                                                                          SHA-512:EA933709C68F8199858A1CC1FFDA67EE7458CC57A163E672535EB0B4C37BFDC200604C7506748DAC3158B6CA63C2F076A2C6252B2A596E59F83D3B1D4BC9C901
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset de DAYS_OF_WEEK_ABBREV [list \.. "So"\.. "Mo"\.. "Di"\.. "Mi"\.. "Do"\.. "Fr"\.. "Sa"].. ::msgcat::mcset de DAYS_OF_WEEK_FULL [list \.. "Sonntag"\.. "Montag"\.. "Dienstag"\.. "Mittwoch"\.. "Donnerstag"\.. "Freitag"\.. "Samstag"].. ::msgcat::mcset de MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mrz"\.. "Apr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset de MONTHS_FULL [list \.. "Januar"\.. "Februar"\.. "M\u00e4rz"\.. "April"\.. "Mai"\.. "Juni"\.. "Juli"\.. "August"\.. "September"\.. "Oktober"\.. "November"\.. "Dezember"\.. ""].. ::msgcat::mcset de BCE "v.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):847
                                                                                                                                                                                                                                                          Entropy (8bit):4.412930056658995
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR831sMm47fpK2++SIui7dHqWZ0ZItovGvzvW:431h+mx1Wm+QjW
                                                                                                                                                                                                                                                          MD5:A6227CD4F7434952D093F1F3C64B4378
                                                                                                                                                                                                                                                          SHA1:0DDB9A49CB83DDF2396B2ECA85093260710496C2
                                                                                                                                                                                                                                                          SHA-256:1C02D14140196623297F858E2EEF00B4159E1C6FAFE044EC65A48C9C24D46540
                                                                                                                                                                                                                                                          SHA-512:D63F34024356F5CE0335D14EA557F4BBF238CCA8265DD27C039C70F7F28FE737F368B030DEE10B2C536512D2815E1F5B19838D08745C6A76A39050D573597EB3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset de_AT MONTHS_ABBREV [list \.. "J\u00e4n"\.. "Feb"\.. "M\u00e4r"\.. "Apr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset de_AT MONTHS_FULL [list \.. "J\u00e4nner"\.. "Februar"\.. "M\u00e4rz"\.. "April"\.. "Mai"\.. "Juni"\.. "Juli"\.. "August"\.. "September"\.. "Oktober"\.. "November"\.. "Dezember"\.. ""].. ::msgcat::mcset de_AT DATE_FORMAT "%Y-%m-%d".. ::msgcat::mcset de_AT TIME_FORMAT "%T".. ::msgcat::mcset de_AT TIME_FORMAT_12 "%T".. ::msgcat::mcset de_AT DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1276
                                                                                                                                                                                                                                                          Entropy (8bit):4.389082225723362
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83B8VSysVB8VsZKKgJ5Mm47fpK26aSIui7dHqWZ0ZIlj5VevjevbDvW:43Bt1VBbZKKgJs6qx1Wc5VojobzW
                                                                                                                                                                                                                                                          MD5:C351057D8E5328C0790901D1F4DBEC9F
                                                                                                                                                                                                                                                          SHA1:F73DE8AEF7F8083B0726760AA003E81067A68588
                                                                                                                                                                                                                                                          SHA-256:532845CD15EC821C1939D000C648694A64E8CA8F0C14BAD5D79682CF991481CE
                                                                                                                                                                                                                                                          SHA-512:8152AD082D0A6A4EBE7E1CCA9D4A5F2E48ABE3F09F4385A517C523A67CA3B08E0F20C193D0F6850F37E55ED0CD6FBD201FE22CC824AF170976D04DB061212F2D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset de_BE DAYS_OF_WEEK_ABBREV [list \.. "Son"\.. "Mon"\.. "Die"\.. "Mit"\.. "Don"\.. "Fre"\.. "Sam"].. ::msgcat::mcset de_BE DAYS_OF_WEEK_FULL [list \.. "Sonntag"\.. "Montag"\.. "Dienstag"\.. "Mittwoch"\.. "Donnerstag"\.. "Freitag"\.. "Samstag"].. ::msgcat::mcset de_BE MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "M\u00e4r"\.. "Apr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset de_BE MONTHS_FULL [list \.. "Januar"\.. "Februar"\.. "M\u00e4rz"\.. "April"\.. "Mai"\.. "Juni"\.. "Juli"\.. "August"\.. "September"\.. "Oktober"\.. "November"\.. "Dezember"\.. ""].. ::m
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2304
                                                                                                                                                                                                                                                          Entropy (8bit):4.371322909589862
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR833v+ZYYWtv+nWfFyL1NYOg+EKVJQ19tWQYmYaYRn9sWuSAJIJ6eRa6WrmdlX:43/pZyLjY0uYR9QmdkjC9r
                                                                                                                                                                                                                                                          MD5:7DD14B1F4FF532DCAF6D4C6F0DF82E9A
                                                                                                                                                                                                                                                          SHA1:707875FEF4207EBB71D066FDC54C7F68560C6DAD
                                                                                                                                                                                                                                                          SHA-256:8B23E0E2F0F319BB9A2DFDCCDC565FF79A62FA85094811189B6BC41594232B6B
                                                                                                                                                                                                                                                          SHA-512:5ECA072DE5DD7890270AE268C7C8D40EE2DB6966643604D16E54194DB0AD74FDA8D04848331E61B387E8B494AF18252E38671D939069EC4C90C672A629563B88
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset el DAYS_OF_WEEK_ABBREV [list \.. "\u039a\u03c5\u03c1"\.. "\u0394\u03b5\u03c5"\.. "\u03a4\u03c1\u03b9"\.. "\u03a4\u03b5\u03c4"\.. "\u03a0\u03b5\u03bc"\.. "\u03a0\u03b1\u03c1"\.. "\u03a3\u03b1\u03b2"].. ::msgcat::mcset el DAYS_OF_WEEK_FULL [list \.. "\u039a\u03c5\u03c1\u03b9\u03b1\u03ba\u03ae"\.. "\u0394\u03b5\u03c5\u03c4\u03ad\u03c1\u03b1"\.. "\u03a4\u03c1\u03af\u03c4\u03b7"\.. "\u03a4\u03b5\u03c4\u03ac\u03c1\u03c4\u03b7"\.. "\u03a0\u03ad\u03bc\u03c0\u03c4\u03b7"\.. "\u03a0\u03b1\u03c1\u03b1\u03c3\u03ba\u03b5\u03c5\u03ae"\.. "\u03a3\u03ac\u03b2\u03b2\u03b1\u03c4\u03bf"].. ::msgcat::mcset el MONTHS_ABBREV [list \.. "\u0399\u03b1\u03bd"\.. "\u03a6\u03b5\u03b2"\.. "\u039c\u03b1\u03c1"\.. "\u0391\u03c0\u03c1"\.. "\u039c\u03b1\u03ca"\.. "\u0399\u03bf\u
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):307
                                                                                                                                                                                                                                                          Entropy (8bit):4.896073290907262
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoCwmGjbmvFjoCws6W3v1oCws6W3v6p6HyFjoCwmT+3vjbe:4EnLB383QrmdSs6W3vss6W3v6QSoJ3ve
                                                                                                                                                                                                                                                          MD5:5B31AD8AC0000B01C4BD04BF6FC4784C
                                                                                                                                                                                                                                                          SHA1:F55145B473DDCAE38A0F7297D58B80B12B2A5271
                                                                                                                                                                                                                                                          SHA-256:705C66C14B6DE682EC7408EABDBA0800C626629E64458971BC8A4CBD3D5DB111
                                                                                                                                                                                                                                                          SHA-512:1CCE6BCAE5D1F7D80E10687F0BCA2AE1B2DD53F04A0F443DC9B552804D60E708E64326B62BA4E3787325D89837B4AC8CCCA9AF6F39CBD654BCC8A9C27EA63BB8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_AU DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset en_AU TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset en_AU TIME_FORMAT_12 "%I:%M:%S %P %z".. ::msgcat::mcset en_AU DATE_TIME_FORMAT "%e/%m/%Y %H:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):312
                                                                                                                                                                                                                                                          Entropy (8bit):4.870560620756039
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoCr3FuoCsX3vtfNrsoCsX3v6YNIdjoCs+3v3FnN9vn:4EnLB383H3Fb3vtNN3v6y43v3FnNNn
                                                                                                                                                                                                                                                          MD5:DDA87ACED97F9F7771788A1A0A1E4433
                                                                                                                                                                                                                                                          SHA1:E221653CD659C095098180344654770FF059331B
                                                                                                                                                                                                                                                          SHA-256:BC87754A253C1036E423FA553DA182DBC56F62A13EDA811D8CD9E8AFA40404A6
                                                                                                                                                                                                                                                          SHA-512:BB95D9241B05686CA15C413746DD06071635CB070F38847BE9702397A86C01A3D54DEBE1ACAA51834AB74DB8D0F75E353995183864E382721425756EE46B0B1E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_BE DATE_FORMAT "%d %b %Y".. ::msgcat::mcset en_BE TIME_FORMAT "%k:%M:%S".. ::msgcat::mcset en_BE TIME_FORMAT_12 "%k h %M min %S s %z".. ::msgcat::mcset en_BE DATE_TIME_FORMAT "%d %b %Y %k:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.915769170926952
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xosmGMoss6W3v6ay/5osmT+3vR6HyFvn:4EnLB383hr8s6W3v6ay/hJ3voSVn
                                                                                                                                                                                                                                                          MD5:4CBF90CE15ECCB6B695AA78D7D659454
                                                                                                                                                                                                                                                          SHA1:30C26ADB03978C5E7288B964A14B692813D6E0B8
                                                                                                                                                                                                                                                          SHA-256:EC48F18995D46F82B1CC71EA285174505A50E3BA2017BCCE2D807149B7543FD0
                                                                                                                                                                                                                                                          SHA-512:CC809EBD1B2B5D9E918C2E2CE4E7075DFB0744C583F17C1C234D8437EF0C34654D2F09FF77544AD3430CEC78ABC70AA5F85F71AD1489A687B8087FCDFE07B088
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_BW DATE_FORMAT "%d %B %Y".. ::msgcat::mcset en_BW TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_BW DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):295
                                                                                                                                                                                                                                                          Entropy (8bit):4.87629705076992
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoAhgqyFjoAZF3vX5oAZF3v6cvBoAh9+3vnFDL8vn:4EnLB383FhgqWDZF3vVZF3v6cvdhI3vM
                                                                                                                                                                                                                                                          MD5:BFC4A48F5B10D137A4D32B440C47D3C6
                                                                                                                                                                                                                                                          SHA1:C90EF2A8291DE589BC12D0A5B8AF2F0B00FEB7CD
                                                                                                                                                                                                                                                          SHA-256:3CF2D0937FD95264549CF5C768B898F01D4875A3EB4A85D457D758BC11DFEC6E
                                                                                                                                                                                                                                                          SHA-512:A91B81A956A438CA7274491CA107A2647CBDFB8AEB5FD7A58238F315590C74F83F2EBA4AA5C4E9A4A54F1FC1636318E94E5E4BBEA467326E0EACED079741E640
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_CA DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset en_CA TIME_FORMAT "%r".. ::msgcat::mcset en_CA TIME_FORMAT_12 "%I:%M:%S %p".. ::msgcat::mcset en_CA DATE_TIME_FORMAT "%a %d %b %Y %r %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):286
                                                                                                                                                                                                                                                          Entropy (8bit):4.892405843607203
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoEbtvqyFjoELE3vLjoELE3v6mjoEbto+3vnFDoAkvn:4EnLB383BbtvqWHLE3vTLE3v6EbtF3vW
                                                                                                                                                                                                                                                          MD5:52E55DE8C489265064A01CEEC823DCDD
                                                                                                                                                                                                                                                          SHA1:16F314A56AE0EAC9DAD58ADDEA6B25813A5BAA05
                                                                                                                                                                                                                                                          SHA-256:C2CE5B74F9E9C190B21C5DF4106303B7B794481228FB9A57065B9C822A1059C3
                                                                                                                                                                                                                                                          SHA-512:6010F29BF75D0CB4EE4F10781423A8CC68D5018DE8C633CD1217A7FE1299A0532E8C0E5D120188B748171EB255C587BB0B64B7384A58F725F3B6A4B9EA04393E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_GB DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset en_GB TIME_FORMAT "%T".. ::msgcat::mcset en_GB TIME_FORMAT_12 "%T".. ::msgcat::mcset en_GB DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):329
                                                                                                                                                                                                                                                          Entropy (8bit):4.851471679101967
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoa+joaQ9PoaAx/G4soaYYW3v6ay/5oaAx/T+3v4x6HyFvn:4EnLB383BSiF4KxW3v6ay/B/3v4ISVn
                                                                                                                                                                                                                                                          MD5:DE2A484508615D7C1377522AFF03E16C
                                                                                                                                                                                                                                                          SHA1:C27C0D10E7667AD95FFF731B4E45B2C6E665CC36
                                                                                                                                                                                                                                                          SHA-256:563450A38DB6C6A1911BC04F4F55B816910B3E768B1465A69F9B3BD27292DBEE
                                                                                                                                                                                                                                                          SHA-512:A360B0FD7E36BCC0FB4603D622C36199E5D4C705396C6701F29730EB5CB33D81B208541CADFAED5303FC329C7C6A465D23CA9584F0DEC2DE128E258478DD6661
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_HK AM "AM".. ::msgcat::mcset en_HK PM "PM".. ::msgcat::mcset en_HK DATE_FORMAT "%B %e, %Y".. ::msgcat::mcset en_HK TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_HK DATE_TIME_FORMAT "%B %e, %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):286
                                                                                                                                                                                                                                                          Entropy (8bit):4.833246107458447
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoK6qyFjoKi+3vLjoKi+3v6mjoKv+3vnFDoAkvn:4EnLB383CqW13vJ3v6b3v9dmn
                                                                                                                                                                                                                                                          MD5:57F0BBE1316D14BC41D0858902A7980A
                                                                                                                                                                                                                                                          SHA1:B68BF99A021B9F01FE69341DF06F5D1453156A97
                                                                                                                                                                                                                                                          SHA-256:9E0DCEE86A03B7BDD831E0008868A9B874C506315BF01DF3982AD3813FD3BA8E
                                                                                                                                                                                                                                                          SHA-512:864F32254AAD39859AFC47D0C90DC5F38CA86EF0BBC7DE61BE253756C22B7806E616B59802C4F4D7B2F5543BF7C070FFF6FAF253E0A337EC443337E63A2E5A57
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_IE DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset en_IE TIME_FORMAT "%T".. ::msgcat::mcset en_IE TIME_FORMAT_12 "%T".. ::msgcat::mcset en_IE DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):318
                                                                                                                                                                                                                                                          Entropy (8bit):4.80637980762728
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoKr3ujoKrGtoKr5vMoKrw3v1oKr5o+3voAsvn:4EnLB383T9xvT3vJF3vonn
                                                                                                                                                                                                                                                          MD5:1A54E506E70B2125C6016B373D3DD074
                                                                                                                                                                                                                                                          SHA1:15289902BAA93208D8FB224E119166D0E044E34E
                                                                                                                                                                                                                                                          SHA-256:ADEA3A1AB8AA84237DDB2F276ABDB96DCB4C51932E920D1A5E336904E1138664
                                                                                                                                                                                                                                                          SHA-512:0D663233E6C96515713B3B829B605E72D8CE581AEF1C02FF6CA96598C040DCA42A3AC765EE9B5002E8969A331EB19A9AF0F8215F7113D0AD2F2EB2C560239D53
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_IN AM "AM".. ::msgcat::mcset en_IN PM "PM".. ::msgcat::mcset en_IN DATE_FORMAT "%d %B %Y".. ::msgcat::mcset en_IN TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset en_IN DATE_TIME_FORMAT "%d %B %Y %H:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):307
                                                                                                                                                                                                                                                          Entropy (8bit):4.939458132662909
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoyejbmvFjo63v1o63v6p6HyFjoy7+3vjb0ysvn:4EnLB383temdj3vd3v6QS1S3ven
                                                                                                                                                                                                                                                          MD5:7E81708F107658FFD31C3BFBF704A488
                                                                                                                                                                                                                                                          SHA1:7941ED040707591B68581337F8D90FA03C5E1406
                                                                                                                                                                                                                                                          SHA-256:EC305B7CB393421E6826D8F4FEA749D3902EBA53BFA488F2B463412F4070B9ED
                                                                                                                                                                                                                                                          SHA-512:8F038FF960F81D96FF9E3454D8ABDA7FFDA5B99DA304ACECC42E74DDBED839388246F66B58928DA902D3B475FBA46602B34F6829A87ECB1124FFC47C036B4DBE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_NZ DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset en_NZ TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset en_NZ TIME_FORMAT_12 "%I:%M:%S %P %z".. ::msgcat::mcset en_NZ DATE_TIME_FORMAT "%e/%m/%Y %H:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):329
                                                                                                                                                                                                                                                          Entropy (8bit):4.824360175945298
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoojoOo2e4soe3v6ay/5o27+3v4x6HyFvn:4EnLB38304u3v6ay/k3v4ISVn
                                                                                                                                                                                                                                                          MD5:E2E3BD806C20D7FB88109B7F3B84C072
                                                                                                                                                                                                                                                          SHA1:2D7AD6BECA9C4D611BAE9747AD55A3E9385C2B42
                                                                                                                                                                                                                                                          SHA-256:3A9C22B07906544C04F7A29B800FCE87C09D7FDF5C251236925115CF251A3890
                                                                                                                                                                                                                                                          SHA-512:B14756B59BCABF8B29B41AC688E4F3A011735AF190B88F88B7B5FDDD3DA77F63FFC0F7875B3B453729CD3BC65E79F75F6E632CA68952EF473F78337D89E80BF2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_PH AM "AM".. ::msgcat::mcset en_PH PM "PM".. ::msgcat::mcset en_PH DATE_FORMAT "%B %e, %Y".. ::msgcat::mcset en_PH TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_PH DATE_TIME_FORMAT "%B %e, %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.911413468674953
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoQW53FuoQGuX3v6ZwoQWa+3v3F0fxvn:4EnLB383V83FOJ3v62c3v3FEn
                                                                                                                                                                                                                                                          MD5:F70245D73BE985091459ADF74B089EBC
                                                                                                                                                                                                                                                          SHA1:21D52C336C08526D9DCF1AEC1F0701CB8B073D7A
                                                                                                                                                                                                                                                          SHA-256:D565679AE9AACBFE3B5273FE29BD46F46FFBB63C837D7925C11356D267F5FF82
                                                                                                                                                                                                                                                          SHA-512:171C70EB10D5E6421A55CE9B1AE99763E23FB6A6F563F69FE099D07C07FCA0CF8D3F6F00C5BB38BFF59A5F4C311506C4A9593F86C12B3B9E1861E72656B3800B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_SG DATE_FORMAT "%d %b %Y".. ::msgcat::mcset en_SG TIME_FORMAT_12 "%P %I:%M:%S".. ::msgcat::mcset en_SG DATE_TIME_FORMAT "%d %b %Y %P %I:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):251
                                                                                                                                                                                                                                                          Entropy (8bit):4.937431055623088
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoOr0lIZoOK3v6poOs+3v0l6Uvn:4EnLB383z+3v6R3vl2n
                                                                                                                                                                                                                                                          MD5:FCA7B13CA6C9527D396A95BEA94CC92D
                                                                                                                                                                                                                                                          SHA1:E6F338A08F72DA11B97F70518D1565E6EF9AD798
                                                                                                                                                                                                                                                          SHA-256:67C253E2A187AA814809418E5B7A21F3A1F9FB5073458A59D80290F58C6C1EB4
                                                                                                                                                                                                                                                          SHA-512:37B8B4EA24B1C77AF0252A17660650CB2D4F8BB55C75817D6A94E1B81A3DDEF9913D12D3BF80C7BFE524CD0AD84E353E73238056759E6545BFE69EF5F806B8B7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_ZA DATE_FORMAT "%Y/%m/%d".. ::msgcat::mcset en_ZA TIME_FORMAT_12 "%I:%M:%S".. ::msgcat::mcset en_ZA DATE_TIME_FORMAT "%Y/%m/%d %I:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.934659260313229
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoEmGMoEs6W3v6ay/5oEmT+3vR6HyFvn:4EnLB383Zr0s6W3v6ay/ZJ3voSVn
                                                                                                                                                                                                                                                          MD5:A302091F490344B7A79C9463480AD7CF
                                                                                                                                                                                                                                                          SHA1:E3992D665077177BAD5A4771F1BAF52C2AD1829C
                                                                                                                                                                                                                                                          SHA-256:6F4754CE29DFA4F0E7957923249151CE8277395D1AF9F102D61B185F85899E4E
                                                                                                                                                                                                                                                          SHA-512:FEBDB0BD6D0FD4C592DB781836F93F0C579399D324112F8829B769303CC6EEA487AAB14EBD60ED1B4F3B3DABF501601C9F65656327FF54853BF2CD9EC6A2F00F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_ZW DATE_FORMAT "%d %B %Y".. ::msgcat::mcset en_ZW TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_ZW DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1285
                                                                                                                                                                                                                                                          Entropy (8bit):4.3537859241297845
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83dRb4vyomrIsmZ55vrAO0LH+50ydAcveva:43PT5rWvrAR60yW6oa
                                                                                                                                                                                                                                                          MD5:D87605E6282713EED41D56D53B7A04FD
                                                                                                                                                                                                                                                          SHA1:41AAD4BD3B72CCBB6A762FEED3C24931642DD867
                                                                                                                                                                                                                                                          SHA-256:98D52CAB5CA65789D1DC37949B65BAF0272AB87BCCBB4D4982C3AF380D5406AB
                                                                                                                                                                                                                                                          SHA-512:4A4F51B2FD0248B52530B5D9FE6BFCFE455147CBE2C1F073804A53666945405F89CBBAD219FFF6904C1F92885F7C53B9D9A969732D662CEA8EC1717B3303B294
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset eo DAYS_OF_WEEK_ABBREV [list \.. "di"\.. "lu"\.. "ma"\.. "me"\.. "\u0135a"\.. "ve"\.. "sa"].. ::msgcat::mcset eo DAYS_OF_WEEK_FULL [list \.. "diman\u0109o"\.. "lundo"\.. "mardo"\.. "merkredo"\.. "\u0135a\u016ddo"\.. "vendredo"\.. "sabato"].. ::msgcat::mcset eo MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "a\u016dg"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset eo MONTHS_FULL [list \.. "januaro"\.. "februaro"\.. "marto"\.. "aprilo"\.. "majo"\.. "junio"\.. "julio"\.. "a\u016dgusto"\.. "septembro"\.. "oktobro"\.. "novembro"\.. "decembro"\.. ""].. ::m
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1232
                                                                                                                                                                                                                                                          Entropy (8bit):4.2910064237800025
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83hEVIhlp4herIsYoorrClH+Fo9ARhprBvtFvr6:43OVY7+ercrmsYsr1thr6
                                                                                                                                                                                                                                                          MD5:91DE6EE8E1A251EF73CC74BFB0216CAC
                                                                                                                                                                                                                                                          SHA1:1FB01E3CF2CAFA95CC451BC34AB89DC542BBD7DD
                                                                                                                                                                                                                                                          SHA-256:E9A6FE8CCE7C808487DA505176984D02F7D644425934CEDB10B521FE1E796202
                                                                                                                                                                                                                                                          SHA-512:46CFD80E68461F165EE6A93AB6B433E4D4DA6A9A76CB7F3EF5766AC67567A7AFFB7B4E950A5AFA7C69C91F72AC82D2A448D32E39BBFC0BF26D2257460471EEC1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es DAYS_OF_WEEK_ABBREV [list \.. "dom"\.. "lun"\.. "mar"\.. "mi\u00e9"\.. "jue"\.. "vie"\.. "s\u00e1b"].. ::msgcat::mcset es DAYS_OF_WEEK_FULL [list \.. "domingo"\.. "lunes"\.. "martes"\.. "mi\u00e9rcoles"\.. "jueves"\.. "viernes"\.. "s\u00e1bado"].. ::msgcat::mcset es MONTHS_ABBREV [list \.. "ene"\.. "feb"\.. "mar"\.. "abr"\.. "may"\.. "jun"\.. "jul"\.. "ago"\.. "sep"\.. "oct"\.. "nov"\.. "dic"\.. ""].. ::msgcat::mcset es MONTHS_FULL [list \.. "enero"\.. "febrero"\.. "marzo"\.. "abril"\.. "mayo"\.. "junio"\.. "julio"\.. "agosto"\.. "septiembre"\.. "octubre"\.. "noviembre"\.. "diciembre"\.. ""].. ::msgc
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):248
                                                                                                                                                                                                                                                          Entropy (8bit):4.878377455979812
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xo8GzvFjot/W3v1o8T+3v9ysvn:4EnLB3833GzdV3vLK3vnn
                                                                                                                                                                                                                                                          MD5:313966A7E4F50BB77996FDE45E342CA9
                                                                                                                                                                                                                                                          SHA1:021DF7211DAE9A635D52F7005672C157DBBAE182
                                                                                                                                                                                                                                                          SHA-256:B97DCEA4FEC3E14632B1511D8C4F9E5A157D97B4EBBC7C6EE100C3558CB2947F
                                                                                                                                                                                                                                                          SHA-512:79DCC76263310523BAF1100C70918FCE6BECB47BE360E4A26F11C61F27E14FC28B588A9253AA0C1F08F45AE8A03312A30FBDCF4FDFFDC5BF9D086C4B539DE022
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_AR DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_AR TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset es_AR DATE_TIME_FORMAT "%d/%m/%Y %H:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.924579610789789
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoYePWWjoU3v6ry/5oY7+3vPUe6HyFvn:4EnLB383nedh3v6ry/nS3vs3SVn
                                                                                                                                                                                                                                                          MD5:EF58B1097A3C6F2133BD7AA8CCC1AD1B
                                                                                                                                                                                                                                                          SHA1:BD479E4635F3CD70A6A90E07B7E92757BC9E2687
                                                                                                                                                                                                                                                          SHA-256:B47F55539DB6F64304DEA080D6F9A39165F1B9D4704DCBA4C182DBD3AA31A11B
                                                                                                                                                                                                                                                          SHA-512:F9EB1489E5002200D255A45DC57132DEFD2A2C6DE5BC049D0D9720575E4FDD1B6A212D9E15974C6A2E0D0886069EA0DD967AD7C20845EC38EB74CBED0C3E5BE1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_BO DATE_FORMAT "%d-%m-%Y".. ::msgcat::mcset es_BO TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_BO DATE_TIME_FORMAT "%d-%m-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.9352990174129925
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xodvPWWjok3v6ry/5odo+3vPUe6HyFvn:4EnLB383OdV3v6ry/i3vs3SVn
                                                                                                                                                                                                                                                          MD5:42BCE0EE3A3F9E9782E5DE72C989903A
                                                                                                                                                                                                                                                          SHA1:0960646417A61E8C31D408AE00B36A1284D0300E
                                                                                                                                                                                                                                                          SHA-256:9D1A2A6EBA673C6F6D964DBCDDF228CB64978F282E70E494B60D74E16A1DB9CB
                                                                                                                                                                                                                                                          SHA-512:C53DDCC17F261CFFAA2205879A131CFD23A7BCF4D3787090A0EA8D18530C4805903ED6CF31B53A34C70510A314EBBB68676E9F128289B42C5EFBC701405D5645
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_CL DATE_FORMAT "%d-%m-%Y".. ::msgcat::mcset es_CL TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_CL DATE_TIME_FORMAT "%d-%m-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.908553844782894
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xo4FjbmvFjo4F+3v6ry/5o4++3vjb0f6HyFvn:4EnLB3831mdD+3v6ry/P3vbSVn
                                                                                                                                                                                                                                                          MD5:6A8F31AE734DCEE4845454408CDB3BC5
                                                                                                                                                                                                                                                          SHA1:A3B9A0124D3CFA9E0E5957612897B23193AD5D59
                                                                                                                                                                                                                                                          SHA-256:5FAC53ACFB305C055AFD0BA824742A78CB506046B26DAC21C73F0BB60C2B889A
                                                                                                                                                                                                                                                          SHA-512:188A65CFE2FBD04D83F363AEA166F224137C8A7009A9EBEB24B2A9AC89D9484D3A7109A4CE08F5C0A28911D81571230CC37554F4F19956AE163F9304911EE53C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_CO DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset es_CO TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_CO DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.919346233482604
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xo76GzvFjoTW3v6ry/5o76T+3v9f6HyFvn:4EnLB383K6Gzdj3v6ry/K6K3vMSVn
                                                                                                                                                                                                                                                          MD5:2EDDA3F61BA4D049E6C871D88322CF72
                                                                                                                                                                                                                                                          SHA1:40AFB64AF810596FCBDBD742ACAFE25CE56F3949
                                                                                                                                                                                                                                                          SHA-256:A33DC22330D087B8567670B4915C334FF1741EE03F05D616CC801ECFDA1D9E64
                                                                                                                                                                                                                                                          SHA-512:B6A6059B44F064C5CB59A3DAFAA7BE9064EE3E38F5FA6391017D931EF3A2B471DC4D556B7BEC6852FD1F6260EF17F476754D6BEA89E035748E9304977513CFB5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_CR DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_CR TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_CR DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.913083040975068
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xomerQZ2jou3v6ry/5om7+3vrQZg6HyFvn:4EnLB383sk4/3v6ry/s3vkrSVn
                                                                                                                                                                                                                                                          MD5:76CFD4F568EA799F9A4082865633FF97
                                                                                                                                                                                                                                                          SHA1:B09846BBF7A78243A5075F2DC9241791DCBA434B
                                                                                                                                                                                                                                                          SHA-256:8DC2F857E91912ED46A94EB6B37DD6170EA7BCDDCD41CB85C0926A74EE12FCC1
                                                                                                                                                                                                                                                          SHA-512:58B20A8A5D1F8C19AC36E61965106266B7E6F7E95DDD6AD9C4BB9FD7FFC561CB0E2103639D901A6A78CE2DD154CBF7F3AE0F71B4DC1CCB11DC6BB40D9C6E2157
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_DO DATE_FORMAT "%m/%d/%Y".. ::msgcat::mcset es_DO TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_DO DATE_TIME_FORMAT "%m/%d/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.915857529388286
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xozgzvFjoro+3v6ry/5oz9+3v9f6HyFvn:4EnLB383OgzdkF3v6ry/OI3vMSVn
                                                                                                                                                                                                                                                          MD5:94B713B1560FE7711EA746F1CEBD37CD
                                                                                                                                                                                                                                                          SHA1:E7047E8F04D731D38FA328FBC0E1856C4A8BB23D
                                                                                                                                                                                                                                                          SHA-256:52AB5A6C9DD4F130A75C049B3AF8F54B84071FC190374BCCF5FA0E1F3B91EB21
                                                                                                                                                                                                                                                          SHA-512:EE807D4D74A609F642CC3C6FC3D736708F67A6931DEB95288AB5822DA256BE4C908A346036195CF4266408458906D28BB5C715EEAFCACFC4FE45D4E6D8E435FE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_EC DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_EC TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_EC DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.9102355704853435
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xohvjbmvFjoI3v6ry/5oho+3vjb0f6HyFvn:4EnLB383KmdJ3v6ry/W3vbSVn
                                                                                                                                                                                                                                                          MD5:761D0A468DF2EE75BC2CAB09D5FF38CD
                                                                                                                                                                                                                                                          SHA1:D627BE45FE71CCB3CA53153393C075FF5136C2F3
                                                                                                                                                                                                                                                          SHA-256:19B4D3025156C060A16328370A3FDB9F141298DECFC8F97BE606F6438FECE2EE
                                                                                                                                                                                                                                                          SHA-512:6CF7C9004A8A3B70495862B7D21921B1A6263C2153FEBC5C4997366498ABBFE70263B436C2B4998550780A4C3A58DCF0AAE7420FF9D414323D731FA44BD83104
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_GT DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset es_GT TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_GT DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.947925914291734
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoIvriSFjoP3v6ry/5oIo+3vrig6HyFvn:4EnLB383V+2m3v6ry/v3v+lSVn
                                                                                                                                                                                                                                                          MD5:33CEE7F947A484B076F5FA7871A30FEB
                                                                                                                                                                                                                                                          SHA1:F77F8D1F42008770A6FF1F5097C863ECF482BEBE
                                                                                                                                                                                                                                                          SHA-256:07873D4D59BB41000706A844859C73D26B1FF794058AA83CFFCA804981A24038
                                                                                                                                                                                                                                                          SHA-512:EBF6873F9CB554489EFCD352943100C00171E49D27153769D1C4DB25E2D1F44F2D34869B596C267C9BB59ED0444468D9982137CFB1C6035FB15A855BB867133B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_HN DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_HN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_HN DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.9102355704853435
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoPjbmvFjoH+3v6ry/5oI+3vjb0f6HyFvn:4EnLB383UmdD3v6ry/k3vbSVn
                                                                                                                                                                                                                                                          MD5:678D7A6DC32355246BF3AC485A24AF4D
                                                                                                                                                                                                                                                          SHA1:B6C273D3BE5FB9F5A221B0333870CCE41CEDFDE4
                                                                                                                                                                                                                                                          SHA-256:A0F57137D2C0ABDC933E03CFB188F5632176C195CEADB9DC80D469C8DC6CEDC6
                                                                                                                                                                                                                                                          SHA-512:571404CCB0591C681C975E3F7A6C6972FAF2362F1D48BFC95E69A9EAE2DB3F40BF4B666C41950C4924E3FD820C61ED91204F92283B8554F1BD35B64D53BD4125
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_MX DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset es_MX TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_MX DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.918215906418583
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoe/GriSFjo3W3v6ry/5oe/T+3vrig6HyFvn:4EnLB383Re+2eW3v6ry/RS3v+lSVn
                                                                                                                                                                                                                                                          MD5:471C41907CE5DB1F30C647A789870F78
                                                                                                                                                                                                                                                          SHA1:C575A639609620AF7C56430991D0E4C2B50BDEC5
                                                                                                                                                                                                                                                          SHA-256:6250663DA1378E54BEDCEF206583D212BC0D61D04D070495238D33715BB20CAE
                                                                                                                                                                                                                                                          SHA-512:CAE32DF8F583542CAFE3292501725D85B697A5C1F9A0A7993490E8A69B6CE5CE3DE3AA2733B14D989A8D13B5E31B437DB42E9AB9D1851FE72313592C752B5061
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_NI DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_NI TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_NI DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.906719336603863
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoX5rQZ2joHE3v6ry/5oXa+3vrQZg6HyFvn:4EnLB383ak4F3v6ry/G3vkrSVn
                                                                                                                                                                                                                                                          MD5:571F6716293442672521F70854A5AD05
                                                                                                                                                                                                                                                          SHA1:525EBDEA6F85FC769B6C0C0B179BD98381647123
                                                                                                                                                                                                                                                          SHA-256:EBB661C1C09E7D4F6FBCC4B2DAD0F41442B1FFDD27F003ABDC0375DD316E57D7
                                                                                                                                                                                                                                                          SHA-512:C6176EE48515BDFC09B8347DAC5FD2C0165AA765916457DC7B057E526785AC912481CB72F118D2943372213B23CE3C39739263C2B3DA4DBFEB24C522ACC0439D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PA DATE_FORMAT "%m/%d/%Y".. ::msgcat::mcset es_PA TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PA DATE_TIME_FORMAT "%m/%d/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.90959433688075
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoIgzvFjoQ9X3v6ry/5oI9+3v9f6HyFvn:4EnLB383+zdB3v6ry/y3vMSVn
                                                                                                                                                                                                                                                          MD5:5A5997D834DDD3E2E8FF8C6956AD54AC
                                                                                                                                                                                                                                                          SHA1:AB4110E37B3665D738A8F2B3E64CBA9E99127301
                                                                                                                                                                                                                                                          SHA-256:90C130B66958CF63CB3DDD2C633E58444357DBAB44C56831DD794CBD2EB1AED0
                                                                                                                                                                                                                                                          SHA-512:1FEB8E77EA7B886E4A06279AC8A4B6200DBB86DCD28989651B92A0C9147A7BCFBB871DF8F904A1CF8F869BFFBD21325505AC44A4DBEBE1EFC87D43174597F1F3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PE DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_PE TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PE DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.905689521403511
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xo06GriSFjoeW3v6ry/5o06T+3vrig6HyFvn:4EnLB383gG+263v6ry/gK3v+lSVn
                                                                                                                                                                                                                                                          MD5:CE811BB8D12C7E6D53338759CCFB0A22
                                                                                                                                                                                                                                                          SHA1:0AED290AA479DE6887CCB58D3F0A0F379EF8D558
                                                                                                                                                                                                                                                          SHA-256:F790E8E48DC079DCD7DEB58170561006A31294F7E4ACBF9CF2ABFA3DB9E3FA9E
                                                                                                                                                                                                                                                          SHA-512:0C73654CC3D33F76D9BF545BD6C5E42CBDD10B6D9750BFD6536806010F3B6A3C3647FB9D5E7E75A39823FDB857E13D07B7F987809C94B9F980E6D3A6D3108E85
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PR DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_PR TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PR DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.917539255090736
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xo/5zvFjovE3v6ry/5o/a+3v9f6HyFvn:4EnLB383Czdt3v6ry/+3vMSVn
                                                                                                                                                                                                                                                          MD5:9CD6FAC4121E3D287C87157142E32845
                                                                                                                                                                                                                                                          SHA1:3081FE2197017EC8E052756A407880C1C4ED026A
                                                                                                                                                                                                                                                          SHA-256:70263F7EB22822DFEE8849B7AC4418ED9331275A71E77236B59226396505CDFF
                                                                                                                                                                                                                                                          SHA-512:25DC054085C4078734988EEDD87E31ABE93DA8B43512E924DE4BCDE9F8EC670436B72FAD1855484F9AC71DD0BEDD9ED30304D02219C4FFC4B0516D8889BDF9F9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PY DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_PY TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PY DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.929035824905457
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xofriSFjo3+3v6ry/5oY+3vrig6HyFvn:4EnLB383Y+22+3v6ry/Q3v+lSVn
                                                                                                                                                                                                                                                          MD5:AF300EA6E733DC6820768EA16194B472
                                                                                                                                                                                                                                                          SHA1:7766A6EB3D07BCC759CF6718EF3D6EC3FCE13565
                                                                                                                                                                                                                                                          SHA-256:26A38B3745C95673D21BABB987F1D41EE08DDA945C670F5432BA0CE6F893C0E9
                                                                                                                                                                                                                                                          SHA-512:C38D67C912584BE539D71881C6517AC186CBB336A160602DA716CE2708B2D38CE8FA7DD23EDB98890ABB7119B924B6C7816C18EC18F20C49D6284DF2386E32EE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_SV DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_SV TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_SV DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.923802447598272
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xooygzvFjooq9X3v6ry/5ooy9+3v9f6HyFvn:4EnLB3835rzdbsX3v6ry/5J3vMSVn
                                                                                                                                                                                                                                                          MD5:2DC550FEC3F477B1159B824479BCE707
                                                                                                                                                                                                                                                          SHA1:4D0B20CF3E50B64D74655A405A7750E0B0BB4375
                                                                                                                                                                                                                                                          SHA-256:1291B58810739EA0651493DD7887F5EE3E14BDB806E06DD4BB8AE2520C742EDA
                                                                                                                                                                                                                                                          SHA-512:B12B927ACA6274904928A6A6CAEC8339A794C74A1F1804FF93AABC132AF9AD8AC5117F20067A60EFEBC9887150D7ACA5BE9643FF61509666011FD203211C25B9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_UY DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_UY TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_UY DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.928484426267027
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoXrzvFjoXK3v6ry/5oXs+3v9f6HyFvn:4EnLB3838zdv3v6ry/c3vMSVn
                                                                                                                                                                                                                                                          MD5:184D6C4B9F0AA874DEB959F63F7CC01B
                                                                                                                                                                                                                                                          SHA1:5FB370B498289590C977F6B489FF646F0FB27425
                                                                                                                                                                                                                                                          SHA-256:91191517403C712299919F9C797F952502E33CB6961D1DBEE3A7C9E8D2B170B9
                                                                                                                                                                                                                                                          SHA-512:881CCAB0950AE993744ECCA141120C005F53D684167A3E5CBDDF950D110D630FB2B4F6AE6E3D0E06D5110AE25EA00A4F4DAFB03AD3B227DC8C63464D434431DA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_VE DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_VE TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_VE DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1258
                                                                                                                                                                                                                                                          Entropy (8bit):4.391217201307309
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83P1Y2+1YoQVTsC/m48qpRTVTR7I/68qqq4Z0yoN7emG5wsvtqmsv5t:43P1p+1jQ9sq8y9v8Yko7emG5wKtqmKX
                                                                                                                                                                                                                                                          MD5:C8C5EF2FA6DD8DBD5BBD2699BE1A0BF6
                                                                                                                                                                                                                                                          SHA1:F5E26B40786B8987C98F9CBDEF5522043574A9ED
                                                                                                                                                                                                                                                          SHA-256:4BEE224C21B0483CFF39BE145C671AA20CB7872C8727FD918C0E8ECA2BBEB172
                                                                                                                                                                                                                                                          SHA-512:757FA85C137A11C1A3F4A8392C7A4E4030A67D0E593FA25A98BEC07DB295399AB2C0D9EBE61E07420B14387A29C060DC3AF812A1E7B85110DBB13C3C3DCB3600
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset et DAYS_OF_WEEK_ABBREV [list \.. "P"\.. "E"\.. "T"\.. "K"\.. "N"\.. "R"\.. "L"].. ::msgcat::mcset et DAYS_OF_WEEK_FULL [list \.. "p\u00fchap\u00e4ev"\.. "esmasp\u00e4ev"\.. "teisip\u00e4ev"\.. "kolmap\u00e4ev"\.. "neljap\u00e4ev"\.. "reede"\.. "laup\u00e4ev"].. ::msgcat::mcset et MONTHS_ABBREV [list \.. "Jaan"\.. "Veebr"\.. "M\u00e4rts"\.. "Apr"\.. "Mai"\.. "Juuni"\.. "Juuli"\.. "Aug"\.. "Sept"\.. "Okt"\.. "Nov"\.. "Dets"\.. ""].. ::msgcat::mcset et MONTHS_FULL [list \.. "Jaanuar"\.. "Veebruar"\.. "M\u00e4rts"\.. "Aprill"\.. "Mai"\.. "Juuni"\.. "Juuli"\.. "August"\.. "September"\.. "Oktoober"\.. "November"\.. "De
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1032
                                                                                                                                                                                                                                                          Entropy (8bit):4.002617252503668
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83DEXk8TT7vXk8TTMtzCIsOo/ssP6tvf1I49sHT:434bTbbTc+RjKi4mz
                                                                                                                                                                                                                                                          MD5:ED9805AF5BFB54EB28C6CB3975F86F5B
                                                                                                                                                                                                                                                          SHA1:2BD91BD850028712F35A2DDB2555036FBF6E8114
                                                                                                                                                                                                                                                          SHA-256:6889B57D29B670C6CFB7B5A3F2F1749D12C802E8E9629014D06CE23C034C7EF1
                                                                                                                                                                                                                                                          SHA-512:16F31DE5D2B0D3ED2D975C7891C73C48F073CDAC28F17572FC9424C2D384DDFE9E5E235F17C788F42840CB2D819D2D9499B909AB80FEF1B09F2AE1627CF1DADC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset eu DAYS_OF_WEEK_ABBREV [list \.. "igandea"\.. "astelehena"\.. "asteartea"\.. "asteazkena"\.. "osteguna"\.. "ostirala"\.. "larunbata"].. ::msgcat::mcset eu DAYS_OF_WEEK_FULL [list \.. "igandea"\.. "astelehena"\.. "asteartea"\.. "asteazkena"\.. "osteguna"\.. "ostirala"\.. "larunbata"].. ::msgcat::mcset eu MONTHS_ABBREV [list \.. "urt"\.. "ots"\.. "mar"\.. "api"\.. "mai"\.. "eka"\.. "uzt"\.. "abu"\.. "ira"\.. "urr"\.. "aza"\.. "abe"\.. ""].. ::msgcat::mcset eu MONTHS_FULL [list \.. "urtarrila"\.. "otsaila"\.. "martxoa"\.. "apirila"\.. "maiatza"\.. "ekaina"\.. "uztaila"\.. "abuztua"\.. "iraila"\.. "urria"\.. "azaroa"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):294
                                                                                                                                                                                                                                                          Entropy (8bit):4.915392589807169
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoszFnJF+l6VvBoszw3vLjoszw3v6mjosz++3v/RHvn:4EnLB383FL+l6VQ3vO3v6G3vZPn
                                                                                                                                                                                                                                                          MD5:4C91AA000D4316585893025CBB96E910
                                                                                                                                                                                                                                                          SHA1:3D4E73839A1A8CB9DEC1E59D9D2813257D9480F0
                                                                                                                                                                                                                                                          SHA-256:D45CC432E5743E6CEC34E9A1E0F91A9D5C315CDA409E0826B51AD9D908479EB6
                                                                                                                                                                                                                                                          SHA-512:0731F2EEB22ADC7EF8AF215B9EB4C5A66B33BC90E4F80CF7AA482AD002CB30543547230124A0507EC79EDDD6903A042EDA5D7C8AFD77F7FC994EFC6853FABB05
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset eu_ES DATE_FORMAT "%a, %Yeko %bren %da".. ::msgcat::mcset eu_ES TIME_FORMAT "%T".. ::msgcat::mcset eu_ES TIME_FORMAT_12 "%T".. ::msgcat::mcset eu_ES DATE_TIME_FORMAT "%y-%m-%d %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1711
                                                                                                                                                                                                                                                          Entropy (8bit):4.21837106187395
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83CnMqnbxbGwgjSyiY/Xw2mS1yM/8ye48YyfNqTb2gyj/8yHkQp:43Yzyhgvs9yi4P
                                                                                                                                                                                                                                                          MD5:7AB25F4E7E457469DC61A33176B3AA72
                                                                                                                                                                                                                                                          SHA1:EEA98283D250A99E33DD4D5D9B1B76A029716CE6
                                                                                                                                                                                                                                                          SHA-256:86898728B275288693B200568DC927C3FF5B9050690876C4441A8339DAE06386
                                                                                                                                                                                                                                                          SHA-512:7524437F91E91751BEB7A378D7674C49E5D84B716FE962F4C23580C46A671F3F33638FCD37A8F90C86E24DA8F54448E06AC9C3AEFFB5613E94A04E512C1AD68D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fa DAYS_OF_WEEK_ABBREV [list \.. "\u06cc\u2214"\.. "\u062f\u2214"\.. "\u0633\u2214"\.. "\u0686\u2214"\.. "\u067e\u2214"\.. "\u062c\u2214"\.. "\u0634\u2214"].. ::msgcat::mcset fa DAYS_OF_WEEK_FULL [list \.. "\u06cc\u06cc\u200c\u0634\u0646\u0628\u0647"\.. "\u062f\u0648\u0634\u0646\u0628\u0647"\.. "\u0633\u0647\u200c\u0634\u0646\u0628\u0647"\.. "\u0686\u0647\u0627\u0631\u0634\u0646\u0628\u0647"\.. "\u067e\u0646\u062c\u200c\u0634\u0646\u0628\u0647"\.. "\u062c\u0645\u0639\u0647"\.. "\u0634\u0646\u0628\u0647"].. ::msgcat::mcset fa MONTHS_ABBREV [list \.. "\u0698\u0627\u0646"\.. "\u0641\u0648\u0631"\.. "\u0645\u0627\u0631"\.. "\u0622\u0648\u0631"\.. "\u0645\u0640\u0647"\.. "\u0698\u0648\u0646"\.. "\u0698\u0648\u06cc"\.. "\u0627\u0648\u062a
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2009
                                                                                                                                                                                                                                                          Entropy (8bit):4.491667766230948
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83KnMqnbxbGUgjDiY/Xw2mS1yM/8ye48tfNqTb2gyj/8yHkQLoRv9v/vNv0P:43wihgvsai4Rmv53JU
                                                                                                                                                                                                                                                          MD5:C59EE7CA80AD9F612A21C8B6674A820E
                                                                                                                                                                                                                                                          SHA1:AEFD631EFC1892063244FA622DE1A091C461E370
                                                                                                                                                                                                                                                          SHA-256:6B56545C1AE1DE53BC2389BB7AE59F115BADE24F907E384E079491DC77D6541D
                                                                                                                                                                                                                                                          SHA-512:42F52091480599D317FB80DF8E52A6C6F88614C6172BF4033974DD136FB30E6F47D38982C8A7BC14CF3165C3EBAE3680F94DF3A0ED079AB68165286251CD0BD7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fa_IN DAYS_OF_WEEK_ABBREV [list \.. "\u06cc\u2214"\.. "\u062f\u2214"\.. "\u0633\u2214"\.. "\u0686\u2214"\.. "\u067e\u2214"\.. "\u062c\u2214"\.. "\u0634\u2214"].. ::msgcat::mcset fa_IN DAYS_OF_WEEK_FULL [list \.. "\u06cc\u06cc\u200c\u0634\u0646\u0628\u0647"\.. "\u062f\u0648\u0634\u0646\u0628\u0647"\.. "\u0633\u0647\u200c\u0634\u0646\u0628\u0647"\.. "\u0686\u0647\u0627\u0631\u0634\u0646\u0628\u0647"\.. "\u067e\u0646\u062c\u200c\u0634\u0646\u0628\u0647"\.. "\u062c\u0645\u0639\u0647"\.. "\u0634\u0646\u0628\u0647"].. ::msgcat::mcset fa_IN MONTHS_ABBREV [list \.. "\u0698\u0627\u0646"\.. "\u0641\u0648\u0631"\.. "\u0645\u0627\u0631"\.. "\u0622\u0648\u0631"\.. "\u0645\u0640\u0647"\.. "\u0698\u0648\u0646"\.. "\u0698\u0648\u06cc"\.. "\u0627\u0
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):426
                                                                                                                                                                                                                                                          Entropy (8bit):5.12739029869254
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:4EnLB383D2WGz7A/3vy3v6TANCmK3vz7AAbn:4aR83DoPivkvFk5vPN
                                                                                                                                                                                                                                                          MD5:9778A7C3ABD37ECBEC0BB9715E52FAF8
                                                                                                                                                                                                                                                          SHA1:D8063CA7779674EB1D9FE3E4B4774DB20B93038B
                                                                                                                                                                                                                                                          SHA-256:3D9779C27E8960143D00961F6E82124120FD47B7F3CB82DB3DF21CDD9090C707
                                                                                                                                                                                                                                                          SHA-512:B90B4A96CE5E8B9BF512B98C406603C60EA00F6740D04CD1FC30810C7155A37851AE5E28716F959137806F1A9E3152D2A0D79B8EA7E681A0737A28593657DE66
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fa_IR AM "\u0635\u0628\u062d".. ::msgcat::mcset fa_IR PM "\u0639\u0635\u0631".. ::msgcat::mcset fa_IR DATE_FORMAT "%d\u2044%m\u2044%Y".. ::msgcat::mcset fa_IR TIME_FORMAT "%S:%M:%H".. ::msgcat::mcset fa_IR TIME_FORMAT_12 "%S:%M:%l %P".. ::msgcat::mcset fa_IR DATE_TIME_FORMAT "%d\u2044%m\u2044%Y %S:%M:%H %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1195
                                                                                                                                                                                                                                                          Entropy (8bit):4.32217771842326
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83KTvIhmuw4tW/UWJTttWKeqA+3ewvtyv3e6:43YvIwuw4t05ttnlzt0p
                                                                                                                                                                                                                                                          MD5:CC06F0ABD8F985654DAD8256598EBCB7
                                                                                                                                                                                                                                                          SHA1:71C880F9F395ACD32AF7F538033211F392F83645
                                                                                                                                                                                                                                                          SHA-256:9929A6B7139BD7E0F29487F7888A83E4C4F5E9CE0352738CFCA94EE2DDF3BD6B
                                                                                                                                                                                                                                                          SHA-512:E1292665270B6FBF7738CC3864B55194E7B827C6AD9492FB2E54DC1B626159B243052CE502335B9D92E2B8F58A4DD1FA0E628CB6A9D1D3A652FE2B93A3FB711A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fi DAYS_OF_WEEK_ABBREV [list \.. "su"\.. "ma"\.. "ti"\.. "ke"\.. "to"\.. "pe"\.. "la"].. ::msgcat::mcset fi DAYS_OF_WEEK_FULL [list \.. "sunnuntai"\.. "maanantai"\.. "tiistai"\.. "keskiviikko"\.. "torstai"\.. "perjantai"\.. "lauantai"].. ::msgcat::mcset fi MONTHS_ABBREV [list \.. "tammi"\.. "helmi"\.. "maalis"\.. "huhti"\.. "touko"\.. "kes\u00e4"\.. "hein\u00e4"\.. "elo"\.. "syys"\.. "loka"\.. "marras"\.. "joulu"\.. ""].. ::msgcat::mcset fi MONTHS_FULL [list \.. "tammikuu"\.. "helmikuu"\.. "maaliskuu"\.. "huhtikuu"\.. "toukokuu"\.. "kes\u00e4kuu"\.. "hein\u00e4kuu"\.. "elokuu"\.. "syyskuu"\.. "lokakuu"\.. "marraskuu"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1033
                                                                                                                                                                                                                                                          Entropy (8bit):4.15884265510429
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR834YPxTSBFSa+E6rIsmYmyAxyIQbXHU92W1T:43a6rIyAE0B
                                                                                                                                                                                                                                                          MD5:5D224E66FD9521CA4327D4F164CD6585
                                                                                                                                                                                                                                                          SHA1:FC8F4C1D9A69931679028DE02155D96A18F6542E
                                                                                                                                                                                                                                                          SHA-256:2EC9B03469FA38B260915C93318F446EA5E12B9090BD441936B57552EBA1E3C9
                                                                                                                                                                                                                                                          SHA-512:0E0F97D99F0274A8A92AA7DC992B252A0BB696D69A8835602D8F4C03A6A15780F45971F00863436949CD81AD7DF6EE6BC463CE5B9FECF5E39508BA4D4E83C693
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fo DAYS_OF_WEEK_ABBREV [list \.. "sun"\.. "m\u00e1n"\.. "t\u00fds"\.. "mik"\.. "h\u00f3s"\.. "fr\u00ed"\.. "ley"].. ::msgcat::mcset fo DAYS_OF_WEEK_FULL [list \.. "sunnudagur"\.. "m\u00e1nadagur"\.. "t\u00fdsdagur"\.. "mikudagur"\.. "h\u00f3sdagur"\.. "fr\u00edggjadagur"\.. "leygardagur"].. ::msgcat::mcset fo MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "mai"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "des"\.. ""].. ::msgcat::mcset fo MONTHS_FULL [list \.. "januar"\.. "februar"\.. "mars"\.. "apr\u00edl"\.. "mai"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):286
                                                                                                                                                                                                                                                          Entropy (8bit):4.864028070948858
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoZA4WjoZd3vLjoZd3v6mjoZd+3vnFDoAkvn:4EnLB3831P23vS3v6u3v9dmn
                                                                                                                                                                                                                                                          MD5:92E2B6483B2374817548F4EAA1731820
                                                                                                                                                                                                                                                          SHA1:071E1E9368CCB4EC864E78622B2113F460920203
                                                                                                                                                                                                                                                          SHA-256:C3DCCF5E5904C24D4AD9AAA36160A78F5397A7452510C0C0E61DE4DE863305CB
                                                                                                                                                                                                                                                          SHA-512:E79D4D38A22298252FA46D15C383CFB2A1E49E8196C265A58F9BA4982DFD9CE29E87C0B85BE3F39617359451831B792FCD3092A52EDF8FFD999AFE5CFE1D170D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fo_FO DATE_FORMAT "%d/%m-%Y".. ::msgcat::mcset fo_FO TIME_FORMAT "%T".. ::msgcat::mcset fo_FO TIME_FORMAT_12 "%T".. ::msgcat::mcset fo_FO DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1257
                                                                                                                                                                                                                                                          Entropy (8bit):4.383721663740675
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR835LzAX2t6KOkPwzZIGzRmzQf1waGqHvivh:43mlwIFZtA/qPkh
                                                                                                                                                                                                                                                          MD5:4D63B4A7CF13A28A6F6784B5597EEF43
                                                                                                                                                                                                                                                          SHA1:FE1B35A93CB72666D7D6BC37D9BE081B05A00CD9
                                                                                                                                                                                                                                                          SHA-256:96B1E1E12CD13A56722EBF27D362C70B467342FA1282A40B89FB16B5105A0480
                                                                                                                                                                                                                                                          SHA-512:5647CAE859B62C7CE1CEE6426A076361D2A29EFE6B6F311DDC0E7D006194BA68D575852FEC5FDE2AB43DF8AE440C57013D32A3951095CB856327070FD9BD1C76
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr DAYS_OF_WEEK_ABBREV [list \.. "dim."\.. "lun."\.. "mar."\.. "mer."\.. "jeu."\.. "ven."\.. "sam."].. ::msgcat::mcset fr DAYS_OF_WEEK_FULL [list \.. "dimanche"\.. "lundi"\.. "mardi"\.. "mercredi"\.. "jeudi"\.. "vendredi"\.. "samedi"].. ::msgcat::mcset fr MONTHS_ABBREV [list \.. "janv."\.. "f\u00e9vr."\.. "mars"\.. "avr."\.. "mai"\.. "juin"\.. "juil."\.. "ao\u00fbt"\.. "sept."\.. "oct."\.. "nov."\.. "d\u00e9c."\.. ""].. ::msgcat::mcset fr MONTHS_FULL [list \.. "janvier"\.. "f\u00e9vrier"\.. "mars"\.. "avril"\.. "mai"\.. "juin"\.. "juillet"\.. "ao\u00fbt"\.. "septembre"\.. "octobre"\.. "novembre"\.. "d\u00e9cembre
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):286
                                                                                                                                                                                                                                                          Entropy (8bit):4.910112619660625
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoXqyFjoIX3vLjoIX3v6mjog+3vnFDoAkvn:4EnLB383AqWv3vL3v6d3v9dmn
                                                                                                                                                                                                                                                          MD5:07EEADB8C2F2425FF9A27E46A81827A2
                                                                                                                                                                                                                                                          SHA1:AA18A651C64098C7885F1F869B9F221453F42987
                                                                                                                                                                                                                                                          SHA-256:AAD828BCBB512FBD9902DCDD3812247A74913CC574DEB07DA95A7BBE74B1FE48
                                                                                                                                                                                                                                                          SHA-512:1FA60B1A69B2F5FD2C009EC18695A937C4484D7C418F7E8398D95723B857698143E0584A546F9032B75894730CBBEF78453061AC13D90199FF702E148D983C28
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr_BE DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset fr_BE TIME_FORMAT "%T".. ::msgcat::mcset fr_BE TIME_FORMAT_12 "%T".. ::msgcat::mcset fr_BE DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):286
                                                                                                                                                                                                                                                          Entropy (8bit):4.890376345610709
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xooIso13vLjo13v6mjo1+3vnFDoAkvn:4EnLB383vIF3vU3v6A3v9dmn
                                                                                                                                                                                                                                                          MD5:2F70BDDE7685E2892C5F79C632FC2F0F
                                                                                                                                                                                                                                                          SHA1:FD1A6F6042E59D1563ABB5858C348C1D785C435E
                                                                                                                                                                                                                                                          SHA-256:0624DF9A56723DDB89E59736C20A5837DEA2206A789EBE7EEF19AD287590CA45
                                                                                                                                                                                                                                                          SHA-512:50FC0C91AB2C75FFC4F100C0D42DFC4B2101DB9713FD77E6FF5BF3F25A0AF4A535A4709CF4586809CEEE76C25B66ABC0DD4FD61524510C57AA0E63EA8F46E8D5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr_CA DATE_FORMAT "%Y-%m-%d".. ::msgcat::mcset fr_CA TIME_FORMAT "%T".. ::msgcat::mcset fr_CA TIME_FORMAT_12 "%T".. ::msgcat::mcset fr_CA DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):288
                                                                                                                                                                                                                                                          Entropy (8bit):4.913241133684606
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoFt28oF+3vLjoF+3v6mjo++3vnFDoAkvn:4EnLB383yte+3vs+3v6/3v9dmn
                                                                                                                                                                                                                                                          MD5:83FC7EBA68C3727F7C13C8EEAF79823F
                                                                                                                                                                                                                                                          SHA1:81C27F9B97F5F5190F7189230535EC09CD228158
                                                                                                                                                                                                                                                          SHA-256:290CA6EB74BAEAC4E2420D0755D148849F89EE87E37860F25CBB7B8AFA3EDCBC
                                                                                                                                                                                                                                                          SHA-512:35DA46558A246D7B3FAB02208001CE986E2E6DD88D6318AF743F4E81CA6920471D1425BB009A7476A79E7F61E1353C027B765331CD8EFA07A9E884DCB73F2195
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr_CH DATE_FORMAT "%d. %m. %y".. ::msgcat::mcset fr_CH TIME_FORMAT "%T".. ::msgcat::mcset fr_CH TIME_FORMAT_12 "%T".. ::msgcat::mcset fr_CH DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1188
                                                                                                                                                                                                                                                          Entropy (8bit):4.314271783103334
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR835k0CM/hlrXa754pD73/tKSx54pbIK5f2CA:43W05rXUa173/VadDA
                                                                                                                                                                                                                                                          MD5:67D137E5D853DB61A4B4264871E793F7
                                                                                                                                                                                                                                                          SHA1:4280E7F662DE792175AF8B4C93874F035F716F0F
                                                                                                                                                                                                                                                          SHA-256:880806867ACABD9B39E3029A5ADD26B690CC5709082D43B0959EBA725EA07AB5
                                                                                                                                                                                                                                                          SHA-512:C27B745143539D3E6D94BB754DCA35065CDE9B1AA6EE038D47F658175CFACC20236124D38BE5BBB03CAF8F613BD748C43CB8DFCC9234E915D18B5A477BAEF94E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ga DAYS_OF_WEEK_ABBREV [list \.. "Domh"\.. "Luan"\.. "M\u00e1irt"\.. "C\u00e9ad"\.. "D\u00e9ar"\.. "Aoine"\.. "Sath"].. ::msgcat::mcset ga DAYS_OF_WEEK_FULL [list \.. "D\u00e9 Domhnaigh"\.. "D\u00e9 Luain"\.. "D\u00e9 M\u00e1irt"\.. "D\u00e9 C\u00e9adaoin"\.. "D\u00e9ardaoin"\.. "D\u00e9 hAoine"\.. "D\u00e9 Sathairn"].. ::msgcat::mcset ga MONTHS_ABBREV [list \.. "Ean"\.. "Feabh"\.. "M\u00e1rta"\.. "Aib"\.. "Beal"\.. "Meith"\.. "I\u00fail"\.. "L\u00fan"\.. "MF\u00f3mh"\.. "DF\u00f3mh"\.. "Samh"\.. "Noll"\.. ""].. ::msgcat::mcset ga MONTHS_FULL [list \.. "Ean\u00e1ir"\.. "Feabhra"\.. "M\u00e1rta"\.. "Aibre\u00e1n"\.. "M\u00ed na Bealtaine"\.. "Meith"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):286
                                                                                                                                                                                                                                                          Entropy (8bit):4.824539027053997
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xobHAygDobHAqo+3vLjobHAqo+3v6mjobHAy9+3vnFDoAkv:4EnLB383p23vy3v6a3v9dmn
                                                                                                                                                                                                                                                          MD5:C27BD7F317AAADB380F4C38AE0D2FDA6
                                                                                                                                                                                                                                                          SHA1:79870A0E68AA0A9B301414EDC21889F83BB81E40
                                                                                                                                                                                                                                                          SHA-256:3F9615C617D3CDBC1E127B3EFEE785B0CB5E92E17B7DABAC80DA2BEAF076362C
                                                                                                                                                                                                                                                          SHA-512:3605B9A914284CF1D3CC90DF2F21A86C0472AEE59800942DC93D842C7AE164E1DA72813787F163DC80B72269D2C391953ABAD6A8B72CCF069BEE96D418A173E9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ga_IE DATE_FORMAT "%d.%m.%y".. ::msgcat::mcset ga_IE TIME_FORMAT "%T".. ::msgcat::mcset ga_IE TIME_FORMAT_12 "%T".. ::msgcat::mcset ga_IE DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):997
                                                                                                                                                                                                                                                          Entropy (8bit):4.120890519790248
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83okzalCcPdJ5rK8yzMY4JlV1ZDqqIkFo8w:43JkPj9K8y4HHZLIQtw
                                                                                                                                                                                                                                                          MD5:A3D098C1A47E380F7C25233A52FBDE38
                                                                                                                                                                                                                                                          SHA1:C97E4EAA9E7A7F99950F422B93C57134B532C639
                                                                                                                                                                                                                                                          SHA-256:34D61B49DBF9584893051FFB458D6DE9E7E2E7774AC0011F70C4DD4184EBA81C
                                                                                                                                                                                                                                                          SHA-512:4687AB3D2FAA65FED90678EBC08C074959E93A9FEFAF3D61EEE39DB08FD200CB57C0DDB4DDBF6451FE1EF5E07EA976EDEF830769FF403CE51734129CEF24DA9F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset gl DAYS_OF_WEEK_ABBREV [list \.. "Dom"\.. "Lun"\.. "Mar"\.. "M\u00e9r"\.. "Xov"\.. "Ven"\.. "S\u00e1b"].. ::msgcat::mcset gl DAYS_OF_WEEK_FULL [list \.. "Domingo"\.. "Luns"\.. "Martes"\.. "M\u00e9rcores"\.. "Xoves"\.. "Venres"\.. "S\u00e1bado"].. ::msgcat::mcset gl MONTHS_ABBREV [list \.. "Xan"\.. "Feb"\.. "Mar"\.. "Abr"\.. "Mai"\.. "Xu\u00f1"\.. "Xul"\.. "Ago"\.. "Set"\.. "Out"\.. "Nov"\.. "Dec"\.. ""].. ::msgcat::mcset gl MONTHS_FULL [list \.. "Xaneiro"\.. "Febreiro"\.. "Marzo"\.. "Abril"\.. "Maio"\.. "Xu\u00f1o"\.. "Xullo"\.. "Agosto"\.. "Setembro"\.. "Outubro"\.. "Novembro"\.. "Decembro"\.. ""]..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.886176304042503
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoPhkgMoPxsF3v6ay/5oPhk9+3vR6HyFvn:4EnLB383WrfK3v6ay/WJ3voSVn
                                                                                                                                                                                                                                                          MD5:78B9163C5E8E5E7049CBF91D1A5889A4
                                                                                                                                                                                                                                                          SHA1:F2F07AF3D79D61C8E0C73B13E2CA8266E10E396B
                                                                                                                                                                                                                                                          SHA-256:B5688CA07D713227B713655877710258CD503617E8DF79293A971649E3134F05
                                                                                                                                                                                                                                                          SHA-512:E86074B687670542CFA097C94D150292E1A73C9F231E92CD84386580A446569CC6F8F5817F46ED64A1D00F95D59F6F1F5D4B961DF3C8335938D83F3517794353
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset gl_ES DATE_FORMAT "%d %B %Y".. ::msgcat::mcset gl_ES TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset gl_ES DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1084
                                                                                                                                                                                                                                                          Entropy (8bit):4.213672208102291
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR832vTXAC2/fS5JfaCroeLaCAQbSm5qJe1:43QTXs32zrf
                                                                                                                                                                                                                                                          MD5:518FC3964D50854081FB79189A42D3E7
                                                                                                                                                                                                                                                          SHA1:59392F16CD56E3E6A685F78974D539FB3A972B98
                                                                                                                                                                                                                                                          SHA-256:404795F2C88D0038F9ED0B5120A251D26EDF8B236E1B1698BC71ACD4DC75AC45
                                                                                                                                                                                                                                                          SHA-512:E5C88CAB8741D631938CEC2E0959C0FE26685C395F5F9F4F1B5C9E146E84D23D897CD7A823AB46D4B62C590AE15EC76B87EB59308ACFB1BB6F61398890B43622
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset gv DAYS_OF_WEEK_ABBREV [list \.. "Jed"\.. "Jel"\.. "Jem"\.. "Jerc"\.. "Jerd"\.. "Jeh"\.. "Jes"].. ::msgcat::mcset gv DAYS_OF_WEEK_FULL [list \.. "Jedoonee"\.. "Jelhein"\.. "Jemayrt"\.. "Jercean"\.. "Jerdein"\.. "Jeheiney"\.. "Jesarn"].. ::msgcat::mcset gv MONTHS_ABBREV [list \.. "J-guer"\.. "T-arree"\.. "Mayrnt"\.. "Avrril"\.. "Boaldyn"\.. "M-souree"\.. "J-souree"\.. "Luanistyn"\.. "M-fouyir"\.. "J-fouyir"\.. "M.Houney"\.. "M.Nollick"\.. ""].. ::msgcat::mcset gv MONTHS_FULL [list \.. "Jerrey-geuree"\.. "Toshiaght-arree"\.. "Mayrnt"\.. "Averil"\.. "Boaldyn"\.. "Mean-souree"\.. "Jerrey-souree"\.. "Luanistyn"\.. "Mean-fouyir"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.936566750568767
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoQbtvMoQLE3v6ay/5oQbto+3vR6HyFvn:4EnLB383PbtvALE3v6ay/PbtF3voSVn
                                                                                                                                                                                                                                                          MD5:0B6BE614EF5F5F25A30D2D33701A9F94
                                                                                                                                                                                                                                                          SHA1:65800FBD73D9DAE550E04E1D818A6B9D1AEF86FE
                                                                                                                                                                                                                                                          SHA-256:86CABF3B9360C0E686CC4CBEB843E971C28BC6D35210ED378B54EB58CC41F3D5
                                                                                                                                                                                                                                                          SHA-512:376D21B38DA49A8F7C2983F2B808FD55AC9F6383BC66DF28DB99DBF61FDC9FFF8CD20F077EC3ED873EF47F0F613BDD9AD02DFFB1CB51F9A36715C7FC798C3B70
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset gv_GB DATE_FORMAT "%d %B %Y".. ::msgcat::mcset gv_GB TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset gv_GB DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1990
                                                                                                                                                                                                                                                          Entropy (8bit):4.298934047406144
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83Y71LCLxL0eCLbCLKCLaCLXL7CLB0p1dLGCoCLU5LT5Gv5LJ9p5LnLEHLGCh:43sl7KqpU/nNbhbOezd2ICn
                                                                                                                                                                                                                                                          MD5:A0E60036EB17208A449AAFC3AAAE622C
                                                                                                                                                                                                                                                          SHA1:9D7479BA85FBB00A2DF2B61F4ED2CBEA8F1EC8C3
                                                                                                                                                                                                                                                          SHA-256:787DA79AF58872BF45AB09E3B6A920A4496B5BD8A4F3C7F010CF013EC2E8EFE0
                                                                                                                                                                                                                                                          SHA-512:46D12C14B5736E5EA97EB728BF58999E9D7C2CF910D8F5AFA3F5D3A86329ABF41A3E2BEBD81EE4EF64BEA0DC173B77A9FE12471C1BD9D768ED552A55B3B80213
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset he DAYS_OF_WEEK_ABBREV [list \.. "\u05d0"\.. "\u05d1"\.. "\u05d2"\.. "\u05d3"\.. "\u05d4"\.. "\u05d5"\.. "\u05e9"].. ::msgcat::mcset he DAYS_OF_WEEK_FULL [list \.. "\u05d9\u05d5\u05dd \u05e8\u05d0\u05e9\u05d5\u05df"\.. "\u05d9\u05d5\u05dd \u05e9\u05e0\u05d9"\.. "\u05d9\u05d5\u05dd \u05e9\u05dc\u05d9\u05e9\u05d9"\.. "\u05d9\u05d5\u05dd \u05e8\u05d1\u05d9\u05e2\u05d9"\.. "\u05d9\u05d5\u05dd \u05d7\u05de\u05d9\u05e9\u05d9"\.. "\u05d9\u05d5\u05dd \u05e9\u05d9\u05e9\u05d9"\.. "\u05e9\u05d1\u05ea"].. ::msgcat::mcset he MONTHS_ABBREV [list \.. "\u05d9\u05e0\u05d5"\.. "\u05e4\u05d1\u05e8"\.. "\u05de\u05e8\u05e5"\.. "\u05d0\u05e4\u05e8"\.. "\u05de\u05d0\u05d9"\.. "\u05d9\u05d5\u05e0"\.. "\u05d9\u05d5\u05dc"\.. "\u05d0\u05d5\u05d2"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1777
                                                                                                                                                                                                                                                          Entropy (8bit):4.2117128941697715
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:438n4kALqrU1fbokQTbWqrU1fbokQTw38:28OD86D8gM
                                                                                                                                                                                                                                                          MD5:4219A929E27308ADC04A9F368F063F38
                                                                                                                                                                                                                                                          SHA1:FA728EEBA8751F4CE032ED32AECFDE124D1B68E2
                                                                                                                                                                                                                                                          SHA-256:192F4A8E77E1627712F85533C9896EF6A040157C7BD56DF3A4A7FA56AD6746C2
                                                                                                                                                                                                                                                          SHA-512:223B137AC1FC15908F5541067736EF3A29493549B963393EB78660036A82982E57CFC4AD09CBD33D32A5187FF9F4ACFB5F83A0C974702434B7FAD1B2539B7F76
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset hi DAYS_OF_WEEK_FULL [list \.. "\u0930\u0935\u093f\u0935\u093e\u0930"\.. "\u0938\u094b\u092e\u0935\u093e\u0930"\.. "\u092e\u0902\u0917\u0932\u0935\u093e\u0930"\.. "\u092c\u0941\u0927\u0935\u093e\u0930"\.. "\u0917\u0941\u0930\u0941\u0935\u093e\u0930"\.. "\u0936\u0941\u0915\u094d\u0930\u0935\u093e\u0930"\.. "\u0936\u0928\u093f\u0935\u093e\u0930"].. ::msgcat::mcset hi MONTHS_ABBREV [list \.. "\u091c\u0928\u0935\u0930\u0940"\.. "\u092b\u093c\u0930\u0935\u0930\u0940"\.. "\u092e\u093e\u0930\u094d\u091a"\.. "\u0905\u092a\u094d\u0930\u0947\u0932"\.. "\u092e\u0908"\.. "\u091c\u0942\u0928"\.. "\u091c\u0941\u0932\u093e\u0908"\.. "\u0905\u0917\u0938\u094d\u0924"\.. "\u0938\u093f\u0924\u092e\u094d\u092c\u0930"\.. "\u0905\u0915\u094d\u091f\u0942\u092c\u0930"\.. "\u0928\u0935\u
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.9286948144352865
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xocv+IZoz3v6ry/5oco+3v+6f6HyFvn:4EnLB383Jvlg3v6ry/JF3vmSVn
                                                                                                                                                                                                                                                          MD5:1C1E1484EA0286175FADCB90937C9F34
                                                                                                                                                                                                                                                          SHA1:5CA1BF19021D529CB3B3A308EFFFCA7E4D073640
                                                                                                                                                                                                                                                          SHA-256:5A3BF0DD61BFB5A2BF75E96B11E0E3528FFAB720A0BF1923853606F8CAF0E76D
                                                                                                                                                                                                                                                          SHA-512:F9A43E1E18ADB6DC6B18BEDC3303A99F514DF6CA54F12100989F734233012D7D60216116915351CCACC12F6942795BF8F3BBD26B15A86E88101067D64BEE54F5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset hi_IN DATE_FORMAT "%d %M %Y".. ::msgcat::mcset hi_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset hi_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1171
                                                                                                                                                                                                                                                          Entropy (8bit):4.36311224714184
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83dVX79VIE9bLTWnh7rT+5dPcdvgrNv5KvOA1:43kmrQ7n+odIrJ6OS
                                                                                                                                                                                                                                                          MD5:906963A3AD09EAC781B35C190B77484E
                                                                                                                                                                                                                                                          SHA1:E5AA49DA9C4987EAFA839115F84612426EB8615E
                                                                                                                                                                                                                                                          SHA-256:105A9180BC5D23738183374FA0EA8DD80484BF3947E1432E515BDC2913C017D9
                                                                                                                                                                                                                                                          SHA-512:557BD1C8306750D09215D9774069A52C7D60E03DE2DF39FF909A8F658AB0565739D127E24ACDC96F736C69A71BEFA30B8A30BB489C7B7FDEA85386C802166349
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset hr DAYS_OF_WEEK_ABBREV [list \.. "ned"\.. "pon"\.. "uto"\.. "sri"\.. "\u010det"\.. "pet"\.. "sub"].. ::msgcat::mcset hr DAYS_OF_WEEK_FULL [list \.. "nedjelja"\.. "ponedjeljak"\.. "utorak"\.. "srijeda"\.. "\u010detvrtak"\.. "petak"\.. "subota"].. ::msgcat::mcset hr MONTHS_ABBREV [list \.. "sij"\.. "vel"\.. "o\u017eu"\.. "tra"\.. "svi"\.. "lip"\.. "srp"\.. "kol"\.. "ruj"\.. "lis"\.. "stu"\.. "pro"\.. ""].. ::msgcat::mcset hr MONTHS_FULL [list \.. "sije\u010danj"\.. "velja\u010da"\.. "o\u017eujak"\.. "travanj"\.. "svibanj"\.. "lipanj"\.. "srpanj"\.. "kolovoz"\.. "rujan"\.. "listopad"\.. "studeni"\.. "prosinac"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1381
                                                                                                                                                                                                                                                          Entropy (8bit):4.511450677731002
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83IFb7ZTmKrkAYm2LZyyApLDV2uZi5WF+shHUTyvtsv+:43C3ZTmKQAyZyyAp0BotK+
                                                                                                                                                                                                                                                          MD5:E398158EE1CD49CB5286D9642D4A61DD
                                                                                                                                                                                                                                                          SHA1:A93A588B0ADD198C067C4BB070DC1E5170E6E208
                                                                                                                                                                                                                                                          SHA-256:993475532F89E1EA7214ADB265294040862305612D680CFF01DD20615B731CCC
                                                                                                                                                                                                                                                          SHA-512:9E5791FB97110FE5F7A1F49FF2ED8801A05E49D5B9AF579474C0081073D2B40ECFFE6E4EB5B61F12B1995FDCC0A557CB572E5E116F951FD286A6254253DAEC01
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset hu DAYS_OF_WEEK_ABBREV [list \.. "V"\.. "H"\.. "K"\.. "Sze"\.. "Cs"\.. "P"\.. "Szo"].. ::msgcat::mcset hu DAYS_OF_WEEK_FULL [list \.. "vas\u00e1rnap"\.. "h\u00e9tf\u0151"\.. "kedd"\.. "szerda"\.. "cs\u00fct\u00f6rt\u00f6k"\.. "p\u00e9ntek"\.. "szombat"].. ::msgcat::mcset hu MONTHS_ABBREV [list \.. "jan."\.. "febr."\.. "m\u00e1rc."\.. "\u00e1pr."\.. "m\u00e1j."\.. "j\u00fan."\.. "j\u00fal."\.. "aug."\.. "szept."\.. "okt."\.. "nov."\.. "dec."\.. ""].. ::msgcat::mcset hu MONTHS_FULL [list \.. "janu\u00e1r"\.. "febru\u00e1r"\.. "m\u00e1rcius"\.. "\u00e1prilis"\.. "m\u00e1jus"\.. "j\u00fanius"\.. "j\u00falius"\.. "augusztus"\.. "szeptembe
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):961
                                                                                                                                                                                                                                                          Entropy (8bit):4.02166638427728
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83dcTcWKutdXaMmEfc2ftdT2dHblWZ0VT:43dQrKutdntdI8g
                                                                                                                                                                                                                                                          MD5:191ACF2E8A8F10A1360B283D42886382
                                                                                                                                                                                                                                                          SHA1:EE2C00D021381EA638B6CE3F395DEA5F8491ED9B
                                                                                                                                                                                                                                                          SHA-256:41C0C3D3B4491E9B36E719466503EFCD325175CB7824C4A5055CB113D347BE0F
                                                                                                                                                                                                                                                          SHA-512:29BC4F7D3FAE7DE392B175FEA76138FA823B7D9D0B051A19A73F7D36D51DE34E0D0C7C129867307ABF51FC92E70853C15BD96B8484AD21EAB0A8EB83B0411E03
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset id DAYS_OF_WEEK_ABBREV [list \.. "Min"\.. "Sen"\.. "Sel"\.. "Rab"\.. "Kam"\.. "Jum"\.. "Sab"].. ::msgcat::mcset id DAYS_OF_WEEK_FULL [list \.. "Minggu"\.. "Senin"\.. "Selasa"\.. "Rabu"\.. "Kamis"\.. "Jumat"\.. "Sabtu"].. ::msgcat::mcset id MONTHS_ABBREV [list \.. "Jan"\.. "Peb"\.. "Mar"\.. "Apr"\.. "Mei"\.. "Jun"\.. "Jul"\.. "Agu"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Des"\.. ""].. ::msgcat::mcset id MONTHS_FULL [list \.. "Januari"\.. "Pebruari"\.. "Maret"\.. "April"\.. "Mei"\.. "Juni"\.. "Juli"\.. "Agustus"\.. "September"\.. "Oktober"\.. "November"\.. "Desember"\.. ""]..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.904408530699153
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xo0kGMo0F/W3v6ay/5o0kT+3vR6HyFvn:4EnLB383wG33v6ay/wK3voSVn
                                                                                                                                                                                                                                                          MD5:FEB4D50576BF3E11A0A40FD29ABE35A7
                                                                                                                                                                                                                                                          SHA1:8CEAA187C8AA5EC101743060A877D039850964CA
                                                                                                                                                                                                                                                          SHA-256:BA7FC0C0452D3E482DB6E19BDF512CACED639BA72B92ED8F66D80B52FEA11AC0
                                                                                                                                                                                                                                                          SHA-512:8B5D18E3D6628F369FB387C8EF08CC80000E0CBE500972958F4AD75F1C2F0DD6058F9777BD7DD0D7C26E7ECAA65E5071E2BF51B560973E88637942116C7576FB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset id_ID DATE_FORMAT "%d %B %Y".. ::msgcat::mcset id_ID TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset id_ID DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1305
                                                                                                                                                                                                                                                          Entropy (8bit):4.457417703528286
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83XVhVTeMVHGPbfXSmWzaZlfFxUQbW1U6ZY95n123etvmv3eTn:43Xz0b/uzaZtXUMw8n
                                                                                                                                                                                                                                                          MD5:ACF0452D5BB6D36A40061D2B0AF4D7A6
                                                                                                                                                                                                                                                          SHA1:9DF4D88F1962A672EFBDDE524550F7A5D02D446D
                                                                                                                                                                                                                                                          SHA-256:778BE3D6BFE2DFFB64FF1AFB9EC8351A3343B314CF93A68E8F7FD1073EE122BB
                                                                                                                                                                                                                                                          SHA-512:34CC02D7D28B5E161ED10250C214375561FD3D00979BFB8BCF3DB72A81BD9B7C225301528B400F7C54D8B6379F772EB6477D5D03F2CF7DC4DD19D22AEEC151B5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset is DAYS_OF_WEEK_ABBREV [list \.. "sun."\.. "m\u00e1n."\.. "\u00feri."\.. "mi\u00f0."\.. "fim."\.. "f\u00f6s."\.. "lau."].. ::msgcat::mcset is DAYS_OF_WEEK_FULL [list \.. "sunnudagur"\.. "m\u00e1nudagur"\.. "\u00feri\u00f0judagur"\.. "mi\u00f0vikudagur"\.. "fimmtudagur"\.. "f\u00f6studagur"\.. "laugardagur"].. ::msgcat::mcset is MONTHS_ABBREV [list \.. "jan."\.. "feb."\.. "mar."\.. "apr."\.. "ma\u00ed"\.. "j\u00fan."\.. "j\u00fal."\.. "\u00e1g\u00fa."\.. "sep."\.. "okt."\.. "n\u00f3v."\.. "des."\.. ""].. ::msgcat::mcset is MONTHS_FULL [list \.. "jan\u00faar"\.. "febr\u00faar"\.. "mars"\.. "apr\u00edl"\.. "ma\u00ed"\.. "j\u00fan\u00ed"\.. "j\u00fal\
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1294
                                                                                                                                                                                                                                                          Entropy (8bit):4.282101355195382
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83JYEVI2vfYpQjAOnhWBIIsmdC2lkOKk+Z+FoPJ6G3vesvY:43JZVB8eAOnh4IzR2+J6G/eKY
                                                                                                                                                                                                                                                          MD5:3354A6FC06C298E33AA14163929E56EB
                                                                                                                                                                                                                                                          SHA1:C3005370DAE8A266AE21F7E2B871AEA5A656A155
                                                                                                                                                                                                                                                          SHA-256:1D72170B9F9028A237364F7CD7EA8B48BD4770E61922205CE862300103B13DE5
                                                                                                                                                                                                                                                          SHA-512:58B64D4F5827CA2A1BF2DDFD1F7EFDDBBD46709A6A9B7277E8EB386D80043A87ADDE2B3D5A49A934E8EB8F797BD735FADA1D22AD3DD856FFE9507F71B9E45CBA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset it DAYS_OF_WEEK_ABBREV [list \.. "dom"\.. "lun"\.. "mar"\.. "mer"\.. "gio"\.. "ven"\.. "sab"].. ::msgcat::mcset it DAYS_OF_WEEK_FULL [list \.. "domenica"\.. "luned\u00ec"\.. "marted\u00ec"\.. "mercoled\u00ec"\.. "gioved\u00ec"\.. "venerd\u00ec"\.. "sabato"].. ::msgcat::mcset it MONTHS_ABBREV [list \.. "gen"\.. "feb"\.. "mar"\.. "apr"\.. "mag"\.. "giu"\.. "lug"\.. "ago"\.. "set"\.. "ott"\.. "nov"\.. "dic"\.. ""].. ::msgcat::mcset it MONTHS_FULL [list \.. "gennaio"\.. "febbraio"\.. "marzo"\.. "aprile"\.. "maggio"\.. "giugno"\.. "luglio"\.. "agosto"\.. "settembre"\.. "ottobre"\.. "novembre"\.. "dicembre"\.. "
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):250
                                                                                                                                                                                                                                                          Entropy (8bit):4.8982877714191035
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoi5jL/oyJ+3v1oia+3vjLtAsvn:4EnLB383b3F+3vV3v3tnn
                                                                                                                                                                                                                                                          MD5:E4400C16406A46C2880250522BED2EDE
                                                                                                                                                                                                                                                          SHA1:787A04037A355FF845025B8865335EB938280BFB
                                                                                                                                                                                                                                                          SHA-256:24B5F303F5C7AF6F63FDC23ADB4D713087AE74B6D18C117D787AF03374C5F57E
                                                                                                                                                                                                                                                          SHA-512:3551DEEF0EAAC66042143F77F2F4DD9154764F35BD624DAB3C9F0F59F3489CA39CE34BC2A69BC5BFBB1926C6F5C39D74A806ECB1A47F6B374101071957FD417B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset it_CH DATE_FORMAT "%e. %B %Y".. ::msgcat::mcset it_CH TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset it_CH DATE_TIME_FORMAT "%e. %B %Y %H:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1689
                                                                                                                                                                                                                                                          Entropy (8bit):4.951012555106795
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83Gl84OCtnbf3wvtMwvLv4GTwhvevTwSoXghGhD6h:43FULWttbdEVoES8gshD6h
                                                                                                                                                                                                                                                          MD5:11FBE427747012444AEEAFD6134034A4
                                                                                                                                                                                                                                                          SHA1:58C72C432053264EAE6335D6CC93C5FFA33C42B8
                                                                                                                                                                                                                                                          SHA-256:2B6D15A191437F1B84FA7023E34153B61E6BF1DE1452EA921E9CCBBE5D4BEB1C
                                                                                                                                                                                                                                                          SHA-512:4F993BDF5D50D6D9F7410C83D226FEF30BA8C989F9977A7025C36BE22CEECCD6C68CDD6AFC5C9CE3D700559C4EDC619042E14DD88EE7583B9D5AA66F0268FD23
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ja DAYS_OF_WEEK_ABBREV [list \.. "\u65e5"\.. "\u6708"\.. "\u706b"\.. "\u6c34"\.. "\u6728"\.. "\u91d1"\.. "\u571f"].. ::msgcat::mcset ja DAYS_OF_WEEK_FULL [list \.. "\u65e5\u66dc\u65e5"\.. "\u6708\u66dc\u65e5"\.. "\u706b\u66dc\u65e5"\.. "\u6c34\u66dc\u65e5"\.. "\u6728\u66dc\u65e5"\.. "\u91d1\u66dc\u65e5"\.. "\u571f\u66dc\u65e5"].. ::msgcat::mcset ja MONTHS_FULL [list \.. "1\u6708"\.. "2\u6708"\.. "3\u6708"\.. "4\u6708"\.. "5\u6708"\.. "6\u6708"\.. "7\u6708"\.. "8\u6708"\.. "9\u6708"\.. "10\u6708"\.. "11\u6708"\.. "12\u6708"].. ::msgcat::mcset ja BCE "\u7d00\u5143\u524d".. ::msgcat::mcset ja CE "\u897f\u66a6".. ::msgcat::mcset ja AM "\u5348\u524d".. ::msgcat::mcset ja PM "\u5348\u5f8c".. ::ms
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1025
                                                                                                                                                                                                                                                          Entropy (8bit):4.097746630492712
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83E7XIE/OWbjH3Tw2PzJrIsmZ5maAXaMHPB:43WlrraA/vB
                                                                                                                                                                                                                                                          MD5:2F79804667D6F8C77BB188D59EF5F3DF
                                                                                                                                                                                                                                                          SHA1:10950ECA798F24A7C405B3E18B559CCC0C056EC1
                                                                                                                                                                                                                                                          SHA-256:96FF17F1CFF976E4E204D3616D1EFCED4D0F907C5E6A0F04B4536CB4AD1190C9
                                                                                                                                                                                                                                                          SHA-512:1B8ADC3B7FF920F8F53A17BFCC7EA24A0F8E276A42E5C63F9880DAE9B74E12716DD12DB647A80A9D99294449146C643EC58A33B03681AA4FA26A5FBC508C248C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kl DAYS_OF_WEEK_ABBREV [list \.. "sab"\.. "ata"\.. "mar"\.. "pin"\.. "sis"\.. "tal"\.. "arf"].. ::msgcat::mcset kl DAYS_OF_WEEK_FULL [list \.. "sabaat"\.. "ataasinngorneq"\.. "marlunngorneq"\.. "pingasunngorneq"\.. "sisamanngorneq"\.. "tallimanngorneq"\.. "arfininngorneq"].. ::msgcat::mcset kl MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset kl MONTHS_FULL [list \.. "januari"\.. "februari"\.. "martsi"\.. "aprili"\.. "maji"\.. "juni"\.. "juli"\.. "augustusi"\.. "septemberi"\.. "oktoberi"\.. "novemberi"\.. "dece
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):286
                                                                                                                                                                                                                                                          Entropy (8bit):4.882476709336307
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoEpb53FuoEpLE3vLjoEpLE3v6mjoEpba+3vnFDoAkvn:4EnLB383jF3Fyw3vxw3v6A/3v9dmn
                                                                                                                                                                                                                                                          MD5:255830678C8724E65C05A7E020E68B5B
                                                                                                                                                                                                                                                          SHA1:0AEA48AB0439C04F92B5CA9A3B5182718B7F116B
                                                                                                                                                                                                                                                          SHA-256:3027CFE9EBD2172CEFC15C025786CAD47A6E2894BF0474AFC1B0C341E70202AA
                                                                                                                                                                                                                                                          SHA-512:99039FFA7269DD136D1693121E261DB5586E86EC401D2B1EB8FB1D13A9A7F1E514D9FC941B838286B986C02ED281828ED67E59002D837E350A64F4832340516A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kl_GL DATE_FORMAT "%d %b %Y".. ::msgcat::mcset kl_GL TIME_FORMAT "%T".. ::msgcat::mcset kl_GL TIME_FORMAT_12 "%T".. ::msgcat::mcset kl_GL DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1621
                                                                                                                                                                                                                                                          Entropy (8bit):4.612163420716489
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:43fMlylslXlslxl1hVuqLGuqqntH4xUyw9:2fKYqVq3f
                                                                                                                                                                                                                                                          MD5:CCB2C2254D3FA3025183DB7E010CAD66
                                                                                                                                                                                                                                                          SHA1:510BBB6A9162F2EF908E6561CC714848C2EA74CA
                                                                                                                                                                                                                                                          SHA-256:EF6FB319C398EEA79B3A951319F831F3B186D556565D17D738E5F9B4B77570F2
                                                                                                                                                                                                                                                          SHA-512:A0264565899BD1B0783ADC0388F893CCE713ADB23BDD63907CF092A74ACB4F7D3BE09DA29801E9C11A7B08CB1706E3771C598ACED351A0FCCBF4EBBD7871148D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ko DAYS_OF_WEEK_ABBREV [list \.. "\uc77c"\.. "\uc6d4"\.. "\ud654"\.. "\uc218"\.. "\ubaa9"\.. "\uae08"\.. "\ud1a0"].. ::msgcat::mcset ko DAYS_OF_WEEK_FULL [list \.. "\uc77c\uc694\uc77c"\.. "\uc6d4\uc694\uc77c"\.. "\ud654\uc694\uc77c"\.. "\uc218\uc694\uc77c"\.. "\ubaa9\uc694\uc77c"\.. "\uae08\uc694\uc77c"\.. "\ud1a0\uc694\uc77c"].. ::msgcat::mcset ko MONTHS_ABBREV [list \.. "1\uc6d4"\.. "2\uc6d4"\.. "3\uc6d4"\.. "4\uc6d4"\.. "5\uc6d4"\.. "6\uc6d4"\.. "7\uc6d4"\.. "8\uc6d4"\.. "9\uc6d4"\.. "10\uc6d4"\.. "11\uc6d4"\.. "12\uc6d4"\.. ""].. ::msgcat::mcset ko MONTHS_FULL [list \.. "1\uc6d4"\.. "2\uc6d4"\.. "3\uc6d4"\.. "4\uc6d4"\.. "5\uc6d4"\.. "6\uc6d4"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):354
                                                                                                                                                                                                                                                          Entropy (8bit):5.058233326545794
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xo56SFZhjAo56m5Ys5o56TGMovBo56a/W3v6mfKo56TT+3+:4EnLB383g62vjV6m5Ysg6TG26a+3v6oo
                                                                                                                                                                                                                                                          MD5:58CA45CE26AF8ECA729BA72898BB633D
                                                                                                                                                                                                                                                          SHA1:CBBEDB7370890A1DB65080A359A9A5C164B525D5
                                                                                                                                                                                                                                                          SHA-256:4CAC8FB43D290A63A4D3215F22228B358AB4FA174F08712DD6C5B64C5E485071
                                                                                                                                                                                                                                                          SHA-512:48CCBD3F7B96D0998B6D1A1F8D7FE2B4B070BB5B8809FABE0A38209AEAF2E95E098292A5B9B5F0954E7729708A2173D32AAD70B6C0F336DB1E9BFA2968E6A56B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ko_KR BCE "\uae30\uc6d0\uc804".. ::msgcat::mcset ko_KR CE "\uc11c\uae30".. ::msgcat::mcset ko_KR DATE_FORMAT "%Y.%m.%d".. ::msgcat::mcset ko_KR TIME_FORMAT_12 "%P %l:%M:%S".. ::msgcat::mcset ko_KR DATE_TIME_FORMAT "%Y.%m.%d %P %l:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1997
                                                                                                                                                                                                                                                          Entropy (8bit):4.202940482570495
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83cm48Vc7VczMmDNVcYVcR0prdSmS68FeDJVcYVcR0prdSmS68FeuT:4354a+0prjS68mq0prjS68pT
                                                                                                                                                                                                                                                          MD5:67FA08F588A3B44D67E42EC1025013BC
                                                                                                                                                                                                                                                          SHA1:6895FEF0476DE0349895DB052B335AC46636B23A
                                                                                                                                                                                                                                                          SHA-256:9D215E31A39FED45B3657144E5F73C942E59E500036CE16B1FFF201FD6358595
                                                                                                                                                                                                                                                          SHA-512:4C2708BD9DD98320D3133EEFFD19A8018F49A36AB8348DB7C0B0287ADB4C052D3EFAD3686C8E46E0520F3CE27F361978272BA8752EB04E5A7BC07780398480DB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kok DAYS_OF_WEEK_FULL [list \.. "\u0906\u0926\u093f\u0924\u094d\u092f\u0935\u093e\u0930"\.. "\u0938\u094b\u092e\u0935\u093e\u0930"\.. "\u092e\u0902\u0917\u0933\u093e\u0930"\.. "\u092c\u0941\u0927\u0935\u093e\u0930"\.. "\u0917\u0941\u0930\u0941\u0935\u093e\u0930"\.. "\u0936\u0941\u0915\u094d\u0930\u0935\u093e\u0930"\.. "\u0936\u0928\u093f\u0935\u093e\u0930"].. ::msgcat::mcset kok MONTHS_ABBREV [list \.. "\u091c\u093e\u0928\u0947\u0935\u093e\u0930\u0940"\.. "\u092b\u0947\u092c\u0943\u0935\u093e\u0930\u0940"\.. "\u092e\u093e\u0930\u094d\u091a"\.. "\u090f\u092a\u094d\u0930\u093f\u0932"\.. "\u092e\u0947"\.. "\u091c\u0942\u0928"\.. "\u091c\u0941\u0932\u0948"\.. "\u0913\u0917\u0938\u094d\u091f"\.. "\u0938\u0947\u092a\u094d\u091f\u0947\u0902\u092c\u0930"\.. "\u0913\u0915\u094d\
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):260
                                                                                                                                                                                                                                                          Entropy (8bit):4.904340548436718
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xo5VsNv+IZo5VsU3v6ry/5o5VsNo+3v+6f6HyFvn:4EnLB383gVsNvlAVsU3v6ry/gVsNF3vj
                                                                                                                                                                                                                                                          MD5:0AA20289A63BA3A14DCFED75EED980DE
                                                                                                                                                                                                                                                          SHA1:2B76013593D886B0724D82849FD1840B20922902
                                                                                                                                                                                                                                                          SHA-256:644F2B6D4BA27AF14891B781DEF60F708A9F18FC2F73566649B631A6DEA3EF09
                                                                                                                                                                                                                                                          SHA-512:6E13E0DC8BFD2ABE0D04B0BC098C40972F088F8D3D6ACA00338B17473ABC6F69840A88EC0C965C493B4270DEC777A0EA2D762BC33044EFE7030E437604EE201B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kok_IN DATE_FORMAT "%d %M %Y".. ::msgcat::mcset kok_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset kok_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1013
                                                                                                                                                                                                                                                          Entropy (8bit):4.060027087416375
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83no1UwRlw4MAwBdc//3rpF6HFoot8:43vglHM7MTCHFs
                                                                                                                                                                                                                                                          MD5:CCEC7B77DCA1F6A406311FC43EE57030
                                                                                                                                                                                                                                                          SHA1:4ED329BB09A8F7C67F8984CD790E9B6819DE6F00
                                                                                                                                                                                                                                                          SHA-256:EAB468AC5BF1833D4F8CD658789413D4A46CAD16B63FB9B906CFF6DC9EA26251
                                                                                                                                                                                                                                                          SHA-512:4EFF6E49CC479A1BF0CEEAE256A1FAE7D4AE7D0ACE23CD87851471EC96BB5AF580C58A142E1B6CE72BC8B6BFF946A38801E681443B7DD9527A1DEB6E7EDD7D22
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kw DAYS_OF_WEEK_ABBREV [list \.. "Sul"\.. "Lun"\.. "Mth"\.. "Mhr"\.. "Yow"\.. "Gwe"\.. "Sad"].. ::msgcat::mcset kw DAYS_OF_WEEK_FULL [list \.. "De Sul"\.. "De Lun"\.. "De Merth"\.. "De Merher"\.. "De Yow"\.. "De Gwener"\.. "De Sadorn"].. ::msgcat::mcset kw MONTHS_ABBREV [list \.. "Gen"\.. "Whe"\.. "Mer"\.. "Ebr"\.. "Me"\.. "Evn"\.. "Gor"\.. "Est"\.. "Gwn"\.. "Hed"\.. "Du"\.. "Kev"\.. ""].. ::msgcat::mcset kw MONTHS_FULL [list \.. "Mys Genver"\.. "Mys Whevrel"\.. "Mys Merth"\.. "Mys Ebrel"\.. "Mys Me"\.. "Mys Evan"\.. "Mys Gortheren"\.. "Mye Est"\.. "Mys Gwyngala"\.. "Mys Hedra"\.. "Mys Du"\.. "Mys Kevardhu"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.959913054070712
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoh6AvMoh633v6ay/5oh6Ao+3vR6HyFvn:4EnLB38346AvR633v6ay/46AF3voSVn
                                                                                                                                                                                                                                                          MD5:18E8576F63B978F1AFEF15AC57B44FBF
                                                                                                                                                                                                                                                          SHA1:D50EB90944FF81E3CBFF942B16C1874EB7EA2562
                                                                                                                                                                                                                                                          SHA-256:EDAC14D929D1C6559EC46E9B460F8F44A189B78FB915F2D641104549CBD94188
                                                                                                                                                                                                                                                          SHA-512:F3DE5EE77BB889DA1353F9C9A1811083AB28BBEE4B7D6C8782F38B1AE44CF77565371A0E18F7E2BACD7EF590BC1215CA3E41AF929A15F60B3E85F6099A4CF378
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset kw_GB DATE_FORMAT "%d %B %Y".. ::msgcat::mcset kw_GB TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset kw_GB DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1307
                                                                                                                                                                                                                                                          Entropy (8bit):4.506235846178408
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83iHYuAMLzHYCaNu3d3nT15T31FhAlDgK/YrDZ/6Qz2C9kGPCveksvc:43iHFnHuUd3/T3xM/+SQCC9kGPEekKc
                                                                                                                                                                                                                                                          MD5:D4EC2E96995E0EB263F338DD16CC4F8D
                                                                                                                                                                                                                                                          SHA1:7ED86175489B1AE3CA5C0E8D42969F951C895D6B
                                                                                                                                                                                                                                                          SHA-256:855B652FCC8066BA45C7DC8DBFD3807D1B4759EA8D71C523567F47BF445D1DE6
                                                                                                                                                                                                                                                          SHA-512:A55E0D759A22360FF6668CEFAFFB812BABB316C447ADDB1FD5CDBC06AE1DA2E891E09952D073164C013AD9BF4184614102E7ADA553EEEFB2BBA26208B79B277F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset lt DAYS_OF_WEEK_ABBREV [list \.. "Sk"\.. "Pr"\.. "An"\.. "Tr"\.. "Kt"\.. "Pn"\.. "\u0160t"].. ::msgcat::mcset lt DAYS_OF_WEEK_FULL [list \.. "Sekmadienis"\.. "Pirmadienis"\.. "Antradienis"\.. "Tre\u010diadienis"\.. "Ketvirtadienis"\.. "Penktadienis"\.. "\u0160e\u0161tadienis"].. ::msgcat::mcset lt MONTHS_ABBREV [list \.. "Sau"\.. "Vas"\.. "Kov"\.. "Bal"\.. "Geg"\.. "Bir"\.. "Lie"\.. "Rgp"\.. "Rgs"\.. "Spa"\.. "Lap"\.. "Grd"\.. ""].. ::msgcat::mcset lt MONTHS_FULL [list \.. "Sausio"\.. "Vasario"\.. "Kovo"\.. "Baland\u017eio"\.. "Gegu\u017e\u0117s"\.. "Bir\u017eelio"\.. "Liepos"\.. "Rugpj\u016b\u010dio"\.. "Rugs\u0117jo"\.. "Spa
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1271
                                                                                                                                                                                                                                                          Entropy (8bit):4.460631492946299
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83Amshb4mZdA7nl9kMmfpK269rkbi5vWm0W9ARivirXsv05vkn:430bHA7XRr95QWQQgaKkn
                                                                                                                                                                                                                                                          MD5:554ED2CAFD25F5F82DA54AE057F4BA98
                                                                                                                                                                                                                                                          SHA1:E25CDF0F9C4B523B5B05408E7820F7B4F627D19E
                                                                                                                                                                                                                                                          SHA-256:7E90D2008B220DB19C796C7107AD69D263B8AC8C7BDDFB879230699D978E9A0A
                                                                                                                                                                                                                                                          SHA-512:612201CCD64A51EC943921196D8C74D8BCA3AB3E35B0C9E91AE7F3A6B36F4F255AA9ADB3A254EC03629B01BD221B0B3F8CC4DFBFAC1F1718775E81CAD188AA86
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset lv DAYS_OF_WEEK_ABBREV [list \.. "Sv"\.. "P"\.. "O"\.. "T"\.. "C"\.. "Pk"\.. "S"].. ::msgcat::mcset lv DAYS_OF_WEEK_FULL [list \.. "sv\u0113tdiena"\.. "pirmdiena"\.. "otrdiena"\.. "tre\u0161diena"\.. "ceturdien"\.. "piektdiena"\.. "sestdiena"].. ::msgcat::mcset lv MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Maijs"\.. "J\u016bn"\.. "J\u016bl"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dec"\.. ""].. ::msgcat::mcset lv MONTHS_FULL [list \.. "janv\u0101ris"\.. "febru\u0101ris"\.. "marts"\.. "apr\u012blis"\.. "maijs"\.. "j\u016bnijs"\.. "j\u016blijs"\.. "augusts"\.. "septembris"\.. "oktobris"\.. "novembris"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2157
                                                                                                                                                                                                                                                          Entropy (8bit):4.299300188052441
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:4389QMsGqdQfRQPjQmofqJp9sk5BstSpWQiQ3QJQ5QL39I0QRQTQ8Ql4J8W:2W8SMq+9sWINi2Kc9I0+gXF
                                                                                                                                                                                                                                                          MD5:888014F13A82511ABEF99497A753BFC3
                                                                                                                                                                                                                                                          SHA1:7F4231BEDE191370B37E8B917B6AD8829D15CA7D
                                                                                                                                                                                                                                                          SHA-256:4C0EB07F0FCB36DD12A3F7EDD6531616611ABF62BF7705B5A37CC59098221D5D
                                                                                                                                                                                                                                                          SHA-512:D748127CC615584901D35B6492EC566448B6C4DA6363858B5145921E9CD09490355CF4315F0F7A8542AA12790CD3432011A643A3A8F74B0119DB0DCE19FD68A4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset mk DAYS_OF_WEEK_ABBREV [list \.. "\u043d\u0435\u0434."\.. "\u043f\u043e\u043d."\.. "\u0432\u0442."\.. "\u0441\u0440\u0435."\.. "\u0447\u0435\u0442."\.. "\u043f\u0435\u0442."\.. "\u0441\u0430\u0431."].. ::msgcat::mcset mk DAYS_OF_WEEK_FULL [list \.. "\u043d\u0435\u0434\u0435\u043b\u0430"\.. "\u043f\u043e\u043d\u0435\u0434\u0435\u043b\u043d\u0438\u043a"\.. "\u0432\u0442\u043e\u0440\u043d\u0438\u043a"\.. "\u0441\u0440\u0435\u0434\u0430"\.. "\u0447\u0435\u0442\u0432\u0440\u0442\u043e\u043a"\.. "\u043f\u0435\u0442\u043e\u043a"\.. "\u0441\u0430\u0431\u043e\u0442\u0430"].. ::msgcat::mcset mk MONTHS_ABBREV [list \.. "\u0458\u0430\u043d."\.. "\u0444\u0435\u0432."\.. "\u043c\u0430\u0440."\.. "\u0430\u043f\u0440."\.. "\u043c\u0430\u0458."\.. "\u0458\u0443\u
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1846
                                                                                                                                                                                                                                                          Entropy (8bit):4.220147808639664
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR833cXh48Vc7VczfVczPmzNVcYVcR0prdSmS68FezUVcYVcR0prdSmS68FeoV:43K4S+0prjS68Yh0prjS68nV
                                                                                                                                                                                                                                                          MD5:07F99E0A05083B10F80A4D6867163B23
                                                                                                                                                                                                                                                          SHA1:B6036C7DA8043E3401583D03831E7A4BF755D93D
                                                                                                                                                                                                                                                          SHA-256:AE873BF5484EACBBE179913D43451BE53378FA701B5D81594D052266B8A09AF0
                                                                                                                                                                                                                                                          SHA-512:3A032C81B8FBFEE6EB66C1538CBD16329A1B393E4684B4E9B3FBCDD6344CE8AD34FA699F76EF953B3EB597D8E253345F54C2E92E7A43611C721038BCC2471EA2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset mr DAYS_OF_WEEK_FULL [list \.. "\u0930\u0935\u093f\u0935\u093e\u0930"\.. "\u0938\u094b\u092e\u0935\u093e\u0930"\.. "\u092e\u0902\u0917\u0933\u0935\u093e\u0930"\.. "\u092e\u0902\u0917\u0933\u0935\u093e\u0930"\.. "\u0917\u0941\u0930\u0941\u0935\u093e\u0930"\.. "\u0936\u0941\u0915\u094d\u0930\u0935\u093e\u0930"\.. "\u0936\u0928\u093f\u0935\u093e\u0930"].. ::msgcat::mcset mr MONTHS_ABBREV [list \.. "\u091c\u093e\u0928\u0947\u0935\u093e\u0930\u0940"\.. "\u092b\u0947\u092c\u0943\u0935\u093e\u0930\u0940"\.. "\u092e\u093e\u0930\u094d\u091a"\.. "\u090f\u092a\u094d\u0930\u093f\u0932"\.. "\u092e\u0947"\.. "\u091c\u0942\u0928"\.. "\u091c\u0941\u0932\u0948"\.. "\u0913\u0917\u0938\u094d\u091f"\.. "\u0938\u0947\u092a\u094d\u091f\u0947\u0902\u092c\u0930"\.. "\u0913\u0915\u094d\u091f\u0
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.89440333975705
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoGNv+IZoGU3v6ry/5oGNo+3v+6f6HyFvn:4EnLB383Zvlw3v6ry/ZF3vmSVn
                                                                                                                                                                                                                                                          MD5:67368E8A5715860BABD44E54A168192F
                                                                                                                                                                                                                                                          SHA1:7790D4B4B28FE5E38AB11CD037FFB826A8EB77FD
                                                                                                                                                                                                                                                          SHA-256:B7B1D379355A1D278E13EF557A887A662E84FB6A9B62B8E19A27927926270EF9
                                                                                                                                                                                                                                                          SHA-512:E95C90CFFA7CC4E61026FC328A4AA0BEE6A54A0061BA0B9459F9F0F4B008DD36F81BC9B8D8B964FA051FCEAB7FECE6D107CD456B3FD01A83B4900ECC3A0BCFA4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset mr_IN DATE_FORMAT "%d %M %Y".. ::msgcat::mcset mr_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset mr_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):957
                                                                                                                                                                                                                                                          Entropy (8bit):4.018924167342869
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:4EnLB383Zm/aufodZmt+JHEA7UVRosmAL/7Idzr43xRRosuL1PJHWZ6tHhHjv:4aR83ZsauSHJkA7umE/72UD21PJWZ0hT
                                                                                                                                                                                                                                                          MD5:7E6A943B7D82404F61BDBD95682073CD
                                                                                                                                                                                                                                                          SHA1:B96DBB1738F293D2842FDCEDF2DEF13004F77A8D
                                                                                                                                                                                                                                                          SHA-256:970B2F3ECC04980FCC2F9531CA6CE2BF36BC12942CB614BF70313B4CB0508985
                                                                                                                                                                                                                                                          SHA-512:12F5A5F7A170EE79D1F4398E96FF2DE84472027C5B5003DE7E86F46713E3F0997439E2EBA03FFB7DB611F0CE0E06EB149F5BD08ED2AA0409DB8348867487FFFD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ms DAYS_OF_WEEK_ABBREV [list \.. "Aha"\.. "Isn"\.. "Sei"\.. "Rab"\.. "Kha"\.. "Jum"\.. "Sab"].. ::msgcat::mcset ms DAYS_OF_WEEK_FULL [list \.. "Ahad"\.. "Isnin"\.. "Selasa"\.. "Rahu"\.. "Khamis"\.. "Jumaat"\.. "Sabtu"].. ::msgcat::mcset ms MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mac"\.. "Apr"\.. "Mei"\.. "Jun"\.. "Jul"\.. "Ogos"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dis"\.. ""].. ::msgcat::mcset ms MONTHS_FULL [list \.. "Januari"\.. "Februari"\.. "Mac"\.. "April"\.. "Mei"\.. "Jun"\.. "Julai"\.. "Ogos"\.. "September"\.. "Oktober"\.. "November"\.. "Disember"\.. ""]..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):265
                                                                                                                                                                                                                                                          Entropy (8bit):4.818053174805798
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoChFfluoChF+3v6xyFjoCh++3vflm68vn:4EnLB383xPflwe3v6gZl3vflm6+n
                                                                                                                                                                                                                                                          MD5:A02F11BE0DF920E63E7A3ACCE746E32D
                                                                                                                                                                                                                                                          SHA1:4A8B1EF1A6F8A5FD022042D6E009A01E4B0FEBD3
                                                                                                                                                                                                                                                          SHA-256:F5B859D8DD2A2B5F756E39B0DFEB26B95878D2F54BA3CE46C56F0F26CF2B554B
                                                                                                                                                                                                                                                          SHA-512:5F9AF8C89F491CB4C158ED73EA4CF32E6A83CF44A94DA6FE1A962C58199BF2348530F3DEFA0C6F433BA3ADEF81AE9B3884F30CD7A841B159D52F9F21008B4F92
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ms_MY DATE_FORMAT "%A %d %b %Y".. ::msgcat::mcset ms_MY TIME_FORMAT_12 "%I:%M:%S %z".. ::msgcat::mcset ms_MY DATE_TIME_FORMAT "%A %d %b %Y %I:%M:%S %z %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):717
                                                                                                                                                                                                                                                          Entropy (8bit):4.55153350337982
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:4EnLB383VYmxWHWog4QUbxMmAMMiGZu+3v6ay/GK3vZsSVn:4aR83VYsxonQ2MmVVGRvjCGsvGSV
                                                                                                                                                                                                                                                          MD5:D8BBEC2F8935054E6081BB5E4AE8F7E3
                                                                                                                                                                                                                                                          SHA1:33FE6D51A284B8760BC6F442329B10374F506BDA
                                                                                                                                                                                                                                                          SHA-256:7DBC4E82D82FDE8CDF522FA10E082289D46B0C1A4A7D7A5FA83FF116677F052B
                                                                                                                                                                                                                                                          SHA-512:BF39C75DD6B3625897D7D44AC253AF5656CA21D0B394F78611584E2606CBC419C4A02353542D23393BEBCCF0CB4D861CDECD61AD89339F78C0260E966B495777
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset mt DAYS_OF_WEEK_ABBREV [list \.. "\u0126ad"\.. "Tne"\.. "Tli"\.. "Erb"\.. "\u0126am"\.. "\u0120im"].. ::msgcat::mcset mt MONTHS_ABBREV [list \.. "Jan"\.. "Fra"\.. "Mar"\.. "Apr"\.. "Mej"\.. "\u0120un"\.. "Lul"\.. "Awi"\.. "Set"\.. "Ott"\.. "Nov"].. ::msgcat::mcset mt BCE "QK".. ::msgcat::mcset mt CE "".. ::msgcat::mcset mt DATE_FORMAT "%A, %e ta %B, %Y".. ::msgcat::mcset mt TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset mt DATE_TIME_FORMAT "%A, %e ta %B, %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1209
                                                                                                                                                                                                                                                          Entropy (8bit):4.313626715960843
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83B0tSYuZrIsmYmPAxyIQ4HU92W16EL3Tvav31:43qhuZrIPAt04yTcF
                                                                                                                                                                                                                                                          MD5:42D02C3CAF28BE4994F27CEF5A183AB7
                                                                                                                                                                                                                                                          SHA1:DC411E8AC12C3D588AB2F3A3C95A75D8689AD402
                                                                                                                                                                                                                                                          SHA-256:534C5DACEF12F818FAF4ED806997A559F95D591F1B6236B0C30B07A107DD13F3
                                                                                                                                                                                                                                                          SHA-512:0BE27572106324FE2B6CDFF4513500DE7582AD1ABEF451FFC62B2050D3875A149DDDB66451E1B3F5BA9216268E9998D2A1C1E8343BBB9EF97947DA054B82818E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nb DAYS_OF_WEEK_ABBREV [list \.. "s\u00f8"\.. "ma"\.. "ti"\.. "on"\.. "to"\.. "fr"\.. "l\u00f8"].. ::msgcat::mcset nb DAYS_OF_WEEK_FULL [list \.. "s\u00f8ndag"\.. "mandag"\.. "tirsdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "l\u00f8rdag"].. ::msgcat::mcset nb MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "mai"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "des"\.. ""].. ::msgcat::mcset nb MONTHS_FULL [list \.. "januar"\.. "februar"\.. "mars"\.. "april"\.. "mai"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\.. "desember"\.. ""].. ::msgcat::mcset nb BC
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1129
                                                                                                                                                                                                                                                          Entropy (8bit):4.235969198645435
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR837Ed+RxRMZZsmUmnZAEEHM92WFU5vtrvs:43AAHRMZZPnZALsCtt7s
                                                                                                                                                                                                                                                          MD5:B9B949794203D204628D4DBEA29587AE
                                                                                                                                                                                                                                                          SHA1:1642D8040144469B5C359E80693E68036F87B849
                                                                                                                                                                                                                                                          SHA-256:9E2FE3851CF13EC79A9B10A09B01CEB0A26044AE0DC90A4E00BE57745E854C79
                                                                                                                                                                                                                                                          SHA-512:0CCCCF6D61423CEE0389C3BA1A8E94F2B092C53465D1937F5595AF91E46DD38B318D6C7EE3D88B89F32BFB952C0D55E0E67B46D7DF306ECA6690E283ADEB2CB9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nl DAYS_OF_WEEK_ABBREV [list \.. "zo"\.. "ma"\.. "di"\.. "wo"\.. "do"\.. "vr"\.. "za"].. ::msgcat::mcset nl DAYS_OF_WEEK_FULL [list \.. "zondag"\.. "maandag"\.. "dinsdag"\.. "woensdag"\.. "donderdag"\.. "vrijdag"\.. "zaterdag"].. ::msgcat::mcset nl MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mrt"\.. "apr"\.. "mei"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset nl MONTHS_FULL [list \.. "januari"\.. "februari"\.. "maart"\.. "april"\.. "mei"\.. "juni"\.. "juli"\.. "augustus"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat::mcset nl DATE_FORM
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):286
                                                                                                                                                                                                                                                          Entropy (8bit):4.865165930946383
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xo4gPPdjog9X3vLjog9X3v6mjo49+3vnFDoAkvn:4EnLB3835gHdPF3vjF3v64I3v9dmn
                                                                                                                                                                                                                                                          MD5:3261F397ED0291368FF1881E7BA08ECE
                                                                                                                                                                                                                                                          SHA1:7147ABB62034EB152B1FED9246A533535F07372C
                                                                                                                                                                                                                                                          SHA-256:77A69DD60D171B321512B14794E75A66FF753410C007997B310790D86E09B057
                                                                                                                                                                                                                                                          SHA-512:C1526F454FA594DAD056B056F76F01D8B2AB713D04EB2A3643416B8E741B248CC94E000BAEE5B0F60436B88B1216FB1DE7F7C3FA456D4A4FBDE24F97C3B739B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nl_BE DATE_FORMAT "%d-%m-%y".. ::msgcat::mcset nl_BE TIME_FORMAT "%T".. ::msgcat::mcset nl_BE TIME_FORMAT_12 "%T".. ::msgcat::mcset nl_BE DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1200
                                                                                                                                                                                                                                                          Entropy (8bit):4.282788574144479
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83tCtrJwuQrIsmYmLAxyIQ4HU92W1W4/3Hv+v31:434suQrILAt0EafIF
                                                                                                                                                                                                                                                          MD5:985E97517C2BF37719A618F575DF392C
                                                                                                                                                                                                                                                          SHA1:65BC07FC3A955300ED09B7485F90AEC18CBAD43F
                                                                                                                                                                                                                                                          SHA-256:06FA2D6D8C59D0B8EAC2EDE5AB0DDB8B6E095D1A023B1966FCE3B65916FA14FB
                                                                                                                                                                                                                                                          SHA-512:75BC14DBAD147A98D32D2AF0BE0BE50F115BB9C3BBE283B53977B9F264A055734B30F6B1C4EEE9686F1874D178C535111731C92D495B7D370FB17213B65C9A40
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nn DAYS_OF_WEEK_ABBREV [list \.. "su"\.. "m\u00e5"\.. "ty"\.. "on"\.. "to"\.. "fr"\.. "lau"].. ::msgcat::mcset nn DAYS_OF_WEEK_FULL [list \.. "sundag"\.. "m\u00e5ndag"\.. "tysdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "laurdag"].. ::msgcat::mcset nn MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "mai"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "des"\.. ""].. ::msgcat::mcset nn MONTHS_FULL [list \.. "januar"\.. "februar"\.. "mars"\.. "april"\.. "mai"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\.. "desember"\.. ""].. ::msgcat::mcset nn BCE "f.Kr."
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1263
                                                                                                                                                                                                                                                          Entropy (8bit):4.459506202908786
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83lUj0ORGgIzdW6RDYKG7FwRc0ypvOvX:43+HMg2W6RDYnFwRc0ydYX
                                                                                                                                                                                                                                                          MD5:79AB7C13AA3833A1DAEADDB1144CCE55
                                                                                                                                                                                                                                                          SHA1:C01ABC2F16549CAEC6B081448B2CBA88A680E250
                                                                                                                                                                                                                                                          SHA-256:61462C325DB0065352D8155307F949869862A86CAC67AD7BB6703F57A7FA2FF3
                                                                                                                                                                                                                                                          SHA-512:79EB696164FDDD9B121558C2780E54E295FF2DC4D8E87A0DE507B4F2925612721A98FF5010199CB68CF894ACA7A07884E9E02F3DC1E078D241431E3DC884C0A1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset pl DAYS_OF_WEEK_ABBREV [list \.. "N"\.. "Pn"\.. "Wt"\.. "\u015ar"\.. "Cz"\.. "Pt"\.. "So"].. ::msgcat::mcset pl DAYS_OF_WEEK_FULL [list \.. "niedziela"\.. "poniedzia\u0142ek"\.. "wtorek"\.. "\u015broda"\.. "czwartek"\.. "pi\u0105tek"\.. "sobota"].. ::msgcat::mcset pl MONTHS_ABBREV [list \.. "sty"\.. "lut"\.. "mar"\.. "kwi"\.. "maj"\.. "cze"\.. "lip"\.. "sie"\.. "wrz"\.. "pa\u017a"\.. "lis"\.. "gru"\.. ""].. ::msgcat::mcset pl MONTHS_FULL [list \.. "stycze\u0144"\.. "luty"\.. "marzec"\.. "kwiecie\u0144"\.. "maj"\.. "czerwiec"\.. "lipiec"\.. "sierpie\u0144"\.. "wrzesie\u0144"\.. "pa\u017adziernik"\.. "listopad"\..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1177
                                                                                                                                                                                                                                                          Entropy (8bit):4.394980756969744
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83CYkjBc1yHYJt//0/I31YMY47flV7YaqgCyt9Fo8g6Gtvt76svi:43C5LHcNnxJ9Ltg6Gpt76Ki
                                                                                                                                                                                                                                                          MD5:8F53B3571DD29E12BD33349CFA32F28F
                                                                                                                                                                                                                                                          SHA1:C125E059B8BFE5FECD482D1A1DA50B8678872BF6
                                                                                                                                                                                                                                                          SHA-256:6F6EEEDDCF232BDCB952592A144810CED44A1CBB4BCC2C062D5F98D441505380
                                                                                                                                                                                                                                                          SHA-512:5CD7E7097B720E5399795126A71348816CBA697FD8F14160779E982ADAB00D5994978E2F9445785B0DE62F6F14232278AD1A65BC53730CA58D676B057F0BC406
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset pt DAYS_OF_WEEK_ABBREV [list \.. "Dom"\.. "Seg"\.. "Ter"\.. "Qua"\.. "Qui"\.. "Sex"\.. "S\u00e1b"].. ::msgcat::mcset pt DAYS_OF_WEEK_FULL [list \.. "Domingo"\.. "Segunda-feira"\.. "Ter\u00e7a-feira"\.. "Quarta-feira"\.. "Quinta-feira"\.. "Sexta-feira"\.. "S\u00e1bado"].. ::msgcat::mcset pt MONTHS_ABBREV [list \.. "Jan"\.. "Fev"\.. "Mar"\.. "Abr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Ago"\.. "Set"\.. "Out"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset pt MONTHS_FULL [list \.. "Janeiro"\.. "Fevereiro"\.. "Mar\u00e7o"\.. "Abril"\.. "Maio"\.. "Junho"\.. "Julho"\.. "Agosto"\.. "Setembro"\.. "Outubro"\.. "Novembro"\.. "Dezembro"
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):286
                                                                                                                                                                                                                                                          Entropy (8bit):4.8608779725401785
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xofm6GPWWjofAW3vLjofAW3v6mjofm6T+3vnFDoAkvn:4EnLB383+NGdg93vk93v6fNK3v9dmn
                                                                                                                                                                                                                                                          MD5:A2626EA95C2480FEA68906AE6A1F6993
                                                                                                                                                                                                                                                          SHA1:A0592902337C00FC2E70B1DFB3A42453A86535BB
                                                                                                                                                                                                                                                          SHA-256:320BE7D5B730091E6FA35F196314737261C8E154577DCF6AC8C2057D44394AD7
                                                                                                                                                                                                                                                          SHA-512:9801A87D024565676D4F3EAF0702C213E59FC2B6719D8BE95C19C9ED53FC43487F65F5408378B401A2B4C2BD4E2E391C2D848CA87739A6082AB7766EC6B9EFE1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset pt_BR DATE_FORMAT "%d-%m-%Y".. ::msgcat::mcset pt_BR TIME_FORMAT "%T".. ::msgcat::mcset pt_BR TIME_FORMAT_12 "%T".. ::msgcat::mcset pt_BR DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1224
                                                                                                                                                                                                                                                          Entropy (8bit):4.350784108088039
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83coPUMSeZmkTMm41icpK+7ZVoImEcVUCWdvHvWIn:43lPHFmkm1iMVoxEc+CWZPWIn
                                                                                                                                                                                                                                                          MD5:F6575EC17966320106FF7ABDFB3186E2
                                                                                                                                                                                                                                                          SHA1:68C6B72D664FDA27450FCE8B5734AB627CE825D7
                                                                                                                                                                                                                                                          SHA-256:25ED6AC7A353E23B954B98611AE3B7E56BDCF2B0CB0DB358253CFB8BEBBB831C
                                                                                                                                                                                                                                                          SHA-512:E564543231922A17C898419545BFA65E5E31FE9F005FDD201B735CFDE08E96FB3B98349C2A7959E29CA8F7E6934B0C4C6DE6B5E67209D0DD9A7746DFEBF037B3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ro DAYS_OF_WEEK_ABBREV [list \.. "D"\.. "L"\.. "Ma"\.. "Mi"\.. "J"\.. "V"\.. "S"].. ::msgcat::mcset ro DAYS_OF_WEEK_FULL [list \.. "duminic\u0103"\.. "luni"\.. "mar\u0163i"\.. "miercuri"\.. "joi"\.. "vineri"\.. "s\u00eemb\u0103t\u0103"].. ::msgcat::mcset ro MONTHS_ABBREV [list \.. "Ian"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Mai"\.. "Iun"\.. "Iul"\.. "Aug"\.. "Sep"\.. "Oct"\.. "Nov"\.. "Dec"\.. ""].. ::msgcat::mcset ro MONTHS_FULL [list \.. "ianuarie"\.. "februarie"\.. "martie"\.. "aprilie"\.. "mai"\.. "iunie"\.. "iulie"\.. "august"\.. "septembrie"\.. "octombrie"\.. "noiembrie"\.. "decembrie"\.. ""].. ::msgcat:
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2091
                                                                                                                                                                                                                                                          Entropy (8bit):4.2886524607041006
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:43D+pQ7keidQfRQPgQHB81Z/sFIAZSQWQXQrQxJQjQRnQBFQiWftkWt:26pgkeoSnpjA4tMYiJcCMFmVRt
                                                                                                                                                                                                                                                          MD5:9F1C8DD58550558977821FD500E7C0E0
                                                                                                                                                                                                                                                          SHA1:EFDD809BC2872A5BE0E353D31BE6D7D72E4B829C
                                                                                                                                                                                                                                                          SHA-256:BB35BB6F07BAEF72C329EC3E95D6527A2736070EE2FFE5DE227E1FF0332390F8
                                                                                                                                                                                                                                                          SHA-512:AA3C5C40AE9D342F8287958355C3321CF60566AD3E84E3D18D782FC022A998DA275506A61010A65D2E7D7578F2919C47C63AB0BA63A38800AA48D4B88ACE54D3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ru DAYS_OF_WEEK_ABBREV [list \.. "\u0412\u0441"\.. "\u041f\u043d"\.. "\u0412\u0442"\.. "\u0421\u0440"\.. "\u0427\u0442"\.. "\u041f\u0442"\.. "\u0421\u0431"].. ::msgcat::mcset ru DAYS_OF_WEEK_FULL [list \.. "\u0432\u043e\u0441\u043a\u0440\u0435\u0441\u0435\u043d\u044c\u0435"\.. "\u043f\u043e\u043d\u0435\u0434\u0435\u043b\u044c\u043d\u0438\u043a"\.. "\u0432\u0442\u043e\u0440\u043d\u0438\u043a"\.. "\u0441\u0440\u0435\u0434\u0430"\.. "\u0447\u0435\u0442\u0432\u0435\u0440\u0433"\.. "\u043f\u044f\u0442\u043d\u0438\u0446\u0430"\.. "\u0441\u0443\u0431\u0431\u043e\u0442\u0430"].. ::msgcat::mcset ru MONTHS_ABBREV [list \.. "\u044f\u043d\u0432"\.. "\u0444\u0435\u0432"\.. "\u043c\u0430\u0440"\.. "\u0430\u043f\u0440"\.. "\u043c\u0430\u0439"\.. "\u0438\u044e\u
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):248
                                                                                                                                                                                                                                                          Entropy (8bit):4.9420431225061
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoVAgWIZoVY9X3vtfNrsoVA9+3vW6Q9vn:4EnLB383SFWIyaX3vtNl/3vWHNn
                                                                                                                                                                                                                                                          MD5:DC98D88964650E302BE97FDB3B33326E
                                                                                                                                                                                                                                                          SHA1:1DDDCC4265D7B980B867FEE674BEF2FD87D823F7
                                                                                                                                                                                                                                                          SHA-256:13E4E79A0ED82034BADE0CFF8DEF5DE1222F6968108AD710662BDB7DAF36D7E1
                                                                                                                                                                                                                                                          SHA-512:F3B9D528C529DD520FEDA3C20ED354E521C5B3C29F3317E15B7939CE06A3D67554D34DD6E54FE038585E46C560C604A1FD7E7F84914086B5994D52CE2C9E99CE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ru_UA DATE_FORMAT "%d.%m.%Y".. ::msgcat::mcset ru_UA TIME_FORMAT "%k:%M:%S".. ::msgcat::mcset ru_UA DATE_TIME_FORMAT "%d.%m.%Y %k:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1212
                                                                                                                                                                                                                                                          Entropy (8bit):4.359036493565628
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83/YIXo4YY0dD6kMm7fX2NaSIvZdHZgHZ/IxvaGWxvtl9svWTN:43rLTR44/yWltOWB
                                                                                                                                                                                                                                                          MD5:E297221FA73BD78577B398BC7D061D21
                                                                                                                                                                                                                                                          SHA1:F2A6B456272F913A9E97C495CEE73AC774C90FA1
                                                                                                                                                                                                                                                          SHA-256:E65D6E5E837DF0A2DF0DB77BCE45334BBC27EFFF9023C37119E75D49932D9D6C
                                                                                                                                                                                                                                                          SHA-512:AB9DDAE7CB21193C7753041F0B88CF2D40987E7E604B47816219458D217F084AA4EBF36719E22AAB3FD71A271D9F956ADC353182991903D7ADE8C8F00F6B2F9B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sh DAYS_OF_WEEK_ABBREV [list \.. "Ned"\.. "Pon"\.. "Uto"\.. "Sre"\.. "\u010cet"\.. "Pet"\.. "Sub"].. ::msgcat::mcset sh DAYS_OF_WEEK_FULL [list \.. "Nedelja"\.. "Ponedeljak"\.. "Utorak"\.. "Sreda"\.. "\u010cetvrtak"\.. "Petak"\.. "Subota"].. ::msgcat::mcset sh MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Maj"\.. "Jun"\.. "Jul"\.. "Avg"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dec"\.. ""].. ::msgcat::mcset sh MONTHS_FULL [list \.. "Januar"\.. "Februar"\.. "Mart"\.. "April"\.. "Maj"\.. "Juni"\.. "Juli"\.. "Avgust"\.. "Septembar"\.. "Oktobar"\.. "Novembar"\.. "Decembar"\.. ""].. ::msgcat::mcset sh BC
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1255
                                                                                                                                                                                                                                                          Entropy (8bit):4.4043119723436135
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83c46o40u3rIsmJIcm93ApLDVb2IcU95WFGEXF3eUCvtz/v3e6:43c3ow3rF93Ap7tEXFREtznp
                                                                                                                                                                                                                                                          MD5:24DA40901D907D35195CC1B3A675EBC7
                                                                                                                                                                                                                                                          SHA1:8AF31248F06FADA5CFB0D83A940CFF5CE70E2577
                                                                                                                                                                                                                                                          SHA-256:976813F6C53C9BEBBF976B0F560FD7FC5E4EC4C574D7E1CD31F9A4056765CB7A
                                                                                                                                                                                                                                                          SHA-512:A9BC6AAFE9AEEDFD1E483E54A2D27871A09ADD6807D8F90410CD2BB82A91BA9DF435652EC9A7C3AD0A080D7F153CA848BB47DAD3936BA30E4AEFF3C474C433CC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sk DAYS_OF_WEEK_ABBREV [list \.. "Ne"\.. "Po"\.. "Ut"\.. "St"\.. "\u0160t"\.. "Pa"\.. "So"].. ::msgcat::mcset sk DAYS_OF_WEEK_FULL [list \.. "Nede\u013ee"\.. "Pondelok"\.. "Utorok"\.. "Streda"\.. "\u0160tvrtok"\.. "Piatok"\.. "Sobota"].. ::msgcat::mcset sk MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "m\u00e1j"\.. "j\u00fan"\.. "j\u00fal"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset sk MONTHS_FULL [list \.. "janu\u00e1r"\.. "febru\u00e1r"\.. "marec"\.. "apr\u00edl"\.. "m\u00e1j"\.. "j\u00fan"\.. "j\u00fal"\.. "august"\.. "september"\.. "okt\u00f3ber"\.. "november"\.. "decem
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1216
                                                                                                                                                                                                                                                          Entropy (8bit):4.333705818952628
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83MIXpC9opYuGS/BrIsmZ5hv1yAxyIVjd392WFThENvt0vJoO:43fXYujZrqyApYJtyR
                                                                                                                                                                                                                                                          MD5:CB76F54CBE0D1AAE8BA956B4C51CBD2A
                                                                                                                                                                                                                                                          SHA1:C1F78375EDB0BD2504553E33B2024C0C63FDB1B2
                                                                                                                                                                                                                                                          SHA-256:11A6264676DBED87E4F718075127E32E107854F35F141642454F484984084486
                                                                                                                                                                                                                                                          SHA-512:69964348FF08DE6EEB5E3DD61057FF0DF5441105EB7BEE7FB7E9AC5E26DCC164E3C7C011CA5CD7BC5B97A7872532331C97CCBC80563F6C5A3548014BFA8BEF16
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sl DAYS_OF_WEEK_ABBREV [list \.. "Ned"\.. "Pon"\.. "Tor"\.. "Sre"\.. "\u010cet"\.. "Pet"\.. "Sob"].. ::msgcat::mcset sl DAYS_OF_WEEK_FULL [list \.. "Nedelja"\.. "Ponedeljek"\.. "Torek"\.. "Sreda"\.. "\u010cetrtek"\.. "Petek"\.. "Sobota"].. ::msgcat::mcset sl MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "avg"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset sl MONTHS_FULL [list \.. "januar"\.. "februar"\.. "marec"\.. "april"\.. "maj"\.. "junij"\.. "julij"\.. "avgust"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat::mcset sl B
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1321
                                                                                                                                                                                                                                                          Entropy (8bit):4.408176575111904
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83F7ONQEwXwjjTlVoSEh76W/X+WZQJ4hv+H6v2V:43NwjPEwl4VQ8q
                                                                                                                                                                                                                                                          MD5:E606F620F03EC0FBDBE6551601299C5F
                                                                                                                                                                                                                                                          SHA1:0B50AB679E8D90D8E7319BCADAC426E004594D3B
                                                                                                                                                                                                                                                          SHA-256:1F4EFD78F6B45B65F73F09B2F52FC13C2A7C4138DCB7664804878D197B6EBDF9
                                                                                                                                                                                                                                                          SHA-512:08AF2B51EB7111E334ADDA3A03F9A8816C104E9742B523EC363FB5131A3DF73D298A8DDCD573D23C23C65CCFD2B8898DF75AE3D4F04BF80744044FB6BAB5EC0A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sq DAYS_OF_WEEK_ABBREV [list \.. "Die"\.. "H\u00ebn"\.. "Mar"\.. "M\u00ebr"\.. "Enj"\.. "Pre"\.. "Sht"].. ::msgcat::mcset sq DAYS_OF_WEEK_FULL [list \.. "e diel"\.. "e h\u00ebn\u00eb"\.. "e mart\u00eb"\.. "e m\u00ebrkur\u00eb"\.. "e enjte"\.. "e premte"\.. "e shtun\u00eb"].. ::msgcat::mcset sq MONTHS_ABBREV [list \.. "Jan"\.. "Shk"\.. "Mar"\.. "Pri"\.. "Maj"\.. "Qer"\.. "Kor"\.. "Gsh"\.. "Sht"\.. "Tet"\.. "N\u00ebn"\.. "Dhj"\.. ""].. ::msgcat::mcset sq MONTHS_FULL [list \.. "janar"\.. "shkurt"\.. "mars"\.. "prill"\.. "maj"\.. "qershor"\.. "korrik"\.. "gusht"\.. "shtator"\.. "tetor"\.. "n\u00ebntor"\.. "dhjetor"\.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2087
                                                                                                                                                                                                                                                          Entropy (8bit):4.307749748884122
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:43ilQTSBQrQP9QenzMKSFD9NI/QiNQEQrQL1KKYjU5rtAx:2I5EyLMKSFZNIYMzYMKKiqW
                                                                                                                                                                                                                                                          MD5:BF363AB60B57F6D8FDCDBFD230A28DDF
                                                                                                                                                                                                                                                          SHA1:6375CBA0A2197DA7E65BEE45C42F02C4F0B9142D
                                                                                                                                                                                                                                                          SHA-256:FA00A7B22C9941F6C2B893F22B703DCB159CA2F2E4005FD6A74A632AEB786BFA
                                                                                                                                                                                                                                                          SHA-512:91AD8085EF321A5A0E4D2ED204940CB66E8E230BBEDE59A8A07D1CEED9155FCC6B075A1FCC44AE834C1FEEEB3A59256C4310684C5AC453D4C50DFABD88469814
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sr DAYS_OF_WEEK_ABBREV [list \.. "\u041d\u0435\u0434"\.. "\u041f\u043e\u043d"\.. "\u0423\u0442\u043e"\.. "\u0421\u0440\u0435"\.. "\u0427\u0435\u0442"\.. "\u041f\u0435\u0442"\.. "\u0421\u0443\u0431"].. ::msgcat::mcset sr DAYS_OF_WEEK_FULL [list \.. "\u041d\u0435\u0434\u0435\u0459\u0430"\.. "\u041f\u043e\u043d\u0435\u0434\u0435\u0459\u0430\u043a"\.. "\u0423\u0442\u043e\u0440\u0430\u043a"\.. "\u0421\u0440\u0435\u0434\u0430"\.. "\u0427\u0435\u0442\u0432\u0440\u0442\u0430\u043a"\.. "\u041f\u0435\u0442\u0430\u043a"\.. "\u0421\u0443\u0431\u043e\u0442\u0430"].. ::msgcat::mcset sr MONTHS_ABBREV [list \.. "\u0408\u0430\u043d"\.. "\u0424\u0435\u0431"\.. "\u041c\u0430\u0440"\.. "\u0410\u043f\u0440"\.. "\u041c\u0430\u0458"\.. "\u0408\u0443\u043d"\.. "\
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1219
                                                                                                                                                                                                                                                          Entropy (8bit):4.3542418837714285
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83qoLt6yLQoAusrIsmZ5m4AcjTHX92WFfjr4MvBvX:43ZLxQNusrr4Aw3Jkq1X
                                                                                                                                                                                                                                                          MD5:3B5C3FFA0829768470BDA1B46D882060
                                                                                                                                                                                                                                                          SHA1:C96799036EC5CCDE799A6B50CD7748908935A2F3
                                                                                                                                                                                                                                                          SHA-256:483916B51BD7E071E88F9EC36AAF3E08FEA823991532F832DE491C6C40B55A9F
                                                                                                                                                                                                                                                          SHA-512:684FA249123878AA7F856DF0FD3B0D9F041113CFEA8EEFA47D0E1948DA23694330BF0D62BA896A3891CD559C16CAE9330BF31508F530AC003D2929D5FD9246D8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sv DAYS_OF_WEEK_ABBREV [list \.. "s\u00f6"\.. "m\u00e5"\.. "ti"\.. "on"\.. "to"\.. "fr"\.. "l\u00f6"].. ::msgcat::mcset sv DAYS_OF_WEEK_FULL [list \.. "s\u00f6ndag"\.. "m\u00e5ndag"\.. "tisdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "l\u00f6rdag"].. ::msgcat::mcset sv MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset sv MONTHS_FULL [list \.. "januari"\.. "februari"\.. "mars"\.. "april"\.. "maj"\.. "juni"\.. "juli"\.. "augusti"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat:
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1040
                                                                                                                                                                                                                                                          Entropy (8bit):4.108744949579904
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:4EnLB383A4mScvhkzoR4mtuWckRkoay3UVxMmALfG7IdzVJ633xRCPLMYMvYo76u:4aR83/Shkz1uckO76kMmEf62qOTdMvvn
                                                                                                                                                                                                                                                          MD5:5774860C8AEECBD48F1502E616158CAB
                                                                                                                                                                                                                                                          SHA1:DE7059713EA7913A0C79F5386833CE2BCAD2CFD7
                                                                                                                                                                                                                                                          SHA-256:1DA068C9AA02EF14A2440758C6040D632D96044A20EC501DBB9E40D8592E0E7F
                                                                                                                                                                                                                                                          SHA-512:91E69222DDF55E9E0E389DB77D7A0F2E082351DC3FB34A1A2C1E350E4187E8BB940F6C2EDE1B8651159C2787AA0BE4D7268F33F7A82CAED03514FCE462530408
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sw DAYS_OF_WEEK_ABBREV [list \.. "Jpi"\.. "Jtt"\.. "Jnn"\.. "Jtn"\.. "Alh"\.. "Iju"\.. "Jmo"].. ::msgcat::mcset sw DAYS_OF_WEEK_FULL [list \.. "Jumapili"\.. "Jumatatu"\.. "Jumanne"\.. "Jumatano"\.. "Alhamisi"\.. "Ijumaa"\.. "Jumamosi"].. ::msgcat::mcset sw MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Mei"\.. "Jun"\.. "Jul"\.. "Ago"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Des"\.. ""].. ::msgcat::mcset sw MONTHS_FULL [list \.. "Januari"\.. "Februari"\.. "Machi"\.. "Aprili"\.. "Mei"\.. "Juni"\.. "Julai"\.. "Agosti"\.. "Septemba"\.. "Oktoba"\.. "Novemba"\.. "Desemba"\.. ""].. ::msgcat::mcset sw BCE "
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1874
                                                                                                                                                                                                                                                          Entropy (8bit):4.080580566597515
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83AI0xnJdnQhmHlHYPKtul+eOPfIxyH5ztUSLu8tptLtrl+eOPfIxyH5ztUSU:43N0dQmHlHYPKtu1HxMtr1Hx/
                                                                                                                                                                                                                                                          MD5:85288236C3997302EA26D7403BBA2C15
                                                                                                                                                                                                                                                          SHA1:05AB389CC4DCF17B37BFF6ED1ECD58D6E9850A01
                                                                                                                                                                                                                                                          SHA-256:AEFDC4255890D5B3FFE5CEE1B457B7D711283C2287ABA644155C10956012F6C1
                                                                                                                                                                                                                                                          SHA-512:8E389D46606176EE14B8356153095B49C9426B80139B672A620F488891F091D1A272D4FB116775900E4AB4EC84DDDEBD8D6AF81AC672F14F148F2BFC638D2B10
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ta DAYS_OF_WEEK_FULL [list \.. "\u0b9e\u0bbe\u0baf\u0bbf\u0bb1\u0bc1"\.. "\u0ba4\u0bbf\u0b99\u0bcd\u0b95\u0bb3\u0bcd"\.. "\u0b9a\u0bc6\u0bb5\u0bcd\u0bb5\u0bbe\u0baf\u0bcd"\.. "\u0baa\u0bc1\u0ba4\u0ba9\u0bcd"\.. "\u0bb5\u0bbf\u0baf\u0bbe\u0bb4\u0ba9\u0bcd"\.. "\u0bb5\u0bc6\u0bb3\u0bcd\u0bb3\u0bbf"\.. "\u0b9a\u0ba9\u0bbf"].. ::msgcat::mcset ta MONTHS_ABBREV [list \.. "\u0b9c\u0ba9\u0bb5\u0bb0\u0bbf"\.. "\u0baa\u0bc6\u0baa\u0bcd\u0bb0\u0bb5\u0bb0\u0bbf"\.. "\u0bae\u0bbe\u0bb0\u0bcd\u0b9a\u0bcd"\.. "\u0b8f\u0baa\u0bcd\u0bb0\u0bb2\u0bcd"\.. "\u0bae\u0bc7"\.. "\u0b9c\u0bc2\u0ba9\u0bcd"\.. "\u0b9c\u0bc2\u0bb2\u0bc8"\.. "\u0b86\u0b95\u0bb8\u0bcd\u0b9f\u0bcd"\.. "\u0b9a\u0bc6\u0baa\u0bcd\u0b9f\u0bae\u0bcd\u0baa\u0bb0\u0bcd"\.. "\u0b85\u0b95\u0bcd\u0b9f\u0bcb\u0baa\u0bb0\u0bcd"\.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):257
                                                                                                                                                                                                                                                          Entropy (8bit):4.863003494480733
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xosDv+IZosK3v6ry/5osDo+3v+6f6HyFvn:4EnLB383ZDvl5K3v6ry/ZDF3vmSVn
                                                                                                                                                                                                                                                          MD5:CF078352DA0507C767F04E31D6C14296
                                                                                                                                                                                                                                                          SHA1:0A9B1255BD85B60D3620AE61370F54748AB7A182
                                                                                                                                                                                                                                                          SHA-256:4978A193076DE56944236F7F1DCECACFF739536DFB3DBEFC1F7FE2B97A8AEAF4
                                                                                                                                                                                                                                                          SHA-512:6FFC85B2A8DECB373EC76B1CD1A9459A30E443319F2C8DB9BBE6E115F5EFEEBAC314D4E8BE996EA55EE46466C6F6057A73078F5FDCF1C4CBAF1A270E45BC10C0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ta_IN DATE_FORMAT "%d %M %Y".. ::msgcat::mcset ta_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset ta_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2149
                                                                                                                                                                                                                                                          Entropy (8bit):4.097884113767283
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:43a8mxI9k3JR0UjjFbPcniLHVktjjFbPcniLHVM:2a8v9k3JdbPcIidbPcIG
                                                                                                                                                                                                                                                          MD5:61E4CB2AAD66285E9113071057F39C35
                                                                                                                                                                                                                                                          SHA1:A2BD21090859669C4B6A875E077825381B7E2702
                                                                                                                                                                                                                                                          SHA-256:9E96C7123100234A7018533764502985A208F2EB3314F5B6332D46016725A63F
                                                                                                                                                                                                                                                          SHA-512:589A2D65508B07B5FDEDA883F71A4B496B25458CA1ECE7C4D4F5DAE82EB683DA82C8E21E57D63A235AB600174C9D362A746B2E27BAA6E3ADE1B7BD9D6000BE27
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset te DAYS_OF_WEEK_ABBREV [list \.. "\u0c06\u0c26\u0c3f"\.. "\u0c38\u0c4b\u0c2e"\.. "\u0c2e\u0c02\u0c17\u0c33"\.. "\u0c2c\u0c41\u0c27"\.. "\u0c17\u0c41\u0c30\u0c41"\.. "\u0c36\u0c41\u0c15\u0c4d\u0c30"\.. "\u0c36\u0c28\u0c3f"].. ::msgcat::mcset te DAYS_OF_WEEK_FULL [list \.. "\u0c06\u0c26\u0c3f\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c38\u0c4b\u0c2e\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c2e\u0c02\u0c17\u0c33\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c2c\u0c41\u0c27\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c17\u0c41\u0c30\u0c41\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c36\u0c41\u0c15\u0c4d\u0c30\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c36\u0c28\u0c3f\u0c35\u0c3e\u0c30\u0c02"].. ::msgcat::mcset te MONTHS_ABBREV [list \.. "\u0c1c\u0c28\u0c35\u0c30\u0c3f"\.. "\u0c2b\u0c3f\u0c2c\u0c4d\u0c30\u0c35\u0c30\u0c3f"\.. "\u0c2e\u0c3
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):419
                                                                                                                                                                                                                                                          Entropy (8bit):5.058324650031252
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:4EnLB383LjZWsn0sHjoD0savzda3v6ry/ZF3vMSVn:4aR833Z1nnHjoDnavzd8vSCZNvMSV
                                                                                                                                                                                                                                                          MD5:BCA040A356E7E8CC597EFB9B9065F8E1
                                                                                                                                                                                                                                                          SHA1:ADAF7EC8C2035BC06E168D3F1BD7F39277E9273F
                                                                                                                                                                                                                                                          SHA-256:B110FEEDDA21ECCEFA624BEF8E1476E9F221FB253880AC370967AE4D0237CA7A
                                                                                                                                                                                                                                                          SHA-512:D408ECE8CF89FB23B45420D3CBA7655EEE713498210889A84EE25D3417360705546D97028EAAAA47764B6E9B0A3699669B98C0A53861A38E0DFCB9F3B8A47BEC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset te_IN AM "\u0c2a\u0c42\u0c30\u0c4d\u0c35\u0c3e\u0c39\u0c4d\u0c28".. ::msgcat::mcset te_IN PM "\u0c05\u0c2a\u0c30\u0c3e\u0c39\u0c4d\u0c28".. ::msgcat::mcset te_IN DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset te_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset te_IN DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2359
                                                                                                                                                                                                                                                          Entropy (8bit):4.382796122808316
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:439X4QKPQJecQwFA0P9JmDsxQ7KHfWkD2CQM0DnWxFDzCYmdrtVP:29ohCi1028QmHfIC4jW3DmHB
                                                                                                                                                                                                                                                          MD5:7F61E1EA256D78948189EF07119663CD
                                                                                                                                                                                                                                                          SHA1:6867E9780049FACE9984B7788B6F362B8D1AD718
                                                                                                                                                                                                                                                          SHA-256:48BEAF693BF5B6EED15234DB0D375B97E6D576A749E9048420C153E6CAFC0259
                                                                                                                                                                                                                                                          SHA-512:F3E24E0B41A7D722AC2FA0E429A2DCB1CCB5BAECC9912ADF6AF79C51366EA1AC9F931F0F44F068F3CEE6873516E6223CC5E7616CF523B1DFB9E528DE4D58454A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset th DAYS_OF_WEEK_ABBREV [list \.. "\u0e2d\u0e32."\.. "\u0e08."\.. "\u0e2d."\.. "\u0e1e."\.. "\u0e1e\u0e24."\.. "\u0e28."\.. "\u0e2a."].. ::msgcat::mcset th DAYS_OF_WEEK_FULL [list \.. "\u0e27\u0e31\u0e19\u0e2d\u0e32\u0e17\u0e34\u0e15\u0e22\u0e4c"\.. "\u0e27\u0e31\u0e19\u0e08\u0e31\u0e19\u0e17\u0e23\u0e4c"\.. "\u0e27\u0e31\u0e19\u0e2d\u0e31\u0e07\u0e04\u0e32\u0e23"\.. "\u0e27\u0e31\u0e19\u0e1e\u0e38\u0e18"\.. "\u0e27\u0e31\u0e19\u0e1e\u0e24\u0e2b\u0e31\u0e2a\u0e1a\u0e14\u0e35"\.. "\u0e27\u0e31\u0e19\u0e28\u0e38\u0e01\u0e23\u0e4c"\.. "\u0e27\u0e31\u0e19\u0e40\u0e2a\u0e32\u0e23\u0e4c"].. ::msgcat::mcset th MONTHS_ABBREV [list \.. "\u0e21.\u0e04."\.. "\u0e01.\u0e1e."\.. "\u0e21\u0e35.\u0e04."\.. "\u0e40\u0e21.\u0e22."\.. "\u0e1e.\u0e04."\.. "\u0e21\u0
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1183
                                                                                                                                                                                                                                                          Entropy (8bit):4.390397293529625
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR83ZVUflVdq4qTr6dyX59508THHCh5LbQgWiNv9KvWIn:43PXTtbTngLhWiJGWIn
                                                                                                                                                                                                                                                          MD5:017F0F989BD5DBBF25E7C797CE09C45C
                                                                                                                                                                                                                                                          SHA1:162922DBD55A31A74410375A36EE7BC50E092BDD
                                                                                                                                                                                                                                                          SHA-256:4B85B345D6C43F7257C6849A60A492397FD5FD9D82DF3A2252189D7A1ECCBB64
                                                                                                                                                                                                                                                          SHA-512:73B6CF395753D863330687404E8A584CB08B81A8CC456DCE7BB49C4EA15EA19E45E3CC1E1367E10915DE14AC6258383289BCFEF55AD2768A50889DF390D37EF9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset tr DAYS_OF_WEEK_ABBREV [list \.. "Paz"\.. "Pzt"\.. "Sal"\.. "\u00c7ar"\.. "Per"\.. "Cum"\.. "Cmt"].. ::msgcat::mcset tr DAYS_OF_WEEK_FULL [list \.. "Pazar"\.. "Pazartesi"\.. "Sal\u0131"\.. "\u00c7ar\u015famba"\.. "Per\u015fembe"\.. "Cuma"\.. "Cumartesi"].. ::msgcat::mcset tr MONTHS_ABBREV [list \.. "Oca"\.. "\u015eub"\.. "Mar"\.. "Nis"\.. "May"\.. "Haz"\.. "Tem"\.. "A\u011fu"\.. "Eyl"\.. "Eki"\.. "Kas"\.. "Ara"\.. ""].. ::msgcat::mcset tr MONTHS_FULL [list \.. "Ocak"\.. "\u015eubat"\.. "Mart"\.. "Nisan"\.. "May\u0131s"\.. "Haziran"\.. "Temmuz"\.. "A\u011fustos"\.. "Eyl\u00fcl"\.. "Ekim"\.. "Kas\u0131m"\.. "Aral\u
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2165
                                                                                                                                                                                                                                                          Entropy (8bit):4.289021158621493
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:436yILgoQjQPxUIkgPDRQnQ0vVQbC1iQwweIgWQDIoZI7QDI3QbI87IVQnIzQ7mh:2AzUe3EhV8CYgrbH7z3fLVTzgn5jyX7p
                                                                                                                                                                                                                                                          MD5:323BD95809A44B0BADC71AD36E5F095B
                                                                                                                                                                                                                                                          SHA1:44F6016873CA955D27545C56CCD24BDB06A83C43
                                                                                                                                                                                                                                                          SHA-256:7093DA7E39CEB6D3F51EB6CF1CCA2D7F3680ED7B8FE4A5F0CECEEF6BEB21AC77
                                                                                                                                                                                                                                                          SHA-512:DB16E0E2D17CE47673DE781A7171944C14CC550FB8EB0920C05B979E4D067E36DF0B59B8BFA81F82D8FCE1FFDDAAD2755E68BFE5BC0DBB11E8716A4D18BA5F7E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset uk DAYS_OF_WEEK_ABBREV [list \.. "\u043d\u0434"\.. "\u043f\u043d"\.. "\u0432\u0442"\.. "\u0441\u0440"\.. "\u0447\u0442"\.. "\u043f\u0442"\.. "\u0441\u0431"].. ::msgcat::mcset uk DAYS_OF_WEEK_FULL [list \.. "\u043d\u0435\u0434\u0456\u043b\u044f"\.. "\u043f\u043e\u043d\u0435\u0434\u0456\u043b\u043e\u043a"\.. "\u0432\u0456\u0432\u0442\u043e\u0440\u043e\u043a"\.. "\u0441\u0435\u0440\u0435\u0434\u0430"\.. "\u0447\u0435\u0442\u0432\u0435\u0440"\.. "\u043f'\u044f\u0442\u043d\u0438\u0446\u044f"\.. "\u0441\u0443\u0431\u043e\u0442\u0430"].. ::msgcat::mcset uk MONTHS_ABBREV [list \.. "\u0441\u0456\u0447"\.. "\u043b\u044e\u0442"\.. "\u0431\u0435\u0440"\.. "\u043a\u0432\u0456\u0442"\.. "\u0442\u0440\u0430\u0432"\.. "\u0447\u0435\u0440\u0432"\.. "\u043b
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1471
                                                                                                                                                                                                                                                          Entropy (8bit):4.44729506678271
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4aR836DNjYTP55YAUy2tJ9kyzW68IFYHMBSW1K1pvhv1O:43dbYJyC8ySgI1dV1O
                                                                                                                                                                                                                                                          MD5:C127F54C462917D3B3EEF5F29F612138
                                                                                                                                                                                                                                                          SHA1:B1D9A67F856D93F98524C6372B352EA0DE1B9CD3
                                                                                                                                                                                                                                                          SHA-256:E9B7AECD456F1D2288604C982B5DED0DCF71DCA968C0B0EAFF4CA16CC3B73EC2
                                                                                                                                                                                                                                                          SHA-512:0B0F132F10580751258D37E070338C3B39DF57FDECDB9D0AFA67E90D6766DDCB4D711876E551ED759D177F1B8F4E9E1DD8F7899F7CB57F8039F55EC4C2984E87
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset vi DAYS_OF_WEEK_ABBREV [list \.. "Th 2"\.. "Th 3"\.. "Th 4"\.. "Th 5"\.. "Th 6"\.. "Th 7"\.. "CN"].. ::msgcat::mcset vi DAYS_OF_WEEK_FULL [list \.. "Th\u01b0\u0301 hai"\.. "Th\u01b0\u0301 ba"\.. "Th\u01b0\u0301 t\u01b0"\.. "Th\u01b0\u0301 n\u0103m"\.. "Th\u01b0\u0301 s\u00e1u"\.. "Th\u01b0\u0301 ba\u0309y"\.. "Chu\u0309 nh\u00e2\u0323t"].. ::msgcat::mcset vi MONTHS_ABBREV [list \.. "Thg 1"\.. "Thg 2"\.. "Thg 3"\.. "Thg 4"\.. "Thg 5"\.. "Thg 6"\.. "Thg 7"\.. "Thg 8"\.. "Thg 9"\.. "Thg 10"\.. "Thg 11"\.. "Thg 12"\.. ""].. ::msgcat::mcset vi MONTHS_FULL [list \.. "Th\u00e1ng m\u00f4\u0323t"\.. "Th\u00e1ng hai"\.. "Th\u00e1ng ba"\.. "Th\u00e1ng t\u01b0"\.. "Th\u00e
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (1598), with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3385
                                                                                                                                                                                                                                                          Entropy (8bit):4.5164095151631125
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:43qrY2BBT7uxDqwPqDa8c3FLbYmhyvMDKbW0YGLuoEyke2gdr:2yPTKdo
                                                                                                                                                                                                                                                          MD5:2F356DE14D48B1091DEAA32D20C38D96
                                                                                                                                                                                                                                                          SHA1:4AB78D47A73290000955A7C1DFDF7106093F69FD
                                                                                                                                                                                                                                                          SHA-256:EB247F5184A59414D3DF7E3ECA51F5998C248CFB27D2C02E62A7A30AB35197A7
                                                                                                                                                                                                                                                          SHA-512:602410830018B455C68AE2EBDD83BA561CF59DA5898E00C80CE7EF619912E591EB38B4C8FE8D9B1F024E7105B0C4D2D326FC855F31E79C1B954429B947DFFBB1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh DAYS_OF_WEEK_ABBREV [list \.. "\u661f\u671f\u65e5"\.. "\u661f\u671f\u4e00"\.. "\u661f\u671f\u4e8c"\.. "\u661f\u671f\u4e09"\.. "\u661f\u671f\u56db"\.. "\u661f\u671f\u4e94"\.. "\u661f\u671f\u516d"].. ::msgcat::mcset zh DAYS_OF_WEEK_FULL [list \.. "\u661f\u671f\u65e5"\.. "\u661f\u671f\u4e00"\.. "\u661f\u671f\u4e8c"\.. "\u661f\u671f\u4e09"\.. "\u661f\u671f\u56db"\.. "\u661f\u671f\u4e94"\.. "\u661f\u671f\u516d"].. ::msgcat::mcset zh MONTHS_ABBREV [list \.. "\u4e00\u6708"\.. "\u4e8c\u6708"\.. "\u4e09\u6708"\.. "\u56db\u6708"\.. "\u4e94\u6708"\.. "\u516d\u6708"\.. "\u4e03\u6708"\.. "\u516b\u6708"\.. "\u4e5d\u6708"\.. "\u5341\u6708"\.. "\u5341\u4e00\u6708"\.. "\u5341\u4e8c\u6708"\.. ""].. ::msgcat::m
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):319
                                                                                                                                                                                                                                                          Entropy (8bit):5.167825099880243
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoX5YBoHJ+3vtfNrsoHJ+3v6MYBoXa+3vYq9vn:4EnLB383U5YMJ+3vtN3J+3v6LcL3vYqN
                                                                                                                                                                                                                                                          MD5:9FCDC2E80E13984D434E3CC91E1ED14C
                                                                                                                                                                                                                                                          SHA1:710D9EE2A71021F4AB609886138EED43C1380ACD
                                                                                                                                                                                                                                                          SHA-256:4C8A855700FEFE8EE21B08030FF4159D8011AE50353F063229C42DE6292475CF
                                                                                                                                                                                                                                                          SHA-512:D899A1F58DF1051BB2C2C4AC859C52A2D19B1593C37022A29439B37A8057ADC3941F3564E2E1D9CEB72AE123A4E12E24C3736343AA3A5EC8749AB5AEBBF65085
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh_CN DATE_FORMAT "%Y-%m-%e".. ::msgcat::mcset zh_CN TIME_FORMAT "%k:%M:%S".. ::msgcat::mcset zh_CN TIME_FORMAT_12 "%P%I\u65f6%M\u5206%S\u79d2".. ::msgcat::mcset zh_CN DATE_TIME_FORMAT "%Y-%m-%e %k:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):780
                                                                                                                                                                                                                                                          Entropy (8bit):4.716025632367214
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:4EnLB383HmSBBHZovDh4ToC4qU3WwVW3v6P3v3WwSn:4aR83Hxo14u3Ww+viv3WwS
                                                                                                                                                                                                                                                          MD5:CFDA7B6463305FA15DBBA72D725A1876
                                                                                                                                                                                                                                                          SHA1:2BF885073FBAF4A38B7AFDA76CA391F195A5A362
                                                                                                                                                                                                                                                          SHA-256:7E1C5BD9EC1A17BB851B0DCABD0DFA9FF9D64B89603D9D3FBEAAC609172346AE
                                                                                                                                                                                                                                                          SHA-512:55F974C706933ECE0575A33C381D9B370B8A408C5C5514C805EC04C8B0CA5BAFAA47267DA98E1805B478A9589FFB7549D79002B2A7AF387049011D78DD7605B6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh_HK DAYS_OF_WEEK_ABBREV [list \.. "\u65e5"\.. "\u4e00"\.. "\u4e8c"\.. "\u4e09"\.. "\u56db"\.. "\u4e94"\.. "\u516d"].. ::msgcat::mcset zh_HK MONTHS_ABBREV [list \.. "1\u6708"\.. "2\u6708"\.. "3\u6708"\.. "4\u6708"\.. "5\u6708"\.. "6\u6708"\.. "7\u6708"\.. "8\u6708"\.. "9\u6708"\.. "10\u6708"\.. "11\u6708"\.. "12\u6708"\.. ""].. ::msgcat::mcset zh_HK DATE_FORMAT "%Y\u5e74%m\u6708%e\u65e5".. ::msgcat::mcset zh_HK TIME_FORMAT_12 "%P%I:%M:%S".. ::msgcat::mcset zh_HK DATE_TIME_FORMAT "%Y\u5e74%m\u6708%e\u65e5 %P%I:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):347
                                                                                                                                                                                                                                                          Entropy (8bit):5.062880051437783
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSyEtJLl73oo6d3/xoOpEoPpFocMohX3v6Zwoh+3v6fxvn:4EnLB383J53v6O3vCn
                                                                                                                                                                                                                                                          MD5:3218F8E6BEDD534277DE0849C423158E
                                                                                                                                                                                                                                                          SHA1:10C006446A10406A5644C4033665E877EBF72AF7
                                                                                                                                                                                                                                                          SHA-256:500546B3211D454659D845B4AB9AEF226125100DF40407C49530DE17CDD4363F
                                                                                                                                                                                                                                                          SHA-512:3142893DA85BA8F83A5B6851B313B5F5FF80D2B989C1AE015665EE70373249B44EFB4FF7C621F1D8F37AC6019EF5E8D6D21C76C48998C3D9072F9C5060AA8813
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh_SG AM "\u4e0a\u5348".. ::msgcat::mcset zh_SG PM "\u4e2d\u5348".. ::msgcat::mcset zh_SG DATE_FORMAT "%d %B %Y".. ::msgcat::mcset zh_SG TIME_FORMAT_12 "%P %I:%M:%S".. ::msgcat::mcset zh_SG DATE_TIME_FORMAT "%d %B %Y %P %I:%M:%S %z"..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1080
                                                                                                                                                                                                                                                          Entropy (8bit):4.187497782275587
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862D7nmdHh5Cv6/lHY8SOSuvvzXipFSgSO5vW5aKmvbsF6VWsXN87QBWcAFy:5veSvKlHYXNujXipFSjKRKXiWsXCGWJy
                                                                                                                                                                                                                                                          MD5:E8D3DF11CE0E7575485573FA07D955D5
                                                                                                                                                                                                                                                          SHA1:3B2C00C85B6C0BFAA1C676C970D6DF1B4BDC3D4A
                                                                                                                                                                                                                                                          SHA-256:E6874647561CE1C5FD1F650C9B167F77AC5B24FD2026046399A9043CF998E5C4
                                                                                                                                                                                                                                                          SHA-512:E2968BE847622CF243C0E498436FD21BDC2E1DF0FD8D694F2C70569D17CE896CDE4968BB8ABDEF9F687439E4EA2D955AE87D6C15E81F881EE1413416A90765D4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Algiers) {.. {-9223372036854775808 732 0 LMT}.. {-2486592732 561 0 PMT}.. {-1855958961 0 0 WET}.. {-1689814800 3600 1 WEST}.. {-1680397200 0 0 WET}.. {-1665363600 3600 1 WEST}.. {-1648342800 0 0 WET}.. {-1635123600 3600 1 WEST}.. {-1616893200 0 0 WET}.. {-1604278800 3600 1 WEST}.. {-1585443600 0 0 WET}.. {-1574038800 3600 1 WEST}.. {-1552266000 0 0 WET}.. {-1539997200 3600 1 WEST}.. {-1531443600 0 0 WET}.. {-956365200 3600 1 WEST}.. {-950486400 0 0 WET}.. {-942012000 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796262400 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766630800 3600 0 CET}.. {-733280400 0 0 WET}.. {-439430400 3600 0 CET}.. {-212029200 0 0 WET}.. {41468400 3600 1 WEST}.. {54774000 0 0 WET}.. {231724800 3600 1 WEST}.. {246240000 3600 0 CET}.. {259545600 7200 1 CEST}.. {275274000 3600 0 CET}.. {309740400 0 0 WET}.. {
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.801054282631739
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2DcjEUEH+DcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2DGs+DR
                                                                                                                                                                                                                                                          MD5:A543BDEB3771017421FB75231F0004F2
                                                                                                                                                                                                                                                          SHA1:D682C58C27562FF3ABAB8EDE8EB6EA754DA7C02E
                                                                                                                                                                                                                                                          SHA-256:064EB7F9A1FA05A317C6BDCA6B102BC1560D980758F9E4DDB010C9E7DC068ECB
                                                                                                                                                                                                                                                          SHA-512:44848D60EDC79AF784A819714C0D9F62DCCB6329B47F25D74AB8C174BF9EC3F783C66FEB27F588A93FABA9BECAF076F453D6D797CE4F28461F7AE69440EA54C7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Asmara) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.806258322241929
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2DcjAWDcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2D8DkOn
                                                                                                                                                                                                                                                          MD5:1B5E386E7A2F10D9385DE4C5683EBB85
                                                                                                                                                                                                                                                          SHA1:FECBA599C37493D2E0AEE8E21BAB40BF8E8DC82A
                                                                                                                                                                                                                                                          SHA-256:76939852A98EA7BF156D0AC18B434CC610DAF5232322C0FBB066CD52C5B72AF7
                                                                                                                                                                                                                                                          SHA-512:B36FABFCDB2187A3A4A211C8E033D96C91E3C4D47907D284E10786555562C82231566033EAB4753EF1E48DF1233CFC8C6C0FB3CA50748BE0B2554A972A88FBA0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Asmera) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.883634030944169
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcxAQDcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2DwNDBS
                                                                                                                                                                                                                                                          MD5:6B9BB5B37C41AA727E31BF03483DC1CA
                                                                                                                                                                                                                                                          SHA1:CB3BBA37B063EA4A54CD15C6E30C14D8CA30D3C0
                                                                                                                                                                                                                                                          SHA-256:F6D1BA22115A6565B6D6ABEB578F001DDB41E673C422C8EA70D0DF77B24115F6
                                                                                                                                                                                                                                                          SHA-512:23DB3E298FDEB165FD85D99E03C00835B584984B814AF7F54A9CDD4A9F93E16B0C58342D319129F46CF8EC36F93DE5EA51B492CA4CABDAB75D84709BC6C26119
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Bamako) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):178
                                                                                                                                                                                                                                                          Entropy (8bit):4.882974805254803
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2Dcx2m/2DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2Dw/2D4yn
                                                                                                                                                                                                                                                          MD5:92FF9E5835C0C80F358BFE69120660A0
                                                                                                                                                                                                                                                          SHA1:724758B43BD79DD8A29B02BE6910D492924F8280
                                                                                                                                                                                                                                                          SHA-256:5047A507D22B68C9349EB6A48C41C80DB4C69F98F99C6574059DEA87178E36C0
                                                                                                                                                                                                                                                          SHA-512:6FCB709DB4AC19191FECE1E8BAC55E77F265B5AF89F7A3565F06BFAF0BEE12E3EAF2F52CA09C68D75C358C25A31867505CE8AD75D7386DCD15F4BE1CE61272CD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Bangui) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.888193386512119
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2Dcx79FHp4DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2Dw7J4c
                                                                                                                                                                                                                                                          MD5:46E5703CF284E44E15E5872DF075FCBC
                                                                                                                                                                                                                                                          SHA1:EA4BFA6D568DFA877F72302ADA21ECC2840D9FD5
                                                                                                                                                                                                                                                          SHA-256:77E610A02CCECE3045B09D07A9BE6100F5AA9C3C2AEB543535C9AE941194F4E4
                                                                                                                                                                                                                                                          SHA-512:1454467FE63E97DFA4DE66E359F68B2D80C92CDE59FC15A4BE513629FFD154D2281EADF3FC78F7AFDDF5A5896195F3A69E66697A659BBB1A0EAFD3E1DA6565EC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Banjul) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):176
                                                                                                                                                                                                                                                          Entropy (8bit):4.847843768169462
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2Dc5iDMXGm2OHGVkeoHsdSawwF6hSVPVFwy:SlSWB9eg/2D4uDm2OHCkeoH1awwFMmMy
                                                                                                                                                                                                                                                          MD5:7E710C939B9CC0C1AC1ECF4239B543C5
                                                                                                                                                                                                                                                          SHA1:429CC87086FB22727815ED05AC6472333FF06013
                                                                                                                                                                                                                                                          SHA-256:2A870E534DE67713C27F2F3B9BF26FA7498C240CF633988CE76DBDAC5B69214D
                                                                                                                                                                                                                                                          SHA-512:70D9365C31C43A95211FC20E9290B24D356FFEFA935B8829CE32831026A196DECDD12226097F6DA3B4B919E137AA0181714680CDBB72B00C130A87E3A4735004
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Bissau) {.. {-9223372036854775808 -3740 0 LMT}.. {-1830380400 -3600 0 -01}.. {157770000 0 0 GMT}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):183
                                                                                                                                                                                                                                                          Entropy (8bit):4.904342145830274
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2Dc8ycXp75h4DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2DAmp1hs
                                                                                                                                                                                                                                                          MD5:7AD3749D7047855CB9B9EC9696015402
                                                                                                                                                                                                                                                          SHA1:F792359AD9EEC2ABD98DAFA6661C1E57BAB89EBE
                                                                                                                                                                                                                                                          SHA-256:8F700409B8EEE33ACE5F050414971FFEE0270949842E58E9299BB5CD6CCF34DE
                                                                                                                                                                                                                                                          SHA-512:681C1B318746C587DEBA6E109D1D5A99D1F3E28FE46C24F36B69D533D884FDDC6EA35BB31A475575D683B73BF129FED761523EC9285F2FF1E4CACA2C54C046C5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Blantyre) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):183
                                                                                                                                                                                                                                                          Entropy (8bit):4.901235831565769
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DciE0TMJZp4DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2D4qGp4D1
                                                                                                                                                                                                                                                          MD5:7028268EE88250AC40547A3FDBBFC67C
                                                                                                                                                                                                                                                          SHA1:5006D499CD1D1CB93EB3DA0EC279F76B7123DAA6
                                                                                                                                                                                                                                                          SHA-256:596DB2D64CDD6250642CB65514D5BCB52F3E3EA83F50D8915D9D4FDEA008F440
                                                                                                                                                                                                                                                          SHA-512:D623C69FE8A6050E77FB819C2F5FAEE35D5034182B1D30A409C17208155501656133E774E402875537335F8201E4734A0B5D327712CBF623AC330F1014D9025B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Brazzaville) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.947752840781864
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2DclbDcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2DkbDEi
                                                                                                                                                                                                                                                          MD5:0EBC2D8F0BD1A32C21070F9397EAC9E2
                                                                                                                                                                                                                                                          SHA1:95AAA97427265635784E8AC624CA863DB9F1475D
                                                                                                                                                                                                                                                          SHA-256:9A15867255B43A954CA60DA11660F157553AAB6A15C50ACD49D182276E0CF4CC
                                                                                                                                                                                                                                                          SHA-512:4CD2E14F84C58E955742637A51D99DB9493972671A2B5D801EBD9D901D4903654E374C59BF010C70071D33FA17788358F78004201A787CCA2AD714D670393488
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Bujumbura) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8472
                                                                                                                                                                                                                                                          Entropy (8bit):3.7175261751408253
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:fLg1GbJFp3gHRQVy7DPUUQkiHMC/+56DEXirCM6Qvrs/PDGgtB9vJzi3kp/o:fWGbJv3yRQaD8UQN/ZiFp/3DGt
                                                                                                                                                                                                                                                          MD5:53F7730B6725D3E41CAE8DB4C205BF67
                                                                                                                                                                                                                                                          SHA1:E09588FC1C2E909F9108866347ACBD0F7495663E
                                                                                                                                                                                                                                                          SHA-256:A7985E0D2273B26BFFA18EE4D87F10FB1AFB9A0F316505919FE99A24909F5E3D
                                                                                                                                                                                                                                                          SHA-512:E7D8AC7499E512FF9364DC870D4336BCE6B9F1A4BC5654AA945C69540A65E8D2B03A592DFE054FFA455CBEBEA362587B9E63B142425F7F9C7ABCE83E57BB56D7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Cairo) {.. {-9223372036854775808 7509 0 LMT}.. {-2185409109 7200 0 EET}.. {-929844000 10800 1 EEST}.. {-923108400 7200 0 EET}.. {-906170400 10800 1 EEST}.. {-892868400 7200 0 EET}.. {-875844000 10800 1 EEST}.. {-857790000 7200 0 EET}.. {-844308000 10800 1 EEST}.. {-825822000 7200 0 EET}.. {-812685600 10800 1 EEST}.. {-794199600 7200 0 EET}.. {-779853600 10800 1 EEST}.. {-762663600 7200 0 EET}.. {-399088800 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336790800 10800 1 EEST}.. {-323654400 7200 0 EET}.. {-305168400 10800 1 EEST}.. {-292032000 7200 0 EET}.. {-273632400 10800 1 EEST}.. {-260496000 7200 0 EET}.. {-242096400 10800 1 EEST}.. {-228960000 7200 0 EET}.. {-210560400 10800 1 EEST}.. {-197424000 7200 0 EET}.. {-178938000 10800 1 EEST}.. {-165801600 7200 0 EET}.. {-147402000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5532
                                                                                                                                                                                                                                                          Entropy (8bit):3.5390967530717847
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:zE+CJZtmaG6/eszBrlJs5M2kyUxCHvyKbGKCVpsvA:7MZSszBrl1iJCbR
                                                                                                                                                                                                                                                          MD5:1F5D7CCD63B55ED651CDDC39DA5CFD2F
                                                                                                                                                                                                                                                          SHA1:7525B6DB7ED59D9639CB7BE0D5D4A6941CBC0805
                                                                                                                                                                                                                                                          SHA-256:02C4452923405B4662D3A38DD6D79E24AC206F4B3FCC513D989F364B6F1778C2
                                                                                                                                                                                                                                                          SHA-512:F6203CB05861AFC61BCED3B4F059BFAB1C53D539838EB957C549824E761E6175F06DA56168AC66A1FEC28BB96442F6F56A3C723F35AEC69DFC9160AB0D5559C8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Casablanca) {.. {-9223372036854775808 -1820 0 LMT}.. {-1773012580 0 0 +00}.. {-956361600 3600 1 +00}.. {-950490000 0 0 +00}.. {-942019200 3600 1 +00}.. {-761187600 0 0 +00}.. {-617241600 3600 1 +00}.. {-605149200 0 0 +00}.. {-81432000 3600 1 +00}.. {-71110800 0 0 +00}.. {141264000 3600 1 +00}.. {147222000 0 0 +00}.. {199756800 3600 1 +00}.. {207702000 0 0 +00}.. {231292800 3600 1 +00}.. {244249200 0 0 +00}.. {265507200 3600 1 +00}.. {271033200 0 0 +00}.. {448243200 3600 0 +01}.. {504918000 0 0 +00}.. {1212278400 3600 1 +00}.. {1220223600 0 0 +00}.. {1243814400 3600 1 +00}.. {1250809200 0 0 +00}.. {1272758400 3600 1 +00}.. {1281222000 0 0 +00}.. {1301788800 3600 1 +00}.. {1312066800 0 0 +00}.. {1335664800 3600 1 +00}.. {1342749600 0 0 +00}.. {1345428000 3600 1 +00}.. {1348970400 0 0 +00}.. {1367114400 3600 1 +00}.. {13731
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7536
                                                                                                                                                                                                                                                          Entropy (8bit):3.8315604186920704
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:TzLdXKy9f4elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxo:TdayR41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:30155093248C4F7E45EF7C0132D2B2AB
                                                                                                                                                                                                                                                          SHA1:FAD100CC49F0CB0910BDE39B43295A47512E1BE6
                                                                                                                                                                                                                                                          SHA-256:8827F7311EDE69A9679BDF2B7418DBF350A2FC8F973E8B1E1E4390D4D5C6D2E8
                                                                                                                                                                                                                                                          SHA-512:469A24AF0C2A4A40CB2488C3E21BB9BBDE057F876EACA08A31FC6F22845063D917A0A4AE96680401E45792DE534EE3A305F137A93C4DF879B4602510D881270E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Ceuta) {.. {-9223372036854775808 -1276 0 LMT}.. {-2177452800 0 0 WET}.. {-1630112400 3600 1 WEST}.. {-1616810400 0 0 WET}.. {-1451692800 0 0 WET}.. {-1442451600 3600 1 WEST}.. {-1427673600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364774400 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333324800 0 0 WET}.. {-1316390400 3600 1 WEST}.. {-1301270400 0 0 WET}.. {-1293840000 0 0 WET}.. {-94694400 0 0 WET}.. {-81432000 3600 1 WEST}.. {-71110800 0 0 WET}.. {141264000 3600 1 WEST}.. {147222000 0 0 WET}.. {199756800 3600 1 WEST}.. {207702000 0 0 WET}.. {231292800 3600 1 WEST}.. {244249200 0 0 WET}.. {265507200 3600 1 WEST}.. {271033200 0 0 WET}.. {448243200 3600 0 CET}.. {504918000 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.88110192592456
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcmMM1+DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2DCM1+c
                                                                                                                                                                                                                                                          MD5:8CDD2EEB7E0EC816F3EC051350FEBF13
                                                                                                                                                                                                                                                          SHA1:37F3A149B4A01DFA2EAB42A28C810BE66AAB7C52
                                                                                                                                                                                                                                                          SHA-256:3176C99FC45337CBCE0CD516DE4B02B8BAA47D00E84F698122A2ADD57797984E
                                                                                                                                                                                                                                                          SHA-512:5A90B6DB45EDAD7734D596FB81FD1959A433F57E71D2212E1DCBD6A12F3FD1FE747FA363C4C787A4D3023F542553C1E2C9CF4F61E28F1BB13042E4AFE3D0FF31
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Conakry) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):183
                                                                                                                                                                                                                                                          Entropy (8bit):4.856992353568779
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcXXMFBx/2DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2DKXEBn
                                                                                                                                                                                                                                                          MD5:946D3B52F915445DBB8EE8BF67F4EFAB
                                                                                                                                                                                                                                                          SHA1:18345968B95E886CA72634D49F2B38F9B29BA629
                                                                                                                                                                                                                                                          SHA-256:D50F9732757B284BAC75526F2CFA585DF7F6974160827AFB0FF66124C7CFD361
                                                                                                                                                                                                                                                          SHA-512:00B531D1352CF35045EE25C777C7FEA17294E9861E68CE2DE0D9884C05EBDEA84D5F4F0E8B5605721295E25C259979446B7DB76525A633C7D2FA35B38962CF43
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Dakar) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):191
                                                                                                                                                                                                                                                          Entropy (8bit):4.8447607449193075
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2Dc8bEH+DcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2DJbVDR
                                                                                                                                                                                                                                                          MD5:7A819572758BC60F4085DF28F1DD1C01
                                                                                                                                                                                                                                                          SHA1:0A5BA34EBFBA5A8E8B896713BA527781FC90FF01
                                                                                                                                                                                                                                                          SHA-256:AB69948637416219A3D458777990FA4568BEBC89388884BBF129C0E1370A560B
                                                                                                                                                                                                                                                          SHA-512:C03E785D1E85292056BB0BDD8DF8326C5DFEB6070AB1C071E1032D14EA69C9DEBC57B2CC7852E35D31652187126CCF0009A6A5C32F9DBB75D56C705535DF05CC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Dar_es_Salaam) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):186
                                                                                                                                                                                                                                                          Entropy (8bit):4.829357904445218
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2DcRHKQ1BQDcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2DOrkDR
                                                                                                                                                                                                                                                          MD5:7981499F9430DC1636C9F834273E0B91
                                                                                                                                                                                                                                                          SHA1:1D63F8578420D56E4A5D9D0881FBEC015421E416
                                                                                                                                                                                                                                                          SHA-256:E7F7560CCD65D53C446ADAE7128A74D37E17DD0B907A2F2FD85322FB8707B497
                                                                                                                                                                                                                                                          SHA-512:3C3F7D78E9A0DE6E2950E1C305EA2DBC986754AE9FB10AC410685F30C39EC235F6F221393099C012E62EE5A7B4F1BED67C96B7B81E90BBA064BA9FE685FE4050
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Djibouti) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):178
                                                                                                                                                                                                                                                          Entropy (8bit):4.850101792457859
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DcnKe2DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2Dml2D4yn
                                                                                                                                                                                                                                                          MD5:44881E75AC32FA95FF6143066EF01B90
                                                                                                                                                                                                                                                          SHA1:A221619B4CDE8BE6A181E1F3869EAB665F2E98B8
                                                                                                                                                                                                                                                          SHA-256:FCF2DAD148F4D2951320EA99730C56D5EB43D505F37416BE4BAD265CE2902706
                                                                                                                                                                                                                                                          SHA-512:4FA67A5F84758366189F0FC4A7FA6C820BA083E1C56EA95D25D21A367F25F76261B7EB5631DFFEB20E095CFD64E770338773F76BD50D4CF6AE29AD3EDFCEC408
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Douala) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5235
                                                                                                                                                                                                                                                          Entropy (8bit):3.544982035908217
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:+eCJZtmaG6/eszBrlJs5M2kyUxCHvyKbGKCVpsvA:+eqZSszBrl1iJCbR
                                                                                                                                                                                                                                                          MD5:2D1BEC251404EFD45E344BD7145457C8
                                                                                                                                                                                                                                                          SHA1:968F3EEF22410AB812A9938A84D00CDA21364024
                                                                                                                                                                                                                                                          SHA-256:79FC1181C194BE52C5E4D147FC06E864C6DC0A8FAF308CD767322AFFB4275DDC
                                                                                                                                                                                                                                                          SHA-512:D29B1A662CA36E708C8B2A3887204CE9642BE3DEA91499F4EC7C1E0C0268D49DF146621A1A1AE5A262FB84B7B7D318BA8E38A7211C838D80ED0357B0810E90C0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/El_Aaiun) {.. {-9223372036854775808 -3168 0 LMT}.. {-1136070432 -3600 0 -01}.. {198291600 0 0 +00}.. {199756800 3600 1 +00}.. {207702000 0 0 +00}.. {231292800 3600 1 +00}.. {244249200 0 0 +00}.. {265507200 3600 1 +00}.. {271033200 0 0 +00}.. {1212278400 3600 1 +00}.. {1220223600 0 0 +00}.. {1243814400 3600 1 +00}.. {1250809200 0 0 +00}.. {1272758400 3600 1 +00}.. {1281222000 0 0 +00}.. {1301788800 3600 1 +00}.. {1312066800 0 0 +00}.. {1335664800 3600 1 +00}.. {1342749600 0 0 +00}.. {1345428000 3600 1 +00}.. {1348970400 0 0 +00}.. {1367114400 3600 1 +00}.. {1373162400 0 0 +00}.. {1376100000 3600 1 +00}.. {1382839200 0 0 +00}.. {1396144800 3600 1 +00}.. {1403920800 0 0 +00}.. {1406944800 3600 1 +00}.. {1414288800 0 0 +00}.. {1427594400 3600 1 +00}.. {1434247200 0 0 +00}.. {1437271200 3600 1 +00}.. {1445738400 0 0 +00}.. {1
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):186
                                                                                                                                                                                                                                                          Entropy (8bit):4.866631090752554
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2Dcu5sp4DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2Dk4DBS
                                                                                                                                                                                                                                                          MD5:6C115220CF951FC2EE3C299F86935B6D
                                                                                                                                                                                                                                                          SHA1:A1CAB8C710BF20553AF45343118C1726CFE922B7
                                                                                                                                                                                                                                                          SHA-256:BC53A4D489F48F14C594C4B0E52079B34E043A5751BBC7DF254A560352243575
                                                                                                                                                                                                                                                          SHA-512:E87A4FD145B645DF034182CAD7F9D2BE5B2D9F3A17B6A9B6C84A0B3E846D92EC4C69DF2E85129B7A1AFBC0CCAAC8E3B1D47EB09F0900A82B908E9F6BF63B9736
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Freetown) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):183
                                                                                                                                                                                                                                                          Entropy (8bit):4.899477454245453
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2DcHK0o/4DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2DAV+4Dt
                                                                                                                                                                                                                                                          MD5:07222D8ED83CDC456B4D5D84C4BDE320
                                                                                                                                                                                                                                                          SHA1:2C657F461FA3F48D56C791AFE4AB7D2EAF45AF60
                                                                                                                                                                                                                                                          SHA-256:653AF88955C4418D973E2F8681A99552EB7BE95BCA64C736072F488462F7B373
                                                                                                                                                                                                                                                          SHA-512:3016D0636F401BD88BCD460F6A61782E7E8A2C32CE4ECB904C711DF414038A5818F0CA3D7FC671C5ABCE70647FC674A2EF9081C5289EBFD184B44885902E007A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Gaborone) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):181
                                                                                                                                                                                                                                                          Entropy (8bit):4.884642061266759
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2Dc0B5h4DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2Dlfh4Dt
                                                                                                                                                                                                                                                          MD5:8666DABE8D196ACD94A9691C592FAF4E
                                                                                                                                                                                                                                                          SHA1:9F7EE009DCEAACA79C6EAA6FC73015D595467919
                                                                                                                                                                                                                                                          SHA-256:06B82C524585192E0E8FC69DCC1CF86183A8C5EF404645DC413FCF3F8C16B0AB
                                                                                                                                                                                                                                                          SHA-512:AAA32FD1B01BFECDD0D1C9C1DF1163374DAFE094C75720EA4095C34F7EAE7DCB594D1A7F6A2A90FB43FF01020F7AEB48E92496E0EE2D039AF23076CD369DD2A7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Harare) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):309
                                                                                                                                                                                                                                                          Entropy (8bit):4.695542624694403
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2DWbzDm2OHePoHvmmXsd//HF2d7d6VcF2d6KsYov:MB862DW7mdHePCvmmcZvF0cVcF/KsFv
                                                                                                                                                                                                                                                          MD5:F0E153FC9B978E30742ABC025CA45E02
                                                                                                                                                                                                                                                          SHA1:73D96F3188190DAC2453E6F18A1C683CECB9CDE3
                                                                                                                                                                                                                                                          SHA-256:5EEF6475E1312051037FCAE3354E32DC0910BE7A5116B71F8CCBE1CCA08D3F1C
                                                                                                                                                                                                                                                          SHA-512:E66F4B5FF18BAAD53AFB1ED36A0827115C793075A61F794F26F32BC9F6799DF816A1F817BEB0C0BC938F89E6F5BFBE1AB4F504F1AF518764103FB287746552C7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Johannesburg) {.. {-9223372036854775808 6720 0 LMT}.. {-2458173120 5400 0 SAST}.. {-2109288600 7200 0 SAST}.. {-860976000 10800 1 SAST}.. {-845254800 7200 0 SAST}.. {-829526400 10800 1 SAST}.. {-813805200 7200 0 SAST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1127
                                                                                                                                                                                                                                                          Entropy (8bit):4.027824722230131
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5mesdOkMV0GbMSHMzNy8MXLwM0JXMfCsMzaMq0QM3W50dM44R8M1XMreM7p0z8M5:5YMV04MSHMzNxMbwM0JXMfCsMzaMq0QJ
                                                                                                                                                                                                                                                          MD5:32EC0589260D9D4BCC85FE91E6F04D00
                                                                                                                                                                                                                                                          SHA1:BAA269852C4AC6B89EA7941E7A75A007E0CF9EDF
                                                                                                                                                                                                                                                          SHA-256:F2646E15488ABF2E960759CEFE5705416E71DA71BB8407B26196244FD1A3394F
                                                                                                                                                                                                                                                          SHA-512:4F485453BE1D186ADBE0908852475C63C57BA498091C222EFFB9A5FEA2DB7F55E1BB2DBDBF6AC0F24CC67D47549FA3F5257655B5449B1BCF1FB5CDB27B03D501
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Juba) {.. {-9223372036854775808 7588 0 LMT}.. {-1230775588 7200 0 CAT}.. {10360800 10800 1 CAST}.. {24786000 7200 0 CAT}.. {41810400 10800 1 CAST}.. {56322000 7200 0 CAT}.. {73432800 10800 1 CAST}.. {87944400 7200 0 CAT}.. {104882400 10800 1 CAST}.. {119480400 7200 0 CAT}.. {136332000 10800 1 CAST}.. {151016400 7200 0 CAT}.. {167781600 10800 1 CAST}.. {182552400 7200 0 CAT}.. {199231200 10800 1 CAST}.. {214174800 7200 0 CAT}.. {230680800 10800 1 CAST}.. {245710800 7200 0 CAT}.. {262735200 10800 1 CAST}.. {277246800 7200 0 CAT}.. {294184800 10800 1 CAST}.. {308782800 7200 0 CAT}.. {325634400 10800 1 CAST}.. {340405200 7200 0 CAT}.. {357084000 10800 1 CAST}.. {371941200 7200 0 CAT}.. {388533600 10800 1 CAST}.. {403477200 7200 0 CAT}.. {419983200 10800 1 CAST}.. {435013200 7200 0 CAT}.. {452037600 10800 1 CAST}.. {466635600 7200
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.837466713772859
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2DcJEl2DcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2DIEl2V
                                                                                                                                                                                                                                                          MD5:E929ED1BC316C71AABE7E625BD562FB1
                                                                                                                                                                                                                                                          SHA1:C20C172518C02D93327F4BBBC5D410BFFEF5039D
                                                                                                                                                                                                                                                          SHA-256:8EA3028CE2B025F0C457DC8F7601279CA5AF565A88B9FE80208F9F1030F2B0D0
                                                                                                                                                                                                                                                          SHA-512:B2FBCF06EACCF18DE97AF1D6BC57D9638E0A36DBF17044FF97F6B9E5089CF9E13E1304F304495324C0ACC1128A7D2D494E7C1FDB95DB0855FCE54F7028096C50
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Kampala) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1131
                                                                                                                                                                                                                                                          Entropy (8bit):4.0421745451318385
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5xe9dSXMV0GbMSHMzNy8MXLwM0JXMfCsMzaMq0QM3W50dM44R8M1XMreM7p0z8MM:5hMV04MSHMzNxMbwM0JXMfCsMzaMq0Qc
                                                                                                                                                                                                                                                          MD5:2BD3850DDBE2F05BF6F24F3AEFF7516C
                                                                                                                                                                                                                                                          SHA1:22B0DBB54E071F30D51A8654CF103F99537F74CD
                                                                                                                                                                                                                                                          SHA-256:F475DB8A857A46B310B12C21D6A9BC6CA9FF2960DA429A9D57FA375F9439E13B
                                                                                                                                                                                                                                                          SHA-512:1CF82FC07348C697F26625673DA7E3D734358B3FBE69D8E2132CAC0D9F00C7E8CDC353676CD9BAC4CBB9E26CF6638CEAE41DF559E7445D9C453409D7115FFC6C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Khartoum) {.. {-9223372036854775808 7808 0 LMT}.. {-1230775808 7200 0 CAT}.. {10360800 10800 1 CAST}.. {24786000 7200 0 CAT}.. {41810400 10800 1 CAST}.. {56322000 7200 0 CAT}.. {73432800 10800 1 CAST}.. {87944400 7200 0 CAT}.. {104882400 10800 1 CAST}.. {119480400 7200 0 CAT}.. {136332000 10800 1 CAST}.. {151016400 7200 0 CAT}.. {167781600 10800 1 CAST}.. {182552400 7200 0 CAT}.. {199231200 10800 1 CAST}.. {214174800 7200 0 CAT}.. {230680800 10800 1 CAST}.. {245710800 7200 0 CAT}.. {262735200 10800 1 CAST}.. {277246800 7200 0 CAT}.. {294184800 10800 1 CAST}.. {308782800 7200 0 CAT}.. {325634400 10800 1 CAST}.. {340405200 7200 0 CAT}.. {357084000 10800 1 CAST}.. {371941200 7200 0 CAT}.. {388533600 10800 1 CAST}.. {403477200 7200 0 CAT}.. {419983200 10800 1 CAST}.. {435013200 7200 0 CAT}.. {452037600 10800 1 CAST}.. {466635600 7
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):181
                                                                                                                                                                                                                                                          Entropy (8bit):4.910322325134086
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2DcCJRx+DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2DRX+DEi
                                                                                                                                                                                                                                                          MD5:3017253E1C6ACCA8D470A014E4BB321D
                                                                                                                                                                                                                                                          SHA1:671B7AC04580B56E2C34F88D123E8296947DDD7E
                                                                                                                                                                                                                                                          SHA-256:73FEB807006897B4B485CB82394867444E890265EFE960EC66D6C0E325DA9372
                                                                                                                                                                                                                                                          SHA-512:2498C380D761A16C183D78BC1BB18B1D2A1BFCB9C703D86A3FC04CCCE43D88C8D4BC3C47CC31639B78A5FE9C8A7445E9DBB52062E2F3B737DA1E7D0FF70F140A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Kigali) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):180
                                                                                                                                                                                                                                                          Entropy (8bit):4.866127364448228
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DcqQFeDcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2DdD4yn
                                                                                                                                                                                                                                                          MD5:41209A335A99803239A854575190C5ED
                                                                                                                                                                                                                                                          SHA1:E6EA627C25513B9DDE053F9A24D509AA317C30A1
                                                                                                                                                                                                                                                          SHA-256:611375C4901AD6C4844C2BB7D02FB17F34996F49E642546A6784D6F0B28530CC
                                                                                                                                                                                                                                                          SHA-512:DF2C0B131F35F54DF5EBF7F8459F98DBABEB6F081247BA95B5D7B41146E2A2EF9BC6B1D909DE57A1223D9C258AB197D9668ED2E111A365C86BABDAA7DF551FB6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Kinshasa) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):235
                                                                                                                                                                                                                                                          Entropy (8bit):4.7936510664790815
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2D4JDm2OHWQvvoHvBsp9boFvoHzIX7uRe6vF9:MB862DymdHWQCvqpmVCzIq
                                                                                                                                                                                                                                                          MD5:EC08046589E85D999A597252FF5368B7
                                                                                                                                                                                                                                                          SHA1:126E3DE158E1E7AF4737D0AB5B51C0F92F416DC7
                                                                                                                                                                                                                                                          SHA-256:DCC9F52F539A67DFD7ABAFDE072ACDAE2B67754C559C8A5FE61979F5A286A066
                                                                                                                                                                                                                                                          SHA-512:84B9AB18BC343C8B8934F5FDD2E2EB413925B04D6F5394AA8337B7B55E6487FB071A83A69BD4D0FA40F7F31EBC57B9908729674542CEA3083D700FCD02D77633
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Lagos) {.. {-9223372036854775808 815 0 LMT}.. {-2035584815 0 0 GMT}.. {-1940889600 815 0 LMT}.. {-1767226415 1800 0 +0030}.. {-1588465800 3600 0 WAT}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):182
                                                                                                                                                                                                                                                          Entropy (8bit):4.865878143076229
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2Dcr7bp4DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2Dgfp4D4y
                                                                                                                                                                                                                                                          MD5:35D8A58EE21E603C6FC4FB896AE6B3D0
                                                                                                                                                                                                                                                          SHA1:F1D0A939D761F3F0954F045814CF5339A5597036
                                                                                                                                                                                                                                                          SHA-256:AB3E797548C7663CF9ABA7FE163635FF7CAB9E6CB61FA1644C0F7B4B5CCE8B99
                                                                                                                                                                                                                                                          SHA-512:97717961987F6B6832C24A7833150CDFE7E82BBEB32DFDB84D2500442AAD9263F8BD4E879591E913D56E9A1991C389EF730211853647A889F358AE3FA37C0185
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Libreville) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):182
                                                                                                                                                                                                                                                          Entropy (8bit):4.862780607964543
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2Dcih4DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2DNh4D4
                                                                                                                                                                                                                                                          MD5:EA21ABBF8B11953916A1C509B8A1B427
                                                                                                                                                                                                                                                          SHA1:35ADC230C57B001BE8A99A3D2E34B609A60A1162
                                                                                                                                                                                                                                                          SHA-256:EACA9124F17E5B11F27D11FA6141D19EB3AC23E155E155B73467BDAA3BC99AA7
                                                                                                                                                                                                                                                          SHA-512:A7972D4F1C5FB988CA04B39E2CDD580F51383BA9D7A66C478275C11A07B8D7A6EFF53A3E1929B0D89F10BCC39D22F285DB2601ED60DB4647C65465643F70C137
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Lome) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):178
                                                                                                                                                                                                                                                          Entropy (8bit):4.856982839546061
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DccLtBQDcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2DXQD4yn
                                                                                                                                                                                                                                                          MD5:40CD47F6DCF51EBEFEF42489F1716257
                                                                                                                                                                                                                                                          SHA1:DF245192A1899A72DE01A57F6969AC060E841734
                                                                                                                                                                                                                                                          SHA-256:4C2FD1E44DFAAF0C0DD2EB56B84B538F1E2D84B301AB2CFB8EE7759783501444
                                                                                                                                                                                                                                                          SHA-512:D39BEB0EEF344B1A44F7D6A806A1D5B956D7D402648EE0C67C4BA46493236840AF975D89A91B2D33B8AA7D6DC9A051E66718DCDBC1C83B0E964215C2E32ED923
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Luanda) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.940313336280723
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2DcfpT0DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2D8pT0Dt
                                                                                                                                                                                                                                                          MD5:71A5DE1276902DB1542840318F9B1AF3
                                                                                                                                                                                                                                                          SHA1:AC3825BF343482E0E4D9D6FAA6FCA4D1A125433B
                                                                                                                                                                                                                                                          SHA-256:24384EEC359FD24D181AAEF3C017E3C345490A8D352B29D19B1B143A29A811C2
                                                                                                                                                                                                                                                          SHA-512:2984EB42A79B8B32BB93DFE71F1C4C0CABFDC9B0A199971347BB3473463FA07FDB5D20227D288BF8653B1BDE347E1297459BBB4C3C34AF7A5434FBF945683577
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Lubumbashi) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):181
                                                                                                                                                                                                                                                          Entropy (8bit):4.905174746463853
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2DcOf+DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2DkDEi
                                                                                                                                                                                                                                                          MD5:1D7FDB388535CC59742CA0F1AEE27FBD
                                                                                                                                                                                                                                                          SHA1:A99FF2CAC47FD333429C22B271E190D979EEC024
                                                                                                                                                                                                                                                          SHA-256:B00801A7279741434D9C2D7EC7322DD93B85EA4F5C9976AB3A43F0AB142E1553
                                                                                                                                                                                                                                                          SHA-512:0174D3C6F9116C36C62AD1EB58203EE7DFE8C37F618B8449D5E45AD6290CF8334F28798877D7A563A12EE533026244D6A49BCCF29B5D7FCB5BCC91481D0DDDE2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Lusaka) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):178
                                                                                                                                                                                                                                                          Entropy (8bit):4.857096806490649
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2Dcn2DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2D42D4yn
                                                                                                                                                                                                                                                          MD5:1CA9B3E7BCD5BC1CC881453D16B09389
                                                                                                                                                                                                                                                          SHA1:1B1964B314E72847D71A42C147CF2BF331B44461
                                                                                                                                                                                                                                                          SHA-256:35D56EFFE9E7E60F17B32BD30486E566B635F0AE7A8948D77395B8E6332E26F1
                                                                                                                                                                                                                                                          SHA-512:9E08D57B7824F5B076D159D9A5106E51450DF24729C36F485B9B68E8F47E8DFC50F9BEC3F11E0AE6579A8E372A5C0F0DA18A2E797CF2115519D1B4E5B64413DD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Malabo) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):149
                                                                                                                                                                                                                                                          Entropy (8bit):4.952872531197478
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2DcfKiMXGm2OHoVoHvdSF2I:SlSWB9eg/2DEZDm2OHoVoHvdI
                                                                                                                                                                                                                                                          MD5:CD429B6891CBF603A93F9A9733E2391B
                                                                                                                                                                                                                                                          SHA1:C6833B83B6D1694AC632018A27915E6F97F708AE
                                                                                                                                                                                                                                                          SHA-256:FE6B6A4BE1B61F7F909A3F6137530DFE6D1754499A4D9B0D1CE4952FFF0AE62D
                                                                                                                                                                                                                                                          SHA-512:6E57B70B71515998AD617954F9DDAE19968B20946542201153DAB47FBE63790D42F41AE29148ECBCE6D12812879BCF0A4EC881507B62CDB2675AB20267220BF9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Maputo) {.. {-9223372036854775808 7820 0 LMT}.. {-2109291020 7200 0 CAT}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):199
                                                                                                                                                                                                                                                          Entropy (8bit):4.964472328419063
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7HbsSHAIgNTzbrN/2DZQs+DWb4n:MByMaHw7NH/t2DZiDWU
                                                                                                                                                                                                                                                          MD5:88C8FF2B480648EDADBD0FB93F754275
                                                                                                                                                                                                                                                          SHA1:BED7A784C378909914CEB0D303DFE6D05FD576B7
                                                                                                                                                                                                                                                          SHA-256:1D80FD86CB733D57D88ECD404E702F750B233ED0CCBFBFFFEED1AAD3B7F1CB04
                                                                                                                                                                                                                                                          SHA-512:CB7F831CF099E85B948AE57FCE9D91C7EAAD39753AF82C56EC15B65830EB4115A71BBC83A71A2AC947CAB24DEDDB557E02FAA5A3264546AE6E60607DF6BD2FA3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Johannesburg)]} {.. LoadTimeZoneFile Africa/Johannesburg..}..set TZData(:Africa/Maseru) $TZData(:Africa/Johannesburg)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):200
                                                                                                                                                                                                                                                          Entropy (8bit):4.957246428185456
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7HbsSHAIgNTzbrN/2DzjEHp4DWb4n:MByMaHw7NH/t2DzjEJ4DWU
                                                                                                                                                                                                                                                          MD5:CA7255B86425BA706D214924856B6818
                                                                                                                                                                                                                                                          SHA1:E9BE6CF871BB1786E842953D41392299952EC9AC
                                                                                                                                                                                                                                                          SHA-256:547197C09C1987350AE5720A4EEC7E8D8F4B9F4A0559726E225E13C707F7C564
                                                                                                                                                                                                                                                          SHA-512:23F9AD0F926A0945A17BBC3DCFF9A3D7EE68EC9423EA78985F5FFC60CC61641B57871F9AA703B5FB9BE842DCD4693D0641F9EDED702240873F58D24CD4D60C32
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Johannesburg)]} {.. LoadTimeZoneFile Africa/Johannesburg..}..set TZData(:Africa/Mbabane) $TZData(:Africa/Johannesburg)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):187
                                                                                                                                                                                                                                                          Entropy (8bit):4.877126792757121
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2DcBEBXCEeDcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2DFSVDR
                                                                                                                                                                                                                                                          MD5:5C2E2B5189E0E816D5BD7AFC8B49A35E
                                                                                                                                                                                                                                                          SHA1:4E43A1ED51399528636D6442B1DDFFD820911407
                                                                                                                                                                                                                                                          SHA-256:25E221BE49DEC5547A74AEB91B0041859C59BC866987272A447AB2343D1CC30C
                                                                                                                                                                                                                                                          SHA-512:B74735CFAB692756BAADFB1A51A8CC0C986F981D8E7E7A8182370A9017E67439875F0115820A349AFB3BE2FA581A721440968EF817471DD2C5E1286E53B2FE99
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Mogadishu) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):208
                                                                                                                                                                                                                                                          Entropy (8bit):4.8660011420394955
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2D3NPDm2OHrFGxYoHvlHIg5pTwdPsy:MB862D3NbmdHhmYCvdIg5GPsy
                                                                                                                                                                                                                                                          MD5:1B3C94B5098E454981C73C1F2AF80164
                                                                                                                                                                                                                                                          SHA1:1EBA9E2DBEA70BB1AE5EB13739518AB5A62D2130
                                                                                                                                                                                                                                                          SHA-256:2BF0D90610211651127402680519B29AB50B15D344263D0C1A22EDEBE5E01E27
                                                                                                                                                                                                                                                          SHA-512:DA4A0BCE7C6750BD7D3BA76B6301B9390723BE0C001C39BE453D80BD87020C2253A75629F68F83C19410D2A75FAF5223A435299CD4AA53DE545EC7C5B5AA54B7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Monrovia) {.. {-9223372036854775808 -2588 0 LMT}.. {-2776979812 -2588 0 MMT}.. {-1604359012 -2670 0 MMT}.. {63593070 0 0 GMT}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):277
                                                                                                                                                                                                                                                          Entropy (8bit):4.655052651600954
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2Dk1Dm2OHsvT5oH99VCV22ufPnVCkVBKBQn9q:MB862DGmdHsvVCjkifvdH9q
                                                                                                                                                                                                                                                          MD5:B640661FB37BB74FAB172DBDF1B433E1
                                                                                                                                                                                                                                                          SHA1:0236A5B53443A4A18B8B9D6AA7732620BE9A6553
                                                                                                                                                                                                                                                          SHA-256:BD8E9765174431C0D403249D3E881C949C83966E9F8162552DA88AE53132467B
                                                                                                                                                                                                                                                          SHA-512:53DCC6DF7C3E0B00A6D98A8DCC4988C8CFD6B53CC89E6F8D32DA41CB532A62D9C6A823675C5039F5639CE0D423F6D571F46F5B93FFC7EFFB4EDFFBF89D46AA12
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Nairobi) {.. {-9223372036854775808 8836 0 LMT}.. {-1946168836 9000 0 +0230}.. {-1309746600 10800 0 EAT}.. {-1261969200 9000 0 +0230}.. {-1041388200 9900 0 +0245}.. {-865305900 10800 0 EAT}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):208
                                                                                                                                                                                                                                                          Entropy (8bit):4.856754881865487
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2DjUfDm2OHNseoH1axCXFHzaSmkFWTvF9:MB862DjULmdHPC1XNzaS3yz
                                                                                                                                                                                                                                                          MD5:EDB548348E590C8CFE04ED172D96B86C
                                                                                                                                                                                                                                                          SHA1:AD3B631FB03819772164402E202AFA781687F597
                                                                                                                                                                                                                                                          SHA-256:9ADA5F5AFB25E823E1F0E8AD2489AAA1C09F01356634A9403670D7AB21CA2E2C
                                                                                                                                                                                                                                                          SHA-512:17E396A9BE497077B774AD1108CC8760ED35FC92F65FFF070F9ACD3C4FB67A335C1C57DF1CCB1570DE14B708EFCA0063990A969E30759C9A47731DA45ED25EFE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Ndjamena) {.. {-9223372036854775808 3612 0 LMT}.. {-1830387612 3600 0 WAT}.. {308703600 7200 1 WAST}.. {321314400 3600 0 WAT}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):178
                                                                                                                                                                                                                                                          Entropy (8bit):4.871519187180041
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DcdhA9Ff2DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2Dsh2f2D1
                                                                                                                                                                                                                                                          MD5:0134039CD1666E983A9B6E43ABD6AF59
                                                                                                                                                                                                                                                          SHA1:A2A99345390F4D17C892CEADE58C604257686764
                                                                                                                                                                                                                                                          SHA-256:B517120AD8DB3F21EAB4E44A78001EE856EB4EA35852C54CCA96D38887DEBCFA
                                                                                                                                                                                                                                                          SHA-512:E5911ADD3D776D87ACFC986C4D2564E3ED9AB12C67F23391ED35FF2A31AD8314B873E31DB8DA4D5E0DAEA12BE34110A8F0C27C9C6126977BAD51C6AD5CDFA39B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Niamey) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):188
                                                                                                                                                                                                                                                          Entropy (8bit):4.909962899502589
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcboGb+DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2Dqbb+c
                                                                                                                                                                                                                                                          MD5:550E482599C2F4280F2C258019BB2547
                                                                                                                                                                                                                                                          SHA1:A39045BEF313094CEDC100A7D695AE51BC9E498D
                                                                                                                                                                                                                                                          SHA-256:64CAF2BF9D45095DF97F419714D5617CF6300ACDB544B621DCE1D594AA9B910C
                                                                                                                                                                                                                                                          SHA-512:4FD29C5B4C0D2BDE69C437E9BF4F08A11E1DAAA689B69F28F3551F550BDCCDD055E4C1A241EDB2FA48B18825AFF792F4860F55983E106EA8224F1D87ED4F7546
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Nouakchott) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.920023025906233
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcXCZDcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2D1DBS
                                                                                                                                                                                                                                                          MD5:6CFC4E938E50C9B591F8CC42A14FA82A
                                                                                                                                                                                                                                                          SHA1:FCE14A5CA62C9005C76D27B849A238E76C834F8A
                                                                                                                                                                                                                                                          SHA-256:03B9C1FE350B5E9F6F333F9519FA394DCC562308D9388A903AF3D3FECEBDC762
                                                                                                                                                                                                                                                          SHA-512:98F22F1D23A9930276A2D306A1473E64DC43547A16CFD01226E4F030A26A3CC4FDED77F790583CC5C078FC6DFCCE81C16A50879AE46A0D3A6F1FA98373F413C7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Ouagadougou) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):182
                                                                                                                                                                                                                                                          Entropy (8bit):4.893842293207225
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DcyTKM0DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2DQD4yn
                                                                                                                                                                                                                                                          MD5:6D979FCD225D5431C7391AE568C6409F
                                                                                                                                                                                                                                                          SHA1:6C9DCD222061CC00FD386773C6BB2861F3429A60
                                                                                                                                                                                                                                                          SHA-256:8FB8692DB9281AE2B087D704168BFD47D3D0901781FEF65BFD62FCB213BA6B50
                                                                                                                                                                                                                                                          SHA-512:32AFA6AF6BFC3D42CA636DD2B96906048EF1ADFBB135BB7E7B77C444FED99FDABB84FBBADF56EC63828FFA7B3371191FF1311822B1C75241EBD9CF602467088E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Porto-Novo) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):234
                                                                                                                                                                                                                                                          Entropy (8bit):4.818597723513168
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2DXDm2OHH5oHvzdoH1aNbbFHRMy:MB862DTmdHH5CvzdC16bZRMy
                                                                                                                                                                                                                                                          MD5:28A5967C797F4B38FB63F823D6F07168
                                                                                                                                                                                                                                                          SHA1:17872E91683B884191D2E4C777FB79DCE6D73EE7
                                                                                                                                                                                                                                                          SHA-256:BA1D60DF2B41320F92A123A714E17E576C89383526B96E0541A464C3FBA415B7
                                                                                                                                                                                                                                                          SHA-512:B335E3D3268631F3A71F4BAD59740F3A5222344E8223C201B8FE885BAA7F1A550FA7778E498D6DC2111F41053856F50B21413AECCE84B80833EC8176F2A1009C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Sao_Tome) {.. {-9223372036854775808 1616 0 LMT}.. {-2713912016 -2205 0 LMT}.. {-1830384000 0 0 GMT}.. {1514768400 3600 0 WAT}.. {1546304400 0 0 GMT}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):186
                                                                                                                                                                                                                                                          Entropy (8bit):4.905303708777235
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcHdDcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2DwdDBS
                                                                                                                                                                                                                                                          MD5:F2D7F7BC4EA3629EC7F0E45300A0CFD2
                                                                                                                                                                                                                                                          SHA1:E7594D378C5DCFEB1E87E13AC79A026260D2E630
                                                                                                                                                                                                                                                          SHA-256:9D8009ACAB019B32B1E87AB10E0AC3765ABCABE8066318DA8CA4905D41562F72
                                                                                                                                                                                                                                                          SHA-512:795E58172907020C85CF0B10BBA35842D5F92872CCB3382DFDC787BAA504C79927FA23BC3104AD63541A95C44CA80977E8247846DE918A0B00963B970F4823D2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Timbuktu) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):954
                                                                                                                                                                                                                                                          Entropy (8bit):4.151253074491018
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862DrmdHrCDWR+f7Zn9ueRSmNvlTtuyI/ZBv8dq8Jw4VFZBZYEuAENSfp8kSYx:5veuDkWx3NdT18kbjjAkxTx
                                                                                                                                                                                                                                                          MD5:2DF9B050D82B06EB89DA908C31C1F1C9
                                                                                                                                                                                                                                                          SHA1:CB294E12560A98D5CEA3BA7004B5519B6C22BAAC
                                                                                                                                                                                                                                                          SHA-256:B447B6B1C351E77F22A2D77C0437F2BBB7D8BDFDFDC3D6285E0D260519CC7110
                                                                                                                                                                                                                                                          SHA-512:BBE281D551E9F8DA7B6BB08D809177615410A11E4B1184ABD220EA8B1F355B2BBC090C6BAAF7E07FD61286891388ECD4026D4433C4E4B6A8D201F8D95E174532
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Tripoli) {.. {-9223372036854775808 3164 0 LMT}.. {-1577926364 3600 0 CET}.. {-574902000 7200 1 CEST}.. {-512175600 7200 1 CEST}.. {-449888400 7200 1 CEST}.. {-347158800 7200 0 EET}.. {378684000 3600 0 CET}.. {386463600 7200 1 CEST}.. {402271200 3600 0 CET}.. {417999600 7200 1 CEST}.. {433807200 3600 0 CET}.. {449622000 7200 1 CEST}.. {465429600 3600 0 CET}.. {481590000 7200 1 CEST}.. {496965600 3600 0 CET}.. {512953200 7200 1 CEST}.. {528674400 3600 0 CET}.. {544230000 7200 1 CEST}.. {560037600 3600 0 CET}.. {575852400 7200 1 CEST}.. {591660000 3600 0 CET}.. {607388400 7200 1 CEST}.. {623196000 3600 0 CET}.. {641775600 7200 0 EET}.. {844034400 3600 0 CET}.. {860108400 7200 1 CEST}.. {875919600 7200 0 EET}.. {1352505600 3600 0 CET}.. {1364515200 7200 1 CEST}.. {1382662800 7200 0 EET}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1111
                                                                                                                                                                                                                                                          Entropy (8bit):4.150944563639585
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862DHmdHjCvbB/lxRjntMVyoKCyFWeey0XSe/OSyHaCgmvLOcSFQSFeSTC6ZPJ:5LemvbplxRhbv+yuh2tIee6kvcw9Cy
                                                                                                                                                                                                                                                          MD5:0C99335A41D33AA8BC1EDA0CB4CDCBF5
                                                                                                                                                                                                                                                          SHA1:5CABC28D318FA5B8307429EA571FFF91EB8E1252
                                                                                                                                                                                                                                                          SHA-256:0760D1028E733888E43E7F1E057217DC2B52786029FCEC67B27EB69CC6A54938
                                                                                                                                                                                                                                                          SHA-512:C8FE685ACA46FD4836F3AABC15833F294E5EBED123A487D04E74A8C5668BDFAFB96D2326760452A6E5A1B9CC25AC6C3918D8C10A7F8EF737456640E3000BBA2F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Tunis) {.. {-9223372036854775808 2444 0 LMT}.. {-2797202444 561 0 PMT}.. {-1855958961 3600 0 CET}.. {-969242400 7200 1 CEST}.. {-950493600 3600 0 CET}.. {-941940000 7200 1 CEST}.. {-891136800 3600 0 CET}.. {-877827600 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-842918400 3600 0 CET}.. {-842223600 7200 1 CEST}.. {-828230400 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796269600 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766634400 3600 0 CET}.. {231202800 7200 1 CEST}.. {243903600 3600 0 CET}.. {262825200 7200 1 CEST}.. {276044400 3600 0 CET}.. {581122800 7200 1 CEST}.. {591145200 3600 0 CET}.. {606870000 7200 1 CEST}.. {622594800 3600 0 CET}.. {641516400 7200 1 CEST}.. {654649200 3600 0 CET}.. {1114902000 7200 1 CEST}.. {1128038400 3600 0 CET}.. {1143334800 7200 1 CEST}.. {1162083600 3600 0 CET}.. {11747
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1649
                                                                                                                                                                                                                                                          Entropy (8bit):3.9974091170263066
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5t+Lmcz0iMHHWMbnHoMcHiM0H+MCySHr/MDHqMafHO8MwHJMHHOMHSHWMHHXM5Hs:OLjQDI6jZ2WFcv
                                                                                                                                                                                                                                                          MD5:4846FB13467BA93EB134D88228D7F534
                                                                                                                                                                                                                                                          SHA1:477FC6144B7DF365606A2E44EF1430F8DF6FB841
                                                                                                                                                                                                                                                          SHA-256:DFC3D1FC182B315B31D999BC103C264BD205EB16F971C8636003A71170D7BD7C
                                                                                                                                                                                                                                                          SHA-512:A719F5083F66CE44FE047880A10B2ED04B66E01C7F0F7DADAE2FFB95172308F091D669BCFED5A236D2A0F80A4A1D78DA7A778DDE3FAECB40170ECDA705573769
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Windhoek) {.. {-9223372036854775808 4104 0 LMT}.. {-2458170504 5400 0 +0130}.. {-2109288600 7200 0 SAST}.. {-860976000 10800 1 SAST}.. {-845254800 7200 0 SAST}.. {637970400 7200 0 CAT}.. {764200800 3600 1 WAT}.. {778640400 7200 0 CAT}.. {796780800 3600 1 WAT}.. {810090000 7200 0 CAT}.. {828835200 3600 1 WAT}.. {841539600 7200 0 CAT}.. {860284800 3600 1 WAT}.. {873594000 7200 0 CAT}.. {891734400 3600 1 WAT}.. {905043600 7200 0 CAT}.. {923184000 3600 1 WAT}.. {936493200 7200 0 CAT}.. {954633600 3600 1 WAT}.. {967942800 7200 0 CAT}.. {986083200 3600 1 WAT}.. {999392400 7200 0 CAT}.. {1018137600 3600 1 WAT}.. {1030842000 7200 0 CAT}.. {1049587200 3600 1 WAT}.. {1062896400 7200 0 CAT}.. {1081036800 3600 1 WAT}.. {1094346000 7200 0 CAT}.. {1112486400 3600 1 WAT}.. {1125795600 7200 0 CAT}.. {1143936000 3600 1 WAT}.. {1157245200 7200
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8447
                                                                                                                                                                                                                                                          Entropy (8bit):3.867931581740766
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:6hvOs5vveFaHU6lgqN/zNMkixlrxYTMcmo1LWF59:6hvOstgqN/zNMkArxiZmf
                                                                                                                                                                                                                                                          MD5:DF52E726B33FA47EB115C1233614E101
                                                                                                                                                                                                                                                          SHA1:26B0E49022FCB929F0160617F9C9D2DBEDC63610
                                                                                                                                                                                                                                                          SHA-256:77231D179260C08690A70AEE6C2517E4B621ED4794D9AEEA7040539F4FF05111
                                                                                                                                                                                                                                                          SHA-512:48AAF25419E07B06E076B0E19F9A0C27EB257556E62FD8F7B2AA963A817823DD89D33AB6AFEAAC2EF2230361D76776355E19CC2BBBB4D19536F823A347AC8AA4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Adak) {.. {-9223372036854775808 44002 0 LMT}.. {-3225223727 -42398 0 LMT}.. {-2188944802 -39600 0 NST}.. {-883573200 -39600 0 NST}.. {-880196400 -36000 1 NWT}.. {-769395600 -36000 1 NPT}.. {-765374400 -39600 0 NST}.. {-757342800 -39600 0 NST}.. {-86878800 -39600 0 BST}.. {-31496400 -39600 0 BST}.. {-21466800 -36000 1 BDT}.. {-5745600 -39600 0 BST}.. {9982800 -36000 1 BDT}.. {25704000 -39600 0 BST}.. {41432400 -36000 1 BDT}.. {57758400 -39600 0 BST}.. {73486800 -36000 1 BDT}.. {89208000 -39600 0 BST}.. {104936400 -36000 1 BDT}.. {120657600 -39600 0 BST}.. {126709200 -36000 1 BDT}.. {152107200 -39600 0 BST}.. {162392400 -36000 1 BDT}.. {183556800 -39600 0 BST}.. {199285200 -36000 1 BDT}.. {215611200 -39600 0 BST}.. {230734800 -36000 1 BDT}.. {247060800 -39600 0 BST}.. {262789200 -36000 1 BDT}.. {278510400 -39600 0 BST}.. {29423880
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8685
                                                                                                                                                                                                                                                          Entropy (8bit):3.9620252256806845
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:esKLO6KLC9+j1giaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:etLhN9DiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                                                                          MD5:BFEACEA04AAA8A69A9AC71CF86BCC15C
                                                                                                                                                                                                                                                          SHA1:1693971B8AAA35021BA34799FB1B9FADC3DA0294
                                                                                                                                                                                                                                                          SHA-256:DE7FBE2B3ED780C6B82099E1E249DD41F4452A3ADB9DD807B1D0EC06049C2302
                                                                                                                                                                                                                                                          SHA-512:E94112A2A5F268C03C58CE3BB4C243B2B9B0FC17CB27FDD58BCD2CCC8D377B805C87A552AE7DE1C5698C5F2C4B0FCAB00A3420B1DAD944C1A2F7A47CE7118F78
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Anchorage) {.. {-9223372036854775808 50424 0 LMT}.. {-3225223727 -35976 0 LMT}.. {-2188951224 -36000 0 AST}.. {-883576800 -36000 0 AST}.. {-880200000 -32400 1 AWT}.. {-769395600 -32400 1 APT}.. {-765378000 -36000 0 AST}.. {-86882400 -36000 0 AHST}.. {-31500000 -36000 0 AHST}.. {-21470400 -32400 1 AHDT}.. {-5749200 -36000 0 AHST}.. {9979200 -32400 1 AHDT}.. {25700400 -36000 0 AHST}.. {41428800 -32400 1 AHDT}.. {57754800 -36000 0 AHST}.. {73483200 -32400 1 AHDT}.. {89204400 -36000 0 AHST}.. {104932800 -32400 1 AHDT}.. {120654000 -36000 0 AHST}.. {126705600 -32400 1 AHDT}.. {152103600 -36000 0 AHST}.. {162388800 -32400 1 AHDT}.. {183553200 -36000 0 AHST}.. {199281600 -32400 1 AHDT}.. {215607600 -36000 0 AHST}.. {230731200 -32400 1 AHDT}.. {247057200 -36000 0 AHST}.. {262785600 -32400 1 AHDT}.. {278506800 -36000 0 AHST}.. {294235200 -3
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):202
                                                                                                                                                                                                                                                          Entropy (8bit):4.908728298285591
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290/8J5290ppv:MByMYbpwt290/8m90b
                                                                                                                                                                                                                                                          MD5:1C3CE9F156ABECEAA794E8F1F3A7ADDB
                                                                                                                                                                                                                                                          SHA1:6F84D0A424FD2DE85E3420EA320A186B277B0295
                                                                                                                                                                                                                                                          SHA-256:F38610019C0A2C18AC71F5AA108B9647D9B5C01DCB55211AFB8312308C41FE70
                                                                                                                                                                                                                                                          SHA-512:CA2DA6F9551E4DBF775D7D059F6F3399E0C4F2A428699726CD2A1B0BB17CCF5CDEEF645EE1759A2A349F3F29E0343600B89CE1F4659CF5D2B58280A381C018AD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Anguilla) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):201
                                                                                                                                                                                                                                                          Entropy (8bit):4.898881450964165
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290//MFe90ppv:MByMYbpwt290//V90b
                                                                                                                                                                                                                                                          MD5:DB16FFE76D625DEC731AB6320F5EF9BF
                                                                                                                                                                                                                                                          SHA1:D286994E03E4F82C08DE094B436FA098648AFADE
                                                                                                                                                                                                                                                          SHA-256:561E58E11DC5A86CAE04B5CB40F43EFCFF9ABC0C841FAC094619E9C5E0B403F8
                                                                                                                                                                                                                                                          SHA-512:8842B616205378AF78B0B2FC3F6517385845DE30FFD477A21ACFA0060D161FB6462A3C266DCFD54F101729446B8E1B2ECF463C9CF2E6CE227B2628A19AF365F9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Antigua) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1782
                                                                                                                                                                                                                                                          Entropy (8bit):3.733307964154526
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5KChlvEw6kSSx5H4a8tf3fkuozd23t8VZDG8+GCRRRd:QIlvEwJSSxdF8tfMuozdCt8VZy8+GCRB
                                                                                                                                                                                                                                                          MD5:9B01680A362EA7B462DC236F6A35E14C
                                                                                                                                                                                                                                                          SHA1:456A5E771F6B749BFDB2BFD59836A6A930499881
                                                                                                                                                                                                                                                          SHA-256:B1327CBEC20A21E3FF873E28A2EDFA271EE3A5C01933779300EABD6B185DA010
                                                                                                                                                                                                                                                          SHA-512:E6C2F5C489BEA31B0AAC3CB1DB750AC2B665DAC0AC82C1CE6756E768305300297BA5E3B32EDEB9E1715452F02223E47674C4F2B1844920F664623C9F34309240
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Araguaina) {.. {-9223372036854775808 -11568 0 LMT}.. {-1767214032 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2048
                                                                                                                                                                                                                                                          Entropy (8bit):3.7664759014118188
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5p9uuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwwfFC8OS0wi:jIu3pfe92jCs/VOHv2kdeRtnxafwwfF0
                                                                                                                                                                                                                                                          MD5:2B9A1EDE5110B46E24F4726664EA1E3F
                                                                                                                                                                                                                                                          SHA1:939D1A7A50544F34B318ACDB52BC6930FE453F6D
                                                                                                                                                                                                                                                          SHA-256:BC86AC89121EC4AA302F6259CCC97EFFD7022DC6CEE3B291C57DA72B6EA0C558
                                                                                                                                                                                                                                                          SHA-512:C204740DACBCECF2CC5CF4FEB687E86B9150512623203C999D6F4EB5FB246D07681A35C28D8445F6A50F49940C321E0AA5E51FE5A73B8ED076F29CEB5B4D4CA2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Buenos_Aires) {.. {-9223372036854775808 -14028 0 LMT}.. {-2372097972 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-7522
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2077
                                                                                                                                                                                                                                                          Entropy (8bit):3.742645155048276
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5/nuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafww3mC8OS0NC:Vuu3pfe92jCs/VOHv2kdeRtnxafww3mP
                                                                                                                                                                                                                                                          MD5:3D2AF5714DFC392ED4BC976784D5A58A
                                                                                                                                                                                                                                                          SHA1:9252DE40B6EF872E1D2F7CDD53DDD21145E93C5C
                                                                                                                                                                                                                                                          SHA-256:A516BB0937977EF949D47B3C8675E30F1CA6C34F8BD298DCF6EBB943580D5317
                                                                                                                                                                                                                                                          SHA-512:8D5FFDB5B578B8EA0291D3A21BDDE25F8301CB16B11AE794FFBA8DCFFE46F6AC5EC03D93E511061B132D84E69E5FAF1BB212837EB8A5A4B4BE517F783837E615
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Catamarca) {.. {-9223372036854775808 -15788 0 LMT}.. {-2372096212 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-7522740
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):242
                                                                                                                                                                                                                                                          Entropy (8bit):4.72138001874583
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7/MMXAXHAIgp/MMXmRN/290/MquQ90/MMXAy:MByMY/MYp/MrRt290/MquQ90/MK
                                                                                                                                                                                                                                                          MD5:8A609667DE461CEDC1127BE38B161459
                                                                                                                                                                                                                                                          SHA1:557D2D55DEA38D1CD1103E183F89C65F4016662B
                                                                                                                                                                                                                                                          SHA-256:8CCD6FC77D55582938F1912B1BA66035882D1BFC18A797C631E5E89ABFBF570B
                                                                                                                                                                                                                                                          SHA-512:DBAFDA069DB5FDBCBA11050AC91A733C1712BD6395939CFFFC5EAA78BD0B70B4AF2D9FB8954C6841CCF3AC5F8EDCF08E604D3F2CF67F1CBEA5EB6D3C4DC7F2FA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Catamarca)]} {.. LoadTimeZoneFile America/Argentina/Catamarca..}..set TZData(:America/Argentina/ComodRivadavia) $TZData(:America/Argentina/Catamarca)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2043
                                                                                                                                                                                                                                                          Entropy (8bit):3.7481312409221594
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5lxQuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafww3mC8OS0n:/xBu3pfe92jCs/VOHv2kdeRtnxafww3j
                                                                                                                                                                                                                                                          MD5:8C1D665A25E61CE462C2AC57687763BF
                                                                                                                                                                                                                                                          SHA1:B5BBC26CF6A24BD5BEA42AC485D62C789B80905F
                                                                                                                                                                                                                                                          SHA-256:FA75E274240A341C6BFE3539CFDC114D125AEAEA3161D3C2409347CF8046042A
                                                                                                                                                                                                                                                          SHA-512:A89A7A92C025B87DA4CDFE99BF70CD0E64690D7BFE827DCBFBF0E91B188003FA26487E72B6B950D3BFC9C854B890E5936F414BBEAAD5F3F0673AC5EFE273CDF4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Cordoba) {.. {-9223372036854775808 -15408 0 LMT}.. {-2372096592 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2041
                                                                                                                                                                                                                                                          Entropy (8bit):3.7481290145270245
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5HluuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwcSPAC8OS0E:xwu3pfe92jCs/VOHv2kdeRtnxafwcDCK
                                                                                                                                                                                                                                                          MD5:995EDE9E1E86DB500C7437A196325E21
                                                                                                                                                                                                                                                          SHA1:4A8FB1511AA124CA2D299EC8DE155EE9D0479180
                                                                                                                                                                                                                                                          SHA-256:43EB79ABC03CBAC661C563DE1BC09D9DD855CBC72DD2B6467EA98F0F90421BA9
                                                                                                                                                                                                                                                          SHA-512:B58B35EA1B2F0388B8108DCF254F3BD1B21894F00A9F313ABC093BC52C36FCDD94B7486DBA38161C9EFCDB12BC3CD81E7E02395B0CA480A7F01148C43CD3054F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Jujuy) {.. {-9223372036854775808 -15672 0 LMT}.. {-2372096328 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000 -
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2106
                                                                                                                                                                                                                                                          Entropy (8bit):3.744252944523733
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5lduuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwwkFC8OS0NC:Tou3pfe92jCs/VOHv2kdeRtnxafwwkFP
                                                                                                                                                                                                                                                          MD5:4A45A063D45EB94214005EF3CA5BCD6D
                                                                                                                                                                                                                                                          SHA1:2420E8591DC53A39EE1A58B2E45DCFAF9503685F
                                                                                                                                                                                                                                                          SHA-256:2B018B791E48269FA9EDA12662FFEC3E2DC33603A918E8B735B8D7D6BEB3B3AA
                                                                                                                                                                                                                                                          SHA-512:0B2824FA3D40B2EDBE8488D50C30368F4CF6E45A39FF6DEBC5BB4FD86F85AD52F5331AD1EB50E5166FA2E735B7E8AA9D94A5FED9421334DB0499524DBE08F737
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/La_Rioja) {.. {-9223372036854775808 -16044 0 LMT}.. {-2372095956 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-75227400
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2077
                                                                                                                                                                                                                                                          Entropy (8bit):3.738002814507529
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5CPBuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwGSmSc8OSI:GUu3pfe92jCs/VOHv2kdeRtnxafwGJld
                                                                                                                                                                                                                                                          MD5:F6CB24E8567B2443224E9E17EE438BFE
                                                                                                                                                                                                                                                          SHA1:8029426C30C4C645EA77C6240391CDB1C3107568
                                                                                                                                                                                                                                                          SHA-256:DC39400BBFD5BDDDC174FE099194806FBFD3FC3AA20E670D67BE0AC35FE97AD4
                                                                                                                                                                                                                                                          SHA-512:6869CFC24C21FBB2DFCCAA9AE7E21A0B24DC002EE792FB28A8F2F05C75C20E93C95A39BD8653AA272AF10FE95922B99EECC1208AACE814817D9441F84360E867
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Mendoza) {.. {-9223372036854775808 -16516 0 LMT}.. {-2372095484 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2080
                                                                                                                                                                                                                                                          Entropy (8bit):3.7580685839169545
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5oQuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwwfFC8OS0NC:qBu3pfe92jCs/VOHv2kdeRtnxafwwfFP
                                                                                                                                                                                                                                                          MD5:212D13CE27AF114A8EC2E04023D218C4
                                                                                                                                                                                                                                                          SHA1:C4C5F86BC6EC0D5EA4C9CF199309D085767B97E8
                                                                                                                                                                                                                                                          SHA-256:A05B6708DEFF0607396BFC6661C2287341C3432841AE353D94A67AC742B5FAFA
                                                                                                                                                                                                                                                          SHA-512:CE7201EEA6A86FB49641410D2EEE4030EDB1B96F3218D764762F5AE23883C796F5742ED69CEC985A9D3582D6C72ED74114DE81508F6DEB4B54865B6974ADC965
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Rio_Gallegos) {.. {-9223372036854775808 -16612 0 LMT}.. {-2372095388 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-7522
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2011
                                                                                                                                                                                                                                                          Entropy (8bit):3.7415813345133975
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5NPuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafww3mC8OS0wF:72u3pfe92jCs/VOHv2kdeRtnxafww3mz
                                                                                                                                                                                                                                                          MD5:A06C33CDFD7E7B630CB1DF34E72E61E5
                                                                                                                                                                                                                                                          SHA1:694826B9B910DA0BD70A9CB547C26E6838B08111
                                                                                                                                                                                                                                                          SHA-256:CAEFC60F2F36EF9FFE0C5921C3C392DE1E95755683A96C1C4EC0BA2C242A4D84
                                                                                                                                                                                                                                                          SHA-512:D6696A6C14EECF2B77EC586F40137BDD95E5CE5C5193570C809FAB9E5FCA4B8744283CEB6818E525C73F6EFF657274410B2622902EE8C15912C8D5F5FA5C805E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Salta) {.. {-9223372036854775808 -15700 0 LMT}.. {-2372096300 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000 -
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2106
                                                                                                                                                                                                                                                          Entropy (8bit):3.747934819596411
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5vXxuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwwkFC8OS0K:hUu3pfe92jCs/VOHv2kdeRtnxafwwkFl
                                                                                                                                                                                                                                                          MD5:32A50D0ABF408D9E59C0580D5B8CC472
                                                                                                                                                                                                                                                          SHA1:EA5BB8860982F8BAFEAEFDE1D6ACD440DA132DFE
                                                                                                                                                                                                                                                          SHA-256:41B2C25E42146A76934B866061BB3245B8ADA0FF4E1BFBA6F8842A30BDD5C132
                                                                                                                                                                                                                                                          SHA-512:E5D2521A4EF53AAD3E74506708EC2768C4D2EE8D6D014DCCF4A6DC290B713B4D46021B66527548C35004E10D753E1B685EEFD55BBE7BF01EC6104D7D8AAC4403
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/San_Juan) {.. {-9223372036854775808 -16444 0 LMT}.. {-2372095556 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-75227400
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2081
                                                                                                                                                                                                                                                          Entropy (8bit):3.7399269084699975
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5MDuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafw6bS2nZSbdI:yCu3pfe92jCs/VOHv2kdeRtnxafwWnZr
                                                                                                                                                                                                                                                          MD5:FB06B66F5D41709C7E85C8B1E9BFCFA0
                                                                                                                                                                                                                                                          SHA1:D5C0C4B12C6190856C300321B1C106C7474BA54B
                                                                                                                                                                                                                                                          SHA-256:A43B35F25E54EF359D046E33281C0A978F0EE8811C93A6809F1F65750878BBB6
                                                                                                                                                                                                                                                          SHA-512:D445F46D6A17A075AD995885E45234A711F53BF3FE2DFC6DFBB611E8AC154B10C91E137927DD66D6A7C596A93BAE5DE283796F341B5095FA0DD05595E1C3A077
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/San_Luis) {.. {-9223372036854775808 -15924 0 LMT}.. {-2372096076 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-75227400
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2105
                                                                                                                                                                                                                                                          Entropy (8bit):3.741704529449777
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5yZujuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafww3mC8OSf:suiu3pfe92jCs/VOHv2kdeRtnxafww3w
                                                                                                                                                                                                                                                          MD5:D9497141EC0DC172E5FF5304FED0BE6B
                                                                                                                                                                                                                                                          SHA1:CD20A4F0C127A84791093010D59DF119DD32340A
                                                                                                                                                                                                                                                          SHA-256:0F7DB23E1280FC19A1FB716E09A9699ADA2AAE24084CAD472B4C325CC9783CCF
                                                                                                                                                                                                                                                          SHA-512:0B71952055013CD6045ED209FD98168083550655FAB91B7870C92098E40C4FE6827EAAF922D34ECE28298CBB14327A76AD6780D480E552F52F865AA11A4AA083
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Tucuman) {.. {-9223372036854775808 -15652 0 LMT}.. {-2372096348 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2075
                                                                                                                                                                                                                                                          Entropy (8bit):3.7445758155279836
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5SHuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwwfFC8OS0jE:YOu3pfe92jCs/VOHv2kdeRtnxafwwfFn
                                                                                                                                                                                                                                                          MD5:16A89FD2CDEE50E534301A9797311A9D
                                                                                                                                                                                                                                                          SHA1:4A4EBA1798214C7CF5ACDC0B2EC8B4716CD968CB
                                                                                                                                                                                                                                                          SHA-256:10B6FF51314D8EE1D010187D8805C4E3D71B778BC6DECB26E66193A5BB3E9EA2
                                                                                                                                                                                                                                                          SHA-512:DBB0BA3F8AA2B54C86EA8B6530C16DF95AF1331FC5F843B113A204DA20B8EF011FE93C27EB917D01B9040D4914057687B4AACCD292A847559AF69150D1BDC4B5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Ushuaia) {.. {-9223372036854775808 -16392 0 LMT}.. {-2372095608 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):199
                                                                                                                                                                                                                                                          Entropy (8bit):4.893042770292303
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290/V90ppv:MByMYbpwt290/V90b
                                                                                                                                                                                                                                                          MD5:CC015E3E5D3293CAA1348B4E0EE5795C
                                                                                                                                                                                                                                                          SHA1:75E7EFD905C9001CE9CA5872DA3915A19BCB00E0
                                                                                                                                                                                                                                                          SHA-256:7490CD66408B8A14C549278FE67DC3338FE9E458F423F01CCBEA00B5E6F6CEF6
                                                                                                                                                                                                                                                          SHA-512:66523F050E4A42A1C9FC8C02B822CD3864A6E35F6364FB6A675F2A503BD8030FE6E380B252068668A79A6593B5042520EE40700DA033517742B3F0ED33D79DAF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Aruba) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7944
                                                                                                                                                                                                                                                          Entropy (8bit):3.5156463862656775
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:j7RXBXLqbvdvZsV4GGdzVUFg7XaMOhKpJq3o5GMJq90vRFhjGF3RxTBhcXBACBLo:jEJgXh
                                                                                                                                                                                                                                                          MD5:181203CAD98E94355B9914A205514904
                                                                                                                                                                                                                                                          SHA1:D361CB53955437270905A9432DE9E7F6C1AE7189
                                                                                                                                                                                                                                                          SHA-256:EAEFE21276EE60C7F876C1D65039999AC069339DCDB82A23FC9206C274510575
                                                                                                                                                                                                                                                          SHA-512:AE9262DFC35579AEB610DF8BB5F7FBB49232195F55F78402405017681F72C0D2A09FA9EB605B406065A1F44FE6785AC0163870C921DAFFC4746DA6EDA3081521
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Asuncion) {.. {-9223372036854775808 -13840 0 LMT}.. {-2524507760 -13840 0 AMT}.. {-1206389360 -14400 0 -04}.. {86760000 -10800 0 -03}.. {134017200 -14400 0 -04}.. {162878400 -14400 0 -04}.. {181368000 -10800 1 -04}.. {194497200 -14400 0 -04}.. {212990400 -10800 1 -04}.. {226033200 -14400 0 -04}.. {244526400 -10800 1 -04}.. {257569200 -14400 0 -04}.. {276062400 -10800 1 -04}.. {291783600 -14400 0 -04}.. {307598400 -10800 1 -04}.. {323406000 -14400 0 -04}.. {339220800 -10800 1 -04}.. {354942000 -14400 0 -04}.. {370756800 -10800 1 -04}.. {386478000 -14400 0 -04}.. {402292800 -10800 1 -04}.. {418014000 -14400 0 -04}.. {433828800 -10800 1 -04}.. {449636400 -14400 0 -04}.. {465451200 -10800 1 -04}.. {481172400 -14400 0 -04}.. {496987200 -10800 1 -04}.. {512708400 -14400 0 -04}.. {528523200 -10800 1 -04}.. {544244400 -14400 0 -04}.. {5
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):187
                                                                                                                                                                                                                                                          Entropy (8bit):4.791603790249234
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0u55DyXHAIg20u5cvRL/2IAcGE/qlOi+4IAcGEu5B:SlSWB9vsM3y7oDSHAIgpdN/290/qlf+M
                                                                                                                                                                                                                                                          MD5:5A45B70C79F533548B3DD332F988E15B
                                                                                                                                                                                                                                                          SHA1:C7485828619A1D4F5CA59D80ABD197100AC58F64
                                                                                                                                                                                                                                                          SHA-256:518BEB6E54AE811F8C725EA8CC42787D48FC605A3476D6E7A00A1B5733CBD6AC
                                                                                                                                                                                                                                                          SHA-512:A81C2EBE282E019ED011EADDB8F74C3E6FBE88D87E8D8706B3022CDCC48EF92AD90F9BCF9F25031664BB6EFE069EAFDD23D9B55BF672FC7528A2DD8CB6B986B4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Panama)]} {.. LoadTimeZoneFile America/Panama..}..set TZData(:America/Atikokan) $TZData(:America/Panama)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):177
                                                                                                                                                                                                                                                          Entropy (8bit):4.812527147763069
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0/yO5WXHAIg20/yOoNvWARL/2IAcGE/ol7x+IAcGs:SlSWB9vsM3y7/yrHAIgp/yH0AN/290/e
                                                                                                                                                                                                                                                          MD5:13479F64BFBDC7583C637E1562C454B4
                                                                                                                                                                                                                                                          SHA1:2F59484C779B0D6033FC14E205DA9BCAB7A5FCB1
                                                                                                                                                                                                                                                          SHA-256:1D6FEE336E71FFFB64874A830C976867C071EBF6B133C296B32F87E3E7D814C9
                                                                                                                                                                                                                                                          SHA-512:D2C5D35BBBDAB8D58BF6185328124796C06B67ADFB4C1828BA5A9CCA500A01BB8BE69635AE7EEA7FA837A27B20D488A08A29B121DD1617BC373390AD95D67E39
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Adak)]} {.. LoadTimeZoneFile America/Adak..}..set TZData(:America/Atka) $TZData(:America/Adak)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2012
                                                                                                                                                                                                                                                          Entropy (8bit):3.703391569010329
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5/ChlvEw6kSSx5H4a8tf3fku+da2XUd23t8VZDG8+GyOd:VIlvEwJSSxdF8tfMu+da2kdCt8VZy8+K
                                                                                                                                                                                                                                                          MD5:69DCC2477D8D81E2F49D295DB6907190
                                                                                                                                                                                                                                                          SHA1:3C6ED0CEF15D3265C962873480EE1809A4DCACA2
                                                                                                                                                                                                                                                          SHA-256:64F1EC14F6B43FF10B564F839152E88DF9262F0947D1DB347557FA902F6FD48C
                                                                                                                                                                                                                                                          SHA-512:71DEA6D47F267AA7326A011872FA74762FA4F8CD57EB149E3B56B3DE9097B0B9258BC4F6C29188B49FC60C1942869B92D9E59FEE6980A5DA5D0029C383D99F39
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Bahia) {.. {-9223372036854775808 -9244 0 LMT}.. {-1767216356 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2073
                                                                                                                                                                                                                                                          Entropy (8bit):4.021485901155292
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:56hey9WUQwuz/V/NF01Y3A6S++S+vS+QQS+1S+9fS+BrS+HoS+8S+/N5S+5zNZf+:5pUIdFS1Y3FUlWQnH7eelN5Lh9LY5Lj
                                                                                                                                                                                                                                                          MD5:4655AE5AB9C39CA05C1FF36FC366679F
                                                                                                                                                                                                                                                          SHA1:F3F1D08EC35907A8F45AA2CFD097F6DCCA75C9B8
                                                                                                                                                                                                                                                          SHA-256:A6233E5BB0D3B30D0E3B94CD797718041AC3C2E75B387D6646A5C0376C5591CD
                                                                                                                                                                                                                                                          SHA-512:3915B845A312147C5B047096033B3D153E4E83AF4C8E4AAA73C8D12E2A8386CFE8EC4568730F9F28863017A60622DD9CC7D97991C966779B4068BC29F6C6B2B3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Bahia_Banderas) {.. {-9223372036854775808 -25260 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {-873828000 -25200 0 MST}.. {-661539600 -28800 0 PST}.. {28800 -25200 0 MST}.. {828867600 -21600 1 MDT}.. {846403200 -25200 0 MST}.. {860317200 -21600 1 MDT}.. {877852800 -25200 0 MST}.. {891766800 -21600 1 MDT}.. {909302400 -25200 0 MST}.. {923216400 -21600 1 MDT}.. {941356800 -25200 0 MST}.. {954666000 -21600 1 MDT}.. {972806400 -25200 0 MST}.. {989139600 -21600 1 MDT}.. {1001836800 -25200 0 MST}.. {1018170000 -21600 1 MDT}.. {1035705600 -25200 0 MST}.. {1049619600 -21600 1 MDT}.. {1067155200 -25200 0 MST}.. {1081069200 -21600 1 MDT}.. {1099209600 -25200 0 MST}.. {1112518800 -21600 1 MDT}.. {1130659200
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):648
                                                                                                                                                                                                                                                          Entropy (8bit):4.251560000277241
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86290eWmdH9Colj/uFkv/lC1/uFkOzQs/lps/Ozfah/OzT/lN/uFkX/ll/uFki:5TWeUo5Skv/Y1SkA/g/Bh/m/rSkX/zSt
                                                                                                                                                                                                                                                          MD5:DC4FA44B2174A4E6F0644FA8EA2E83F9
                                                                                                                                                                                                                                                          SHA1:C12DF8C862A05D569EAF189272F8BF44303595A1
                                                                                                                                                                                                                                                          SHA-256:FD5E04136506C6543A9ACDC890A30BCF0D561148E1063EC857E3913DE1EBA404
                                                                                                                                                                                                                                                          SHA-512:5AC307CD48132B57215CCBAF0BB63F7FA9C5B28DC9F6217C905885D75B0DF131238D4DB2AE707C3DDEE2EDE6C0914644B435FB1CDD9913600D8B69AE95578B0F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Barbados) {.. {-9223372036854775808 -14309 0 LMT}.. {-1841256091 -14400 0 AST}.. {-874263600 -10800 1 ADT}.. {-862682400 -14400 0 AST}.. {-841604400 -10800 1 ADT}.. {-830714400 -14400 0 AST}.. {-820526400 -14400 0 -0330}.. {-811882800 -12600 1 AST}.. {-798660000 -14400 0 -0330}.. {-788904000 -14400 0 AST}.. {234943200 -10800 1 ADT}.. {244616400 -14400 0 AST}.. {261554400 -10800 1 ADT}.. {276066000 -14400 0 AST}.. {293004000 -10800 1 ADT}.. {307515600 -14400 0 AST}.. {325058400 -10800 1 ADT}.. {338706000 -14400 0 AST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1031
                                                                                                                                                                                                                                                          Entropy (8bit):3.8842563546204225
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5fe300cChlrLPsw6kSS3h5R14eH8tf3xd:5+CChlvEw6kSSx5H4a8tf3xd
                                                                                                                                                                                                                                                          MD5:DFA5E50F6AEF1311A4CF74970477E390
                                                                                                                                                                                                                                                          SHA1:5B63676EB8039B2BE767BAA44820F2DAE5B62876
                                                                                                                                                                                                                                                          SHA-256:549625CCB30BD0E025BAC47668BA3AA0CDD8569E5887E483C8D62B5B7302FA50
                                                                                                                                                                                                                                                          SHA-512:4BBB43694E3B54339C549AC3A5488B77366DB1189D8D1834DCF618D9448084A950B575E207064521B1CDFD2E41F7D1D8C5CD9CEB4668D4459585649556136EB0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Belem) {.. {-9223372036854775808 -11636 0 LMT}.. {-1767213964 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3284
                                                                                                                                                                                                                                                          Entropy (8bit):3.8546064195941097
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5pKSxZwR9IVQU55DG5krgGN8wW+YeD1yyfCwoc:HKSjgIVzrG5krRN8wWheD1yu
                                                                                                                                                                                                                                                          MD5:4DA622B685B3B075CC94FC4E23322547
                                                                                                                                                                                                                                                          SHA1:DEB23F0A434549DAE1BE60ACF757BB212C907B92
                                                                                                                                                                                                                                                          SHA-256:E07F45264E28FD5AA54BD48CB701658509829CF989EC9BD79498D070A1BA270F
                                                                                                                                                                                                                                                          SHA-512:9B00BF8870BC4AAEF7F06FCDFEEEF54686A2CC890103696631EB4DEF5AEEAD051EC9069D70A2B22397F18C0067E03A54E75DA18474D6B1BD3BDA2D5313E0AD16
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Belize) {.. {-9223372036854775808 -21168 0 LMT}.. {-1822500432 -21600 0 CST}.. {-1616954400 -19800 1 -0530}.. {-1606069800 -21600 0 CST}.. {-1585504800 -19800 1 -0530}.. {-1574015400 -21600 0 CST}.. {-1554055200 -19800 1 -0530}.. {-1542565800 -21600 0 CST}.. {-1522605600 -19800 1 -0530}.. {-1511116200 -21600 0 CST}.. {-1490551200 -19800 1 -0530}.. {-1479666600 -21600 0 CST}.. {-1459101600 -19800 1 -0530}.. {-1448217000 -21600 0 CST}.. {-1427652000 -19800 1 -0530}.. {-1416162600 -21600 0 CST}.. {-1396202400 -19800 1 -0530}.. {-1384713000 -21600 0 CST}.. {-1364752800 -19800 1 -0530}.. {-1353263400 -21600 0 CST}.. {-1333303200 -19800 1 -0530}.. {-1321813800 -21600 0 CST}.. {-1301248800 -19800 1 -0530}.. {-1290364200 -21600 0 CST}.. {-1269799200 -19800 1 -0530}.. {-1258914600 -21600 0 CST}.. {-1238349600 -19800 1 -0530}.. {-1226860200 -21600
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):206
                                                                                                                                                                                                                                                          Entropy (8bit):4.938043196147077
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290F490ppv:MByMYbpwt290S90b
                                                                                                                                                                                                                                                          MD5:09FD8280CC890F238126F9641DB7C90E
                                                                                                                                                                                                                                                          SHA1:98AB4E0DE8173C2BB2532B07FAE2E71F588AB26F
                                                                                                                                                                                                                                                          SHA-256:FACD0A835D1F425CD323EE453ADE231810B2D1CF6EBA227BA1B50522AE3879F7
                                                                                                                                                                                                                                                          SHA-512:117C24389B7BFB079F4409B1FA6AA547654D7C69A6CBB19218BF2B96F6CFE3CBAAD400D4C2EFE8A9BFE25F44402057427FC8A62DC20A98018D23A7CF9B87401F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Blanc-Sablon) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1199
                                                                                                                                                                                                                                                          Entropy (8bit):3.7988385604912893
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5EThevwnSRs//SFs/pS9/MHSW/WOSr/nSso/TSL/SSU/iS5X/LcSi/xScd/ZlSQZ:5EHSeSFESoSQSrSsCSeSPS1cSQSQlSsp
                                                                                                                                                                                                                                                          MD5:9529221F9B4E104CC598491703B10E6C
                                                                                                                                                                                                                                                          SHA1:5ACD61B525A18DE1919A7484C92EC5D787DF2F25
                                                                                                                                                                                                                                                          SHA-256:10592EA1CB0D02C06A61059EC601F70A706A5053AC923B9EED29388D5E71EF3A
                                                                                                                                                                                                                                                          SHA-512:66BEDB631469651A5E426155428764E3C1C14483E6FEE1505812E8676EB6E82CF0A88F6CC697F03FDA0AF906D91C7DE6E940DF3D33DD247BEF51DBD9A13DEE16
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Boa_Vista) {.. {-9223372036854775808 -14560 0 LMT}.. {-1767211040 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201200
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):246
                                                                                                                                                                                                                                                          Entropy (8bit):4.69807324941896
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/290bJhDm2OHDgoHvcuknov/zEXPKV2kR/uFhU/KVg:MB86290bLmdHDgCvcukCz8O2Y/uF2/Og
                                                                                                                                                                                                                                                          MD5:AA84D4825AF12087954CCBE711D8A888
                                                                                                                                                                                                                                                          SHA1:364913969307A2C04A0C85391B297FE9DFFB4F78
                                                                                                                                                                                                                                                          SHA-256:23DAAA64D1A902A24A3D0772B078E771562CAE4A1A0FE786C3C704643AE4D24A
                                                                                                                                                                                                                                                          SHA-512:CD902554CEC573120C1F8FF9E026927A1C43D1D2B4DB0E0F0CAD5D192211C540ABCCAF8E53DAF43B4ECE1012DAA624109AEF0073E109FA3191EDDED03D9F4C07
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Bogota) {.. {-9223372036854775808 -17776 0 LMT}.. {-2707671824 -17776 0 BMT}.. {-1739041424 -18000 0 -05}.. {704869200 -14400 1 -05}.. {729057600 -18000 0 -05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8605
                                                                                                                                                                                                                                                          Entropy (8bit):3.8563913604109064
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:eSwtktXNmGaLV911sF7Lv/PCewtA8CzSPyDLbrcUia:/jXNDPlLv/PCenJzS6cy
                                                                                                                                                                                                                                                          MD5:005D0BF1320030A7E9CDC97D0C8BB44B
                                                                                                                                                                                                                                                          SHA1:CB236DA840A49B4BCD261114DCA38DADA567B091
                                                                                                                                                                                                                                                          SHA-256:93AF910CB2AD2203B71C1AD49D56DF4A4A14D07F885AFD4E755271F1372A517C
                                                                                                                                                                                                                                                          SHA-512:16A5483392741673BEC020EF6EBE963AB0FB12629D662C586C27A1E9A1BE3FEA8DC3D05A0E84917B8166E48CADA45C74DFABFDC897A6BC94D3C5058D31AD5126
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Boise) {.. {-9223372036854775808 -27889 0 LMT}.. {-2717640000 -28800 0 PST}.. {-1633269600 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-1601820000 -25200 1 PDT}.. {-1583679600 -28800 0 PST}.. {-1471788000 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126255600 -25200 0 MST}.. {129114000 -21600 0 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):239
                                                                                                                                                                                                                                                          Entropy (8bit):4.821972751564724
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7/MQA+zAHAIgp/MQA+zE5N/290BFzk5h490/MQA+zd:MByMY/MV+zhp/MV+zE5t290rzy490/MW
                                                                                                                                                                                                                                                          MD5:6700956D5FE96CEC8D34EB49FF805374
                                                                                                                                                                                                                                                          SHA1:69B9973EF31AE204EFED7485E59CEA99E00815C8
                                                                                                                                                                                                                                                          SHA-256:DEFC5C9DA2D4D4146145A50D692A6BFF698C3B0A1F19EFD82AD0EE7678F39FCF
                                                                                                                                                                                                                                                          SHA-512:A80C03A519F00A4270248E885463090A34B3992B3DEBA94DD6AEBCC50736541655461E4AA10856125B8EF9B92CEB697429EE7088DBC6AB4FAE383FDF11521B7A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Buenos_Aires)]} {.. LoadTimeZoneFile America/Argentina/Buenos_Aires..}..set TZData(:America/Buenos_Aires) $TZData(:America/Argentina/Buenos_Aires)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8154
                                                                                                                                                                                                                                                          Entropy (8bit):3.865968458565713
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:z+bOGaLV9T1sF7Lv/PCewtA8CzSPyDLbrcUia:6f5lLv/PCenJzS6cy
                                                                                                                                                                                                                                                          MD5:DBF49625E87C9C44748A2C6D51BB1015
                                                                                                                                                                                                                                                          SHA1:A135E864687DB354B4C6195986EA29F8F08B3F08
                                                                                                                                                                                                                                                          SHA-256:172706B4ABBC9B8AFA07069CE49223208601D9DC55A986B5814D2D5E5ED73672
                                                                                                                                                                                                                                                          SHA-512:66FE34FF31C5558DBCE9A22BB18B8830C92CABC0E588C92770121244AAC02FA9EE237D7E56028FB6ADD2E0148A8F8E67C3BEC5F8B369EEA5239FA1F1F81C3626
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cambridge_Bay) {.. {-9223372036854775808 0 0 -00}.. {-1577923200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {136371600 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {167821200 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {230720400 -21600 1 MDT}.. {247046400 -25200 0 MST}.. {262774800 -21600 1 MDT}.. {278496000 -25200 0 MST}.. {294224400 -21600 1 MDT}.. {309945600 -25200 0 MST}.. {325674000 -21600 1 MDT}.. {341395200 -25200 0 MST}.. {357123600 -21600 1 MDT}.. {372844800 -25200 0 MST}.. {388573200 -21600 1 MDT}.. {404899200 -25200 0 MST}.. {420022800 -21600 1 MDT}.. {436348800 -25200 0 MST}.. {452077200 -21600 1 MDT}.. {4
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2918
                                                                                                                                                                                                                                                          Entropy (8bit):3.6039149423727013
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:591PSeSFESoSQSrSsCSeSPS1cSQSQlSsSyZS2SqLSwZS4vSoSUSLpSzS4X3/SxSs:5VsE3LMuJALTvn1ZdP7ZbvLfeAh+KIic
                                                                                                                                                                                                                                                          MD5:230A9F7A87BA56C30ACB3B1732F823F3
                                                                                                                                                                                                                                                          SHA1:8263EA723F2AEA7740C7EC54BE0000A06982D765
                                                                                                                                                                                                                                                          SHA-256:6D5BD1355016B03EDEA58DF98BEC26281CD372725B2DCB60B4D748D2FB4346C8
                                                                                                                                                                                                                                                          SHA-512:C357AA33833DBBDC6BC7DD3F23469EADDF08564AF17D7EE935C8AEA5F35B6E3BBDE1E181BC0DBF264051C4BE139261055633D191413DD610B0150AB3CDE161AF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Campo_Grande) {.. {-9223372036854775808 -13108 0 LMT}.. {-1767212492 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1412
                                                                                                                                                                                                                                                          Entropy (8bit):4.034087321254386
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5s5edTS/uVV3iVP/uaP/uAyAhbS+V8S+FfS+UvS+MS+FB3S+QS+rcS+kS+RS+dSB:5DziZAmELf0On9uhcinzPPoUlWQW3
                                                                                                                                                                                                                                                          MD5:7FBCA91F4B7100C4667F24A9AB263109
                                                                                                                                                                                                                                                          SHA1:163A77FF9EAC49B00B5F838DF4D47F079ECF6A83
                                                                                                                                                                                                                                                          SHA-256:FD6C370F82E5CFE374637E0E222E72570857AC3F85143BEEEF9C3D0E7A6C0D04
                                                                                                                                                                                                                                                          SHA-512:124A5D7F58B38F15A90BA48E63D1D38335371D98A2503E691EC6426EB51E87FD61CA05FCA83573DD1DC06DB9E599302C64D226D5DF13B8A62E0A6943318431BE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cancun) {.. {-9223372036854775808 -20824 0 LMT}.. {-1514743200 -21600 0 CST}.. {377935200 -18000 0 EST}.. {828860400 -14400 1 EDT}.. {846396000 -18000 0 EST}.. {860310000 -14400 1 EDT}.. {877845600 -18000 0 EST}.. {891759600 -14400 1 EDT}.. {902041200 -18000 0 CDT}.. {909298800 -21600 0 CST}.. {923212800 -18000 1 CDT}.. {941353200 -21600 0 CST}.. {954662400 -18000 1 CDT}.. {972802800 -21600 0 CST}.. {989136000 -18000 1 CDT}.. {1001833200 -21600 0 CST}.. {1018166400 -18000 1 CDT}.. {1035702000 -21600 0 CST}.. {1049616000 -18000 1 CDT}.. {1067151600 -21600 0 CST}.. {1081065600 -18000 1 CDT}.. {1099206000 -21600 0 CST}.. {1112515200 -18000 1 CDT}.. {1130655600 -21600 0 CST}.. {1143964800 -18000 1 CDT}.. {1162105200 -21600 0 CST}.. {1175414400 -18000 1 CDT}.. {1193554800 -21600 0 CST}.. {1207468800 -18000 1 CDT}.. {1225004400 -21600 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):4.588048586971241
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2909+ETlDm2OHXoHv8HkISlvFVFQVgVJUF/R/OXFxWnVVFQVgVVvR/e:MB86290XmdHXCvydSltvAUeFZ/O/qVva
                                                                                                                                                                                                                                                          MD5:5DDB49759D58931A06740A14F76B431C
                                                                                                                                                                                                                                                          SHA1:E9AC99265D42D140E12BB4DAAA24FABAC65E79FA
                                                                                                                                                                                                                                                          SHA-256:D558C25F165E956E980AA8F554AB3BF24E91B51EADBD2B1065EF6DFDA0E2F984
                                                                                                                                                                                                                                                          SHA-512:318804ED41F36A3A8746C8CD286116787A768B06CAD6057559D1C7105170DE6EAB807EFA52AA8A0E353491B6F8C47D623D4473C1AEAD20B5C00747E07BB282B2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Caracas) {.. {-9223372036854775808 -16064 0 LMT}.. {-2524505536 -16060 0 CMT}.. {-1826739140 -16200 0 -0430}.. {-157750200 -14400 0 -04}.. {1197183600 -16200 0 -0430}.. {1462086000 -14400 0 -04}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):227
                                                                                                                                                                                                                                                          Entropy (8bit):4.666638841481612
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7/MMXAXHAIgp/MMXmRN/29094SXAFB5290/MMXAy:MByMY/MYp/MrRt290mh5290/MK
                                                                                                                                                                                                                                                          MD5:EEB851BE330BCC44A4831763534058B9
                                                                                                                                                                                                                                                          SHA1:A5FC3E69DDBD3C40D9EB4317BBD5BB6C78751B36
                                                                                                                                                                                                                                                          SHA-256:37CD6BDAA6C6EEDFAC3288CA1C11F5CBBE8A17E5F2E790E7635A64B867AFBD87
                                                                                                                                                                                                                                                          SHA-512:7CD0BC822550325EB3198B4AD6CCD38938FA654A03A09C53117560D1FE3FDCD9C892D105F0D7AF44ED52DD7E0475721240D74A10C98619BE9EC4F5410B8FD87D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Catamarca)]} {.. LoadTimeZoneFile America/Argentina/Catamarca..}..set TZData(:America/Catamarca) $TZData(:America/Argentina/Catamarca)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.832612867310476
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2IAcGE91INMXGm2OHEFvpoeoHsdR4FIUPvGXFkUwXvp3VVV:SlSWB9eg/2909qDm2OHEdGeoHm4vOXF6
                                                                                                                                                                                                                                                          MD5:6052E52C8E5A5F43102C47D895797A1F
                                                                                                                                                                                                                                                          SHA1:23DBD40AE96C84E44ADCD1AC33E7871D217C17BC
                                                                                                                                                                                                                                                          SHA-256:873285F3E13CB68DD28EB109ECAD8D260E11A9FF6DF6A4E8E0D4C00B0182695B
                                                                                                                                                                                                                                                          SHA-512:DDE89C70B6F24AD4F585DC5424A6D029E5C898254C9085C588AE699CED4C8316840FF7C87685D7CFAA2E689F01687985454A0C9E3886342E936C56AB688DF732
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cayenne) {.. {-9223372036854775808 -12560 0 LMT}.. {-1846269040 -14400 0 -04}.. {-71092800 -10800 0 -03}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.774923706273939
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0u55DyXHAIg20u5cvRL/2IAcGE91mr4IAcGEu5pvn:SlSWB9vsM3y7oDSHAIgpdN/2909Yr49F
                                                                                                                                                                                                                                                          MD5:AD6E086BEDF05A0BEB66990BD9518BEE
                                                                                                                                                                                                                                                          SHA1:FA0B7E8D6931E79092A90F7EECBA2293AE886AE3
                                                                                                                                                                                                                                                          SHA-256:C38C49AE1C3E67BD2118002DCFCC3C0EFB6892FB9B0106908A9282C414D0BF2E
                                                                                                                                                                                                                                                          SHA-512:A1E40422D15DBCB24A6FE353639A1541FAD7F394D20F8AEB32D4E39667BA264C3E815BAA703B88B90D381540168016A0641CA220BACAF05E80EAA698642B6FFA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Panama)]} {.. LoadTimeZoneFile America/Panama..}..set TZData(:America/Cayman) $TZData(:America/Panama)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11372
                                                                                                                                                                                                                                                          Entropy (8bit):3.814348526052702
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:l6u30Ke1rdJ8SUklvgahLi8hbZlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:l1EKwdJ8SUkl4aUqtfA604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:763E23AA7FB20F8D7CB2F0E87FAFD153
                                                                                                                                                                                                                                                          SHA1:B131A10C1C208BB5E5E178ACD21A679FD0537AC5
                                                                                                                                                                                                                                                          SHA-256:C7707AF88D650F90839E7258356E39D85228B33B6DBCC5C065C3D8733AE28CEE
                                                                                                                                                                                                                                                          SHA-512:FE9C5D2EA253338DDFD79CC8ED2F94D6817BD770C0895752EFB1917E2313735C18475D67191C29BCCD53DEFFF35C1BF0CA5D98C92091DDCD1E97CD6302DC73A4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Chicago) {.. {-9223372036854775808 -21036 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-1577901600 -21600 0 CST}.. {-1563724800 -18000 1 CDT}.. {-1551632400 -21600 0 CST}.. {-1538928000 -18000 1 CDT}.. {-1520182800 -21600 0 CST}.. {-1504454400 -18000 1 CDT}.. {-1491757200 -21600 0 CST}.. {-1473004800 -18000 1 CDT}.. {-1459702800 -21600 0 CST}.. {-1441555200 -18000 1 CDT}.. {-1428253200 -21600 0 CST}.. {-1410105600 -18000 1 CDT}.. {-1396803600 -21600 0 CST}.. {-1378656000 -18000 1 CDT}.. {-1365354000 -21600 0 CST}.. {-1347206400 -18000 1 CDT}.. {-1333904400 -21600 0 CST}.. {-1315152000 -18000 1 CDT}.. {-1301850000 -21600 0 CST}.. {-1283702400 -18000 1 CDT}.. {-1270400400 -21600 0 CST}.. {-1252252800 -18000 1 CDT}.. {-1238950800
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2040
                                                                                                                                                                                                                                                          Entropy (8bit):4.006586050664275
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5wE2e49WU0S+VS+TjV/NF01YmM/parZ375+XiBn:5wEvU033FS1YrpaV5+yBn
                                                                                                                                                                                                                                                          MD5:67738E07092EDB5A9F484ED5CA217EFB
                                                                                                                                                                                                                                                          SHA1:9E428C67AE4BDACA48D189DF60374F3B6523E120
                                                                                                                                                                                                                                                          SHA-256:93438D65EA8F95691748FF749219FAFA1940469BC61CED0B7CBF995B417F20B4
                                                                                                                                                                                                                                                          SHA-512:57C9FE7EAE37504465F33B2AB079ED91700528E330D227E94AE8A06C58DEFA65F1EA1CDF89F835910D92D037DADB45E684A2EA96512B08F83650DD33CCEB8EB6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Chihuahua) {.. {-9223372036854775808 -25460 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {820476000 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {883634400 -21600 0 CST}.. {891766800 -21600 0 MDT}.. {909302400 -25200 0 MST}.. {923216400 -21600 1 MDT}.. {941356800 -25200 0 MST}.. {954666000 -21600 1 MDT}.. {972806400 -25200 0 MST}.. {989139600 -21600 1 MDT}.. {1001836800 -25200 0 MST}.. {1018170000 -21600 1 MDT}.. {1035705600 -25200 0 MST}.. {1049619600 -21600 1 MDT}.. {1067155200 -25200 0 MST}.. {1081069200 -21600 1 MDT}.. {1099209600 -25200 0 MST}.. {1112518800 -21600 1 MDT}.. {1130659200 -25200 0 MST}.. {1143968400 -
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6657
                                                                                                                                                                                                                                                          Entropy (8bit):3.80139797662668
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5T5U9RM/6M/Mp5tyTc8Ln4ypZ9giGuWGwZIoktiz+hL5Cw5feQ5YcT5rBSNNOVQ+:d5LNfzo+C2mWYcNQMsmNTxf6AeO+cblX
                                                                                                                                                                                                                                                          MD5:D4137B6046EE2ABFF42B16B8E5600224
                                                                                                                                                                                                                                                          SHA1:1885B2E30A4973693D3B3AB0546E56F0AC104EDE
                                                                                                                                                                                                                                                          SHA-256:68D45B552D5967172AB7685750C85866D9B4AD25E18C0E837C0CF74B0AB6510D
                                                                                                                                                                                                                                                          SHA-512:78A47479B7BAFE6C28E07A03218AE6059BC992405D58F589CAA99810CEA7F2C5A000EF71B62783C47D0C94B3BE9A5A5C6A477DEA5321B952312A5CA101E987A2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Ciudad_Juarez) {. {-9223372036854775808 -25556 0 LMT}. {-1514739600 -25200 0 MST}. {-1343066400 -21600 0 CST}. {-1234807200 -25200 0 MST}. {-1220292000 -21600 1 MDT}. {-1207159200 -25200 0 MST}. {-1191344400 -21600 0 CST}. {820476000 -21600 0 CST}. {828864000 -18000 1 CDT}. {846399600 -21600 0 CST}. {860313600 -18000 1 CDT}. {877849200 -21600 0 CST}. {883634400 -21600 0 CST}. {891766800 -21600 0 MDT}. {909302400 -25200 0 MST}. {923216400 -21600 1 MDT}. {941356800 -25200 0 MST}. {954666000 -21600 1 MDT}. {972806400 -25200 0 MST}. {989139600 -21600 1 MDT}. {1001836800 -25200 0 MST}. {1018170000 -21600 1 MDT}. {1035705600 -25200 0 MST}. {1049619600 -21600 1 MDT}. {1067155200 -25200 0 MST}. {1081069200 -21600 1 MDT}. {1099209600 -25200 0 MST}. {1112518800 -21600 1 MDT}. {1130659200 -25200 0 MST}. {1143968400 -21600 1 MDT}. {1162108800
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):192
                                                                                                                                                                                                                                                          Entropy (8bit):4.844590153688034
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0u55DyXHAIg20u5cvRL/2IAcGE9WtEaQXs+IAcGEi:SlSWB9vsM3y7oDSHAIgpdN/2909qEacn
                                                                                                                                                                                                                                                          MD5:A0BF04CD77026DC1D2749848AB0EE45E
                                                                                                                                                                                                                                                          SHA1:EA0F1BC11379DF2E421675BC5DE4805CE94B96D6
                                                                                                                                                                                                                                                          SHA-256:C8CBF5A29CC1D0827390CA6E98B2EFCF90743C6DD0ECA143B300050DD4164041
                                                                                                                                                                                                                                                          SHA-512:61968B4E42ECC60C801F959D18D13187AD39D9B81FA1A947F6B6862F99D73E3A30849AC4233DB5705D46F5373C42D8748B15BE9B82822971B4F47E601E5766D8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Panama)]} {.. LoadTimeZoneFile America/Panama..}..set TZData(:America/Coral_Harbour) $TZData(:America/Panama)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):219
                                                                                                                                                                                                                                                          Entropy (8bit):4.78887878252354
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7/MSHAIgp/M1ovN/29093+90/M7:MByMY/M7p/M16t290c90/M7
                                                                                                                                                                                                                                                          MD5:C7CCF5CEC7AA60D6063D1C30F4263ADC
                                                                                                                                                                                                                                                          SHA1:FD8E9AEEEE50656FD3C694CA051895DDC8E5590B
                                                                                                                                                                                                                                                          SHA-256:28B84710EADEF7AD5E7FA63EF519A9D93996D3BB91DD9018333DE3AC4D8FB8DD
                                                                                                                                                                                                                                                          SHA-512:6974F8B238977EE5222368C4B79327BB240580819FCA082261D6994781144D81E2E8843B4F1C9D07EFBEE27311C8930BDAC9C0D6D6718F6FB1600D0000576CDE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Cordoba)]} {.. LoadTimeZoneFile America/Argentina/Cordoba..}..set TZData(:America/Cordoba) $TZData(:America/Argentina/Cordoba)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):431
                                                                                                                                                                                                                                                          Entropy (8bit):4.506976345480408
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86290lnmdHd5CvZN/Mi3yvI8/uF+wSJz/uF+IA/uF+i/X8/uF+ZDVxNv:5mnedIvZN/e5S+w+S+LS+i0S+pB
                                                                                                                                                                                                                                                          MD5:0446EF1A6985A62EDFFB9FFAC7F1DE0E
                                                                                                                                                                                                                                                          SHA1:A43468E120E585E2DCC20205BA1D1E2CCB6C0BC2
                                                                                                                                                                                                                                                          SHA-256:E3061DC6FA9F869F013351A9FDF420448592D7F959C2B4404093432508146F7E
                                                                                                                                                                                                                                                          SHA-512:86D41B0C49489572C3EAEDD5466AA92319C721CCEC9437EBB0F2AAD772FB5ED91A2F2061E00448FB48096B0BAAE9A4E1E644F8AF595B76BE05DBC0C801E6D6ED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Costa_Rica) {.. {-9223372036854775808 -20173 0 LMT}.. {-2524501427 -20173 0 SJMT}.. {-1545071027 -21600 0 CST}.. {288770400 -18000 1 CDT}.. {297234000 -21600 0 CST}.. {320220000 -18000 1 CDT}.. {328683600 -21600 0 CST}.. {664264800 -18000 1 CDT}.. {678344400 -21600 0 CST}.. {695714400 -18000 1 CDT}.. {700635600 -21600 0 CST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.8664633847782905
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0utLaDovXHAIg20utLRYovHRL/2IAcGE9mM7x/h4y:SlSWB9vsM3y7OBHAIgpONYyHN/2909vr
                                                                                                                                                                                                                                                          MD5:0757DD22C0E297CCE8E6678ECA4B39C7
                                                                                                                                                                                                                                                          SHA1:81B31299F9A35C8BA2EC1F59EC21129FFCDCD52F
                                                                                                                                                                                                                                                          SHA-256:A01DDB460420C8765CE8EF7A7D031ABD7BDB17CFA548E7C3B8574C388AA21E17
                                                                                                                                                                                                                                                          SHA-512:F1AFC0F6371A10E4CB74FB2C8985610AEE6C3511861BC09384EDC99D250E9099A1F4430BFC3B0B396C2702BF9991A5A4ECFD53A82C92883460715FA2C1E04579
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Phoenix)]} {.. LoadTimeZoneFile America/Phoenix..}..set TZData(:America/Creston) $TZData(:America/Phoenix)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2912
                                                                                                                                                                                                                                                          Entropy (8bit):3.588248620238414
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5tSeSFESoSQSrSsCSeSPS1cSQSQlSsSyZS2SqLSwZS4vSoSUSLpSzS4X3/SxS1S4:rVsE3LMuJALTvn1ZdP7ZbvLfeAh+KIil
                                                                                                                                                                                                                                                          MD5:264E0CEA9491B404993594E64F13479F
                                                                                                                                                                                                                                                          SHA1:6D4D277FA470A2C7AD0A59B5DA3CC15BEEB74E78
                                                                                                                                                                                                                                                          SHA-256:2D8281CF3FD9E859C5206F781E264854FA876CB36562A08C6C01343C65F8A508
                                                                                                                                                                                                                                                          SHA-512:759C19B4DD0E1F7F1176872806BFB1F17ADF9C992E41B96FEA67D77DD67E9DD3C1683E3B6D27FB092C731F534C6A7441BACFFF0301907217A064523B86992E23
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cuiaba) {.. {-9223372036854775808 -13460 0 LMT}.. {-1767212140 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201200 -1
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):201
                                                                                                                                                                                                                                                          Entropy (8bit):4.876961543280111
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/2909C4e90ppv:MByMYbpwt290690b
                                                                                                                                                                                                                                                          MD5:9459043060E33E8EDC74E78332E96EDF
                                                                                                                                                                                                                                                          SHA1:27963FE063965584D0F226BAE9A08EB2954398F0
                                                                                                                                                                                                                                                          SHA-256:ACCF08CF53C9431E226714DF8BEDE3C91BAF62D5BD7B98CA8B50D7258124D129
                                                                                                                                                                                                                                                          SHA-512:215D9AFAA7227F4447177CE2ABA5A6F7F2F46A9D787845DD32F10D5C22BF9CBE4047AF5E0E66FA7A4F70EEE064A7EC7B67949E565C3C5C60C31F3C19D6915D76
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Curacao) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1128
                                                                                                                                                                                                                                                          Entropy (8bit):3.8794180227436557
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5geNrmFQqFi77FkiVFw1ZFt9SFUXDFH9vMF0mFdS/FyMF8AWXF7HFEJF7cSXHVFS:5/vx7O11pbzvZ+S0xAqe12vey
                                                                                                                                                                                                                                                          MD5:6E37A78AC686A6B48A78541E1900E33C
                                                                                                                                                                                                                                                          SHA1:D41F39FDB6D45921B57341E95A006251B4875961
                                                                                                                                                                                                                                                          SHA-256:968C56F1D0106E1D92C7B094EEF528B6EE1FFA3D7A18BE2F2BA59178C2C0F1E0
                                                                                                                                                                                                                                                          SHA-512:397623149D95FF9A094750EE697F62DF90124BBBE407FB49FBAE335A61629449F2A61EF4471DBD57745B323DFCF3628611CAE9295F2EF7E4A7412A697651FF68
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Danmarkshavn) {.. {-9223372036854775808 -4480 0 LMT}.. {-1686091520 -10800 0 -03}.. {323845200 -7200 0 -02}.. {338950800 -10800 0 -03}.. {354675600 -7200 1 -02}.. {370400400 -10800 0 -03}.. {386125200 -7200 1 -02}.. {401850000 -10800 0 -03}.. {417574800 -7200 1 -02}.. {433299600 -10800 0 -03}.. {449024400 -7200 1 -02}.. {465354000 -10800 0 -03}.. {481078800 -7200 1 -02}.. {496803600 -10800 0 -03}.. {512528400 -7200 1 -02}.. {528253200 -10800 0 -03}.. {543978000 -7200 1 -02}.. {559702800 -10800 0 -03}.. {575427600 -7200 1 -02}.. {591152400 -10800 0 -03}.. {606877200 -7200 1 -02}.. {622602000 -10800 0 -03}.. {638326800 -7200 1 -02}.. {654656400 -10800 0 -03}.. {670381200 -7200 1 -02}.. {686106000 -10800 0 -03}.. {701830800 -7200 1 -02}.. {717555600 -10800 0 -03}.. {733280400 -7200 1 -02}.. {749005200 -10800 0 -03}.. {764730000 -72
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3028
                                                                                                                                                                                                                                                          Entropy (8bit):3.9546287557089177
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5IeVvxBn4nRfngnjSXrwIwEg7MkwY7Twbg7Uwr70vwHg7b6wa7gAHwc7/wzZg7yA:5zxKfpj/AOZFCARCeQbvb5wxMN6Ix
                                                                                                                                                                                                                                                          MD5:DDDAA5386F94219C84F966851693B86B
                                                                                                                                                                                                                                                          SHA1:9B084FA2B323F4AF2BD3BC5962030A329FB68A27
                                                                                                                                                                                                                                                          SHA-256:685A9281E2E864562D35EFDDD39F553B89192C7FE0CE9F29CF51B8332A88A843
                                                                                                                                                                                                                                                          SHA-512:D09B5B12317D27B2E9EEE6FBD745FCD67C6ED1DFC2828997C46537622D474BF458D79831CC0635702321E10008EFC57B4958AA9CB26746F411E60088FFD4C306
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Dawson) {.. {-9223372036854775808 -33460 0 LMT}.. {-2188996940 -32400 0 YST}.. {-1632056400 -28800 1 YDT}.. {-1615125600 -32400 0 YST}.. {-1596978000 -28800 1 YDT}.. {-1583164800 -32400 0 YST}.. {-880203600 -28800 1 YWT}.. {-769395600 -28800 1 YPT}.. {-765381600 -32400 0 YST}.. {-157734000 -32400 0 YST}.. {-147884400 -25200 1 YDDT}.. {-131554800 -32400 0 YST}.. {120646800 -28800 0 PST}.. {315561600 -28800 0 PST}.. {325677600 -25200 1 PDT}.. {341398800 -28800 0 PST}.. {357127200 -25200 1 PDT}.. {372848400 -28800 0 PST}.. {388576800 -25200 1 PDT}.. {404902800 -28800 0 PST}.. {420026400 -25200 1 PDT}.. {436352400 -28800 0 PST}.. {452080800 -25200 1 PDT}.. {467802000 -28800 0 PST}.. {483530400 -25200 1 PDT}.. {499251600 -28800 0 PST}.. {514980000 -25200 1 PDT}.. {530701200 -28800 0 PST}.. {544615200 -25200 1 PDT}.. {562150800 -28800 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1940
                                                                                                                                                                                                                                                          Entropy (8bit):4.024810417421672
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5/eUv5wk7Zw9JmnRsw78wP+7bw+7zwN7SynwpBZ7Fwk47H+wW73wo5775w572Iwl:5DuY/YRRvkGZ+R64CjSUlTGS
                                                                                                                                                                                                                                                          MD5:7868720D39782147B2BD6B039A5BF7E0
                                                                                                                                                                                                                                                          SHA1:6F66404E5CCFF7F020269A316D792D5E7AD4C280
                                                                                                                                                                                                                                                          SHA-256:540804BECDEAB92340EF02D32A62BFD550B71A3DB8D829BE426EE4D210004643
                                                                                                                                                                                                                                                          SHA-512:9CCD124FF954CA2988F07286FFE9ED740E0CEF5F4D76BF090367B74A577E91BF5590EDFE12AFC83ACF5CBFC88C5A68867C58082A2777D08C326A7B18889B08E2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Dawson_Creek) {.. {-9223372036854775808 -28856 0 LMT}.. {-2713881544 -28800 0 PST}.. {-1632060000 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-725817600 -28800 0 PST}.. {-715788000 -25200 1 PDT}.. {-702486000 -28800 0 PST}.. {-684338400 -25200 1 PDT}.. {-671036400 -28800 0 PST}.. {-652888800 -25200 1 PDT}.. {-639586800 -28800 0 PST}.. {-620834400 -25200 1 PDT}.. {-608137200 -28800 0 PST}.. {-589384800 -25200 1 PDT}.. {-576082800 -28800 0 PST}.. {-557935200 -25200 1 PDT}.. {-544633200 -28800 0 PST}.. {-526485600 -25200 1 PDT}.. {-513183600 -28800 0 PST}.. {-495036000 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463586400 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431532000 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {-400082400 -25200 1 PDT}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8920
                                                                                                                                                                                                                                                          Entropy (8bit):3.8540632258197514
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:gjGtwmGaLV911sF7Lv/PCewtA8CzSPyDLbrcUia:gUwDPlLv/PCenJzS6cy
                                                                                                                                                                                                                                                          MD5:0D649599A899ECB3FCF2783DCEE3E37B
                                                                                                                                                                                                                                                          SHA1:ACC796BE75F41A12FB1F8CCBD2B2839AF9876FFE
                                                                                                                                                                                                                                                          SHA-256:3FE2EE8C05C5D6F268B58BD9FC3E3A845DEA257473B29F7B3FB403E917448F3C
                                                                                                                                                                                                                                                          SHA-512:C10D41AB95439B8E978F12F9F58D1ACC9AD15404123FA5FBA0D1CC716E5CF5DA6BD2252450055AC3998DBCB8DD49F7A82ACD53413E3EE78CDA2C42F603DE2C56
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Denver) {.. {-9223372036854775808 -25196 0 LMT}.. {-2717643600 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-1577898000 -25200 0 MST}.. {-1570374000 -21600 1 MDT}.. {-1551628800 -25200 0 MST}.. {-1538924400 -21600 1 MDT}.. {-1534089600 -25200 0 MST}.. {-883587600 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-757357200 -25200 0 MST}.. {-147884400 -21600 1 MDT}.. {-131558400 -25200 0 MST}.. {-116434800 -21600 1 MDT}.. {-100108800 -25200 0 MST}.. {-94669200 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -2
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8430
                                                                                                                                                                                                                                                          Entropy (8bit):3.826664943157435
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:SGiS1A5tCt/cL1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:SG/K5ItON0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:2BBA922E9377D257CBDF6E1367BBB1A2
                                                                                                                                                                                                                                                          SHA1:6F33A44834E8041E78660A326A5DDAF3D7F9DC2A
                                                                                                                                                                                                                                                          SHA-256:84F6897B87D3978D30D35097B78C55434CE55EB65D6E488A391DFC3B3BB5A8FE
                                                                                                                                                                                                                                                          SHA-512:D225824945C08A3521A8288B92B26DFFA712ED3505E72DEDE4A7D1777E58DEA79ADF3F042D22624E4142DD4203BAA4DFF8EB08B7033FDF00059F6C39954EA1A1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Detroit) {.. {-9223372036854775808 -19931 0 LMT}.. {-2051202469 -21600 0 CST}.. {-1724083200 -18000 0 EST}.. {-883594800 -18000 0 EST}.. {-880218000 -14400 1 EWT}.. {-769395600 -14400 1 EPT}.. {-765396000 -18000 0 EST}.. {-757364400 -18000 0 EST}.. {-684349200 -14400 1 EDT}.. {-671047200 -18000 0 EST}.. {-80506740 -14400 0 EDT}.. {-68666400 -18000 0 EST}.. {-52938000 -14400 1 EDT}.. {-37216800 -18000 0 EST}.. {-31518000 -18000 0 EST}.. {94712400 -18000 0 EST}.. {104914800 -14400 1 EDT}.. {120636000 -18000 0 EST}.. {126687600 -14400 1 EDT}.. {152085600 -18000 0 EST}.. {157784400 -18000 0 EST}.. {167814000 -14400 0 EDT}.. {183535200 -18000 0 EST}.. {199263600 -14400 1 EDT}.. {215589600 -18000 0 EST}.. {230713200 -14400 1 EDT}.. {247039200 -18000 0 EST}.. {262767600 -14400 1 EDT}.. {278488800 -18000 0 EST}.. {294217200 -14400 1 EDT}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):202
                                                                                                                                                                                                                                                          Entropy (8bit):4.86856578093135
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290TL3290ppv:MByMYbpwt290Tr290b
                                                                                                                                                                                                                                                          MD5:398D8DBB24CEA2D174EF05F63869C94A
                                                                                                                                                                                                                                                          SHA1:6D0E04165952E873E6ECA33A0E54761B747F0A98
                                                                                                                                                                                                                                                          SHA-256:3DA98AA7D3085845779BE8ED6C93CCBDA92191F17CA67BBF779803E21DA2ABF3
                                                                                                                                                                                                                                                          SHA-512:2652AFD1A3F8A4B84078A964005FE10C64491EC2D47CDE57D5066D07D1D837308FD696F53B9E7B6B0E72F86F9A85128B8CBF5F302F91EADE6D840DF946DE85CD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Dominica) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8600
                                                                                                                                                                                                                                                          Entropy (8bit):3.8579895970456137
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:7SabOGaLm911sF7Lv/PCewtA8CzSPyDLbrcUia:7vf4lLv/PCenJzS6cy
                                                                                                                                                                                                                                                          MD5:EBD169ECA4D45EED28BF7B27809361BC
                                                                                                                                                                                                                                                          SHA1:E89C8484A29D792FB6349CFDFDD30C2FA6B78B6B
                                                                                                                                                                                                                                                          SHA-256:026D51D73D30A3710288F440E0C337E44E3A14D0AA2D7B6C6E53AF43FC72A90C
                                                                                                                                                                                                                                                          SHA-512:45C936ED7D4AF95261180547013454AAEC9FA7672B52AC6077DD99D9FEB6DDD57652FE4EC67BF81F1588384F3027A1872E0C72D9CAEB980B66D2CB6EE9B8ABB0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Edmonton) {.. {-9223372036854775808 -27232 0 LMT}.. {-1998663968 -25200 0 MST}.. {-1632063600 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1600614000 -21600 1 MDT}.. {-1596816000 -25200 0 MST}.. {-1567954800 -21600 1 MDT}.. {-1551628800 -25200 0 MST}.. {-1536505200 -21600 1 MDT}.. {-1523203200 -25200 0 MST}.. {-1504450800 -21600 1 MDT}.. {-1491753600 -25200 0 MST}.. {-1473001200 -21600 1 MDT}.. {-1459699200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-715791600 -21600 1 MDT}.. {-702489600 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {136371600 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {167821200 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {23072
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1230
                                                                                                                                                                                                                                                          Entropy (8bit):3.7989525000422963
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5OXUepdkZss/uuD/uVK/uNC/uvFe/uxJs/u74O/u83C/uc8J/uhF8/uNHs/ulU6w:5OXCZsMw57XJh4CxUF/A6GTrtSUUhfL0
                                                                                                                                                                                                                                                          MD5:6766E75702D8C2D1C986DFCEFCE554F9
                                                                                                                                                                                                                                                          SHA1:39553F80D82BC0134FAF70C9830B96BDCBCEFF1C
                                                                                                                                                                                                                                                          SHA-256:48FC987E5999EA79F24797E0450FE4DAB7CF320DFAD7A47A8A1E037077EC42C9
                                                                                                                                                                                                                                                          SHA-512:A812D0D4254BB0B7DB7AE116652D2A8F97D22C59F2709A17D1CE435FCFB38B807A4E0ED6EA114A66897E29D85226875FA84D28B254A5D17BD1CBA95FAD8349B7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Eirunepe) {.. {-9223372036854775808 -16768 0 LMT}.. {-1767208832 -18000 0 -05}.. {-1206950400 -14400 1 -05}.. {-1191355200 -18000 0 -05}.. {-1175367600 -14400 1 -05}.. {-1159819200 -18000 0 -05}.. {-633812400 -14400 1 -05}.. {-622062000 -18000 0 -05}.. {-602276400 -14400 1 -05}.. {-591825600 -18000 0 -05}.. {-570740400 -14400 1 -05}.. {-560203200 -18000 0 -05}.. {-539118000 -14400 1 -05}.. {-531345600 -18000 0 -05}.. {-191358000 -14400 1 -05}.. {-184190400 -18000 0 -05}.. {-155156400 -14400 1 -05}.. {-150062400 -18000 0 -05}.. {-128890800 -14400 1 -05}.. {-121118400 -18000 0 -05}.. {-99946800 -14400 1 -05}.. {-89582400 -18000 0 -05}.. {-68410800 -14400 1 -05}.. {-57960000 -18000 0 -05}.. {499755600 -14400 1 -05}.. {511243200 -18000 0 -05}.. {530600400 -14400 1 -05}.. {540273600 -18000 0 -05}.. {562136400 -14400 1 -05}.. {571204800
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):279
                                                                                                                                                                                                                                                          Entropy (8bit):4.760311149376001
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/29078iPDm2OHvJ4YoHxHhgdrV/uF+IcmJ3/uF+ivNv:MB8629078AmdHx4YCJSB/uF+QV/uF+w9
                                                                                                                                                                                                                                                          MD5:CEF7277443EB6990E72C7EA7F79A122C
                                                                                                                                                                                                                                                          SHA1:1D3FEA364B3DC129DE3998A1455D5588EBAA6FF8
                                                                                                                                                                                                                                                          SHA-256:C02C6E79398553BD07BEA0BE4B7F0EBDD8BC821595909CFFB49DE4290A0D1D0F
                                                                                                                                                                                                                                                          SHA-512:E6FC530B2CCF010B8D38BC3F49A6859B5C68F4AB604E6305CE75FBE4FC9FF3FCD0187DEBEF6DAE652EEF9695568DBDE31F426E404CC3CC206D78183E0D919234
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/El_Salvador) {.. {-9223372036854775808 -21408 0 LMT}.. {-1546279392 -21600 0 CST}.. {547020000 -18000 1 CDT}.. {559717200 -21600 0 CST}.. {578469600 -18000 1 CDT}.. {591166800 -21600 0 CST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.836337676384058
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qfSfXHAIg20qfORL/2IAcGE7JM7QIAcGEqfBn:SlSWB9vsM3y7ekHAIgpeON/2907390eB
                                                                                                                                                                                                                                                          MD5:005D9C0E50291616A727CFB74A9FD37E
                                                                                                                                                                                                                                                          SHA1:846AE6720382B4F67B37B4256E45246C81DAF899
                                                                                                                                                                                                                                                          SHA-256:3E363BF82545F24CCE8CFA6EEC97BA6E1C2A7730B2A9CE6C48F784821D308A5D
                                                                                                                                                                                                                                                          SHA-512:452326D11D01825764BC40A77D17444D822F3AA202582233DD8B122798478FA83E3A27A02508EAC4CF0C7922AC2563742D773AA870562AE496B34FBB41FBAD63
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Tijuana)]} {.. LoadTimeZoneFile America/Tijuana..}..set TZData(:America/Ensenada) $TZData(:America/Tijuana)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4578
                                                                                                                                                                                                                                                          Entropy (8bit):3.8944281193962818
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5QIgsB/YRRvkGZ+R64CjSUlTG5Al5pj/A1ZFCARCeQbvb5+:6IgzR864CjSETG5sjgZkR/bvt+
                                                                                                                                                                                                                                                          MD5:4A4E023F635C4202018EA9E8F85B5047
                                                                                                                                                                                                                                                          SHA1:38E121FE2D419413E9E791B6C22BFC8D9F7554BC
                                                                                                                                                                                                                                                          SHA-256:AB15023807E7C7D1026C9970D190F1B405D48952464025242C2BB6C6BBB8391A
                                                                                                                                                                                                                                                          SHA-512:F10D21A2C841224879D1C817FC7F477DF582E1BC3603666B55199C098D51D1D5429F8C088C1083C07FC7588AE5C42A1DFBCC6B7C636AD1BE84ED657807A229E5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Fort_Nelson) {.. {-9223372036854775808 -29447 0 LMT}.. {-2713880953 -28800 0 PST}.. {-1632060000 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-757353600 -28800 0 PST}.. {-725817600 -28800 0 PST}.. {-715788000 -25200 1 PDT}.. {-702486000 -28800 0 PST}.. {-684338400 -25200 1 PDT}.. {-671036400 -28800 0 PST}.. {-652888800 -25200 1 PDT}.. {-639586800 -28800 0 PST}.. {-620834400 -25200 1 PDT}.. {-608137200 -28800 0 PST}.. {-589384800 -25200 1 PDT}.. {-576082800 -28800 0 PST}.. {-557935200 -25200 1 PDT}.. {-544633200 -28800 0 PST}.. {-526485600 -25200 1 PDT}.. {-513183600 -28800 0 PST}.. {-495036000 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463586400 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431532000 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):231
                                                                                                                                                                                                                                                          Entropy (8bit):4.778858143786314
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y73GK7JHAIgp3GKZRN/290HXYAp4903GK8:MByMY3GK7Kp3GKnt290Hz4903GK8
                                                                                                                                                                                                                                                          MD5:24C369A3091452DCA7AAEBF4F48F5289
                                                                                                                                                                                                                                                          SHA1:2C2174CB16F490689E6FAC17B6D18F4A0DBD2DC9
                                                                                                                                                                                                                                                          SHA-256:C8948616262CF6990739343ABBBD237E572DB49310099E21DD8F9E317F7D11B3
                                                                                                                                                                                                                                                          SHA-512:80F579572754579706B4EEA49BF30456F3231A308E0616DC430E2428A04992412773421542E4F7FE4E4C7491BA88942FA44B49E87E95A2183211AC2AB523B231
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Indianapolis)]} {.. LoadTimeZoneFile America/Indiana/Indianapolis..}..set TZData(:America/Fort_Wayne) $TZData(:America/Indiana/Indianapolis)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1423
                                                                                                                                                                                                                                                          Entropy (8bit):3.784027854102512
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5MeajcChlrLPsw6kSS3h5R14eH8tf3GvIkuoYVZaIBXR8nd:5rChlvEw6kSSx5H4a8tf3fkuoYVZDNRo
                                                                                                                                                                                                                                                          MD5:E7939C9A3F83D73B82A6DE359365EFD4
                                                                                                                                                                                                                                                          SHA1:06D6E257DA7C317CAFAF6C0B04567A2453CC1660
                                                                                                                                                                                                                                                          SHA-256:C0A836BDAF07F0376B7B0833A0AB3D52BA6E3E1D6F95E247E1AD351CD1096066
                                                                                                                                                                                                                                                          SHA-512:E2BEA04084489B26ADD9A768D2580C1FF7EBAC8A3EA36818F49E85FB14E01500D59D53904F5A17F4DABEF27B4CC2FC3F977EE4C125E5CE739BBE90C130ED3B07
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Fortaleza) {.. {-9223372036854775808 -9240 0 LMT}.. {-1767216360 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8372
                                                                                                                                                                                                                                                          Entropy (8bit):3.8225708746657316
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:w4lTPB10KvnpNWMPm4bPJWXtRbALtuFW4ng2CEBJuQaeEy9P19OBYEi/B51B7/BI:wKCC
                                                                                                                                                                                                                                                          MD5:1C8B0B85BB5578E84A4867546111F946
                                                                                                                                                                                                                                                          SHA1:E08A96F5B369FA53BC1F3F839EC14FF9D334F727
                                                                                                                                                                                                                                                          SHA-256:58C207CBD9DE7A7BB15E48A62CEA9F15DA184B945133DEE88EFF29FD8B66B29E
                                                                                                                                                                                                                                                          SHA-512:54CFBF208AB3E58AFB6BEC40265A452A3C4C684D7F278F51D6495FCA544652A1A5E05BC45F600911191B33C936E5D7D43A28FD2B0884AAB9F63B7AD5EFD574A1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Glace_Bay) {.. {-9223372036854775808 -14388 0 LMT}.. {-2131646412 -14400 0 AST}.. {-1632074400 -10800 1 ADT}.. {-1615143600 -14400 0 AST}.. {-880221600 -10800 1 AWT}.. {-769395600 -10800 1 APT}.. {-765399600 -14400 0 AST}.. {-536443200 -14400 0 AST}.. {-526500000 -10800 1 ADT}.. {-513198000 -14400 0 AST}.. {-504907200 -14400 0 AST}.. {63086400 -14400 0 AST}.. {73461600 -10800 1 ADT}.. {89182800 -14400 0 AST}.. {104911200 -10800 1 ADT}.. {120632400 -14400 0 AST}.. {126244800 -14400 0 AST}.. {136360800 -10800 1 ADT}.. {152082000 -14400 0 AST}.. {167810400 -10800 1 ADT}.. {183531600 -14400 0 AST}.. {199260000 -10800 1 ADT}.. {215586000 -14400 0 AST}.. {230709600 -10800 1 ADT}.. {247035600 -14400 0 AST}.. {262764000 -10800 1 ADT}.. {278485200 -14400 0 AST}.. {294213600 -10800 1 ADT}.. {309934800 -14400 0 AST}.. {325663200 -10800 1 ADT}
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):180
                                                                                                                                                                                                                                                          Entropy (8bit):4.973070790103308
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0wQbSeyXHAIg20wQboAFARL/2IAcGE5GZJ4IAcGEH:SlSWB9vsM3y7lbSeSHAIgplbLFAN/291
                                                                                                                                                                                                                                                          MD5:8263D2B39C2EC3B38A179F8BAD5972DD
                                                                                                                                                                                                                                                          SHA1:18D3462F6846768E16036E860DE90FB345C93047
                                                                                                                                                                                                                                                          SHA-256:5FB2CFBA25CE2F49D4C3911AFF8E7E1FF84EFC2D01F5783772E88246BFBC56AC
                                                                                                                                                                                                                                                          SHA-512:C175CAF972459759553001D48921268E9C6268CED56021BA6339F8CE3DD032DA6180E2B82974D3DCD0DC5F21566DFDBFBE1B6CF24E5E893F2335A449452DB27F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Nuuk)]} {.. LoadTimeZoneFile America/Nuuk..}..set TZData(:America/Godthab) $TZData(:America/Nuuk)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10353
                                                                                                                                                                                                                                                          Entropy (8bit):3.864463676759425
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:zfSacO8f7/ewzlrfFj18KvnpNWMPm4bPJvSuYUHgA0G19OBYEi/B51B7/Bm6BTdW:zfSacOI7/V3SuYUHgAuCC
                                                                                                                                                                                                                                                          MD5:0D646C67105FD0525E7CCC79585CE9DF
                                                                                                                                                                                                                                                          SHA1:06D91FDD8FEEDC299E40079569372F97A9AC6F04
                                                                                                                                                                                                                                                          SHA-256:52D2478289682BF95BFB93D64D679E888C9D23C0F68DFFF7E6E34BFC44B3D892
                                                                                                                                                                                                                                                          SHA-512:FD672613C2B65E12425415630A2F489917EB80DDED41338C9AA7D5D3C6B54E52C516A32493593F518DACF22A91D7A9D2C96DB9C5F1BE2C3BB9842D274BDC04FF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Goose_Bay) {.. {-9223372036854775808 -14500 0 LMT}.. {-2713895900 -12652 0 NST}.. {-1640982548 -12652 0 NST}.. {-1632076148 -9052 1 NDT}.. {-1615145348 -12652 0 NST}.. {-1609446548 -12652 0 NST}.. {-1096921748 -12600 0 NST}.. {-1072989000 -12600 0 NST}.. {-1061670600 -9000 1 NDT}.. {-1048973400 -12600 0 NST}.. {-1030221000 -9000 1 NDT}.. {-1017523800 -12600 0 NST}.. {-998771400 -9000 1 NDT}.. {-986074200 -12600 0 NST}.. {-966717000 -9000 1 NDT}.. {-954624600 -12600 0 NST}.. {-935267400 -9000 1 NDT}.. {-922570200 -12600 0 NST}.. {-903817800 -9000 1 NDT}.. {-891120600 -12600 0 NST}.. {-872368200 -9000 0 NWT}.. {-769395600 -9000 1 NPT}.. {-765401400 -12600 0 NST}.. {-757369800 -12600 0 NST}.. {-746044200 -9000 1 NDT}.. {-733347000 -12600 0 NST}.. {-714594600 -9000 1 NDT}.. {-701897400 -12600 0 NST}.. {-683145000 -9000 1 NDT}.. {-67044
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7522
                                                                                                                                                                                                                                                          Entropy (8bit):3.84007813579738
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:pGStCt/cL1BRv0HY2iU7KKdFL6Aa2K4gSLf8e:pvItOx0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:A17723CE27EC99D1506C45AB1531085B
                                                                                                                                                                                                                                                          SHA1:A83ED7BD09514A829CC8F2EA47BA113F5DCA1090
                                                                                                                                                                                                                                                          SHA-256:560B39485CED4C2A0E85A66EB875331E5879104187D92CB7F05C2F635E34AC99
                                                                                                                                                                                                                                                          SHA-512:110D1253D6915DB046247E4FD3BA9B881146BC3896DE779215E0CC6D1DCC59958C355441955509F5D38E3A3BA166DFD0F2F277000E9E89D6551FBEA0C16974B9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Grand_Turk) {.. {-9223372036854775808 -17072 0 LMT}.. {-2524504528 -18430 0 KMT}.. {-1827687170 -18000 0 EST}.. {284014800 -18000 0 EST}.. {294217200 -14400 1 EDT}.. {309938400 -18000 0 EST}.. {325666800 -14400 1 EDT}.. {341388000 -18000 0 EST}.. {357116400 -14400 1 EDT}.. {372837600 -18000 0 EST}.. {388566000 -14400 1 EDT}.. {404892000 -18000 0 EST}.. {420015600 -14400 1 EDT}.. {436341600 -18000 0 EST}.. {452070000 -14400 1 EDT}.. {467791200 -18000 0 EST}.. {483519600 -14400 1 EDT}.. {499240800 -18000 0 EST}.. {514969200 -14400 1 EDT}.. {530690400 -18000 0 EST}.. {544604400 -14400 1 EDT}.. {562140000 -18000 0 EST}.. {576054000 -14400 1 EDT}.. {594194400 -18000 0 EST}.. {607503600 -14400 1 EDT}.. {625644000 -18000 0 EST}.. {638953200 -14400 1 EDT}.. {657093600 -18000 0 EST}.. {671007600 -14400 1 EDT}.. {688543200 -18000 0 EST}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):201
                                                                                                                                                                                                                                                          Entropy (8bit):4.892013473075135
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/2905Qb90ppv:MByMYbpwt290Ob90b
                                                                                                                                                                                                                                                          MD5:4B9ABEA103F55509550F8B42D88E84B7
                                                                                                                                                                                                                                                          SHA1:E3AA1BCE5E260264E74F77E59C4071B7E496AB41
                                                                                                                                                                                                                                                          SHA-256:EBED070E8E67C5F12FF6E03FE508BE90789F17C793DFE61237B4045B8222580F
                                                                                                                                                                                                                                                          SHA-512:568E375464FF264C5048CB35995945BDE1D5BCC3A108B2A4D0F8389EBF18B4C58EBB1C2122F10BA777D512504A59C7EFDF6069EABD2A5DEA3189204B7F7A6EB4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Grenada) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):204
                                                                                                                                                                                                                                                          Entropy (8bit):4.9138787435596765
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/2905AJLr490ppv:MByMYbpwt290qJLr490b
                                                                                                                                                                                                                                                          MD5:92B091A06198E233B73DF12DFCD818D5
                                                                                                                                                                                                                                                          SHA1:C529488D09F86755E4F22CB4F0E3013C3A1B978D
                                                                                                                                                                                                                                                          SHA-256:6CB1930532831D12057FCB484C60DB64A60A4F6D8195DAFD464826923116A294
                                                                                                                                                                                                                                                          SHA-512:55EAE03CDECAC43BEDD3AA1A32C632A46808F29FF4D97A330F818544E4D10B9E9BA909D6627C38065EB7AC8E2C395FA37797F532CCFC8AB89D4698CCDE17F985
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Guadeloupe) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):399
                                                                                                                                                                                                                                                          Entropy (8bit):4.513185345162455
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862906GGmdHKznC972f/uF+mP/uF+K67Jqd3/uF+eBxE/uF+DAWNv:5neQCgfS+6S+K67Yd3S+e0S+1
                                                                                                                                                                                                                                                          MD5:569CDE7CE1AB84C0F16A25E85A418334
                                                                                                                                                                                                                                                          SHA1:EADE79AB6EDD98C7FE8B10B480C5C530CA014F5C
                                                                                                                                                                                                                                                          SHA-256:14F6A98D602F3648C816B110F3A0BA375E1FFE8FA06BEEAB419DC1ABFA6EDCAF
                                                                                                                                                                                                                                                          SHA-512:AE2ACBF09EED857906811BE2984D6BF92BF2955A9FE2F9F3FFEBB6790902F5C2C870F8561CA13AD9CB7826EECA434BED7CFE7D0D2739996BACEE506D0EB730DC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Guatemala) {.. {-9223372036854775808 -21724 0 LMT}.. {-1617040676 -21600 0 CST}.. {123055200 -18000 1 CDT}.. {130914000 -21600 0 CST}.. {422344800 -18000 1 CDT}.. {433054800 -21600 0 CST}.. {669708000 -18000 1 CDT}.. {684219600 -21600 0 CST}.. {1146376800 -18000 1 CDT}.. {1159678800 -21600 0 CST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):249
                                                                                                                                                                                                                                                          Entropy (8bit):4.745656594295655
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2905xDm2OHHjGeoHv5laITicKpKV0EX/uFhfF/KVg:MB86290jmdHHLCv5FT/gOR/uFpF/Og
                                                                                                                                                                                                                                                          MD5:DF661E312C6CE279CD6829120BE33CF2
                                                                                                                                                                                                                                                          SHA1:4ACDB31E27EF9175C5452BF95F94F9BC280A237F
                                                                                                                                                                                                                                                          SHA-256:6806AA5814BDC679C6EF653C518D2699114BE71D973F49C0864F622038DC2048
                                                                                                                                                                                                                                                          SHA-512:04E7FD01F4DAD981EE8A02487F4A889015C41D07D6DCF420183D387E2188FF3239E345B5D65FB195CA485F5C7B4AD8CFEF51FFFC11EE0C91F0C88FF7B7EF17C1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Guayaquil) {.. {-9223372036854775808 -19160 0 LMT}.. {-2524502440 -18840 0 QMT}.. {-1230749160 -18000 0 -05}.. {722926800 -14400 1 -05}.. {728884800 -18000 0 -05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):248
                                                                                                                                                                                                                                                          Entropy (8bit):4.673559445766137
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2905R3SDm2OHRLx5oH8ZOXFxSyZ1yV/KMMdVVFAKFZ4KVR/ON:MB86290LGmdHBnC8ZODhyV/4d/OeZ4Ke
                                                                                                                                                                                                                                                          MD5:F06C226D8D53EF8859AD91D7EBA5959C
                                                                                                                                                                                                                                                          SHA1:E0B4E6F4ADCB10F1D79FFD928E8684FFE0C0DC5F
                                                                                                                                                                                                                                                          SHA-256:4078D2E361D04A66F22F652E3810CDF7F630CF89399B47E4EC7B1D32B400FD85
                                                                                                                                                                                                                                                          SHA-512:B4385650A0C69B7BD66415CC4BB9FCA854DBB1427E9F2D6C1D8CDB8CCEF9ECBD699C66A83A9AC289DABC5CDBB0A2B044E4097E9A2977AE1802B3BF6E2BB518CF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Guyana) {.. {-9223372036854775808 -13959 0 LMT}.. {-1843589241 -14400 0 -04}.. {-1730577600 -13500 0 -0345}.. {176096700 -10800 0 -03}.. {701841600 -14400 0 -04}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11124
                                                                                                                                                                                                                                                          Entropy (8bit):3.8106487461849885
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:YpQamC9XD81iWQSufutTLBCN8RWnWQ7Z/xVpmtBwXiCDLxcGMe++wzlrfFj10Kvn:2kXCvNc/1/CC
                                                                                                                                                                                                                                                          MD5:6FB9E47841FF397CE36A36C8280E2089
                                                                                                                                                                                                                                                          SHA1:DA210300DC3D94FC3D8BA0A4531341BCA5C5936C
                                                                                                                                                                                                                                                          SHA-256:01E11C7B07925D05E9E1876C310A2B87E0E80EF115D062225212E472B7A964F1
                                                                                                                                                                                                                                                          SHA-512:F61B5A8A7532BBD54A4976DF17A1C6CF51BCC6DC396482FBE169C3081AF27B6CA863F0CDE3E483C59F5A5BD3365592F6984A97173C736B41D3CEEDAD4263A4E5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Halifax) {.. {-9223372036854775808 -15264 0 LMT}.. {-2131645536 -14400 0 AST}.. {-1696276800 -10800 1 ADT}.. {-1680469200 -14400 0 AST}.. {-1640980800 -14400 0 AST}.. {-1632074400 -10800 1 ADT}.. {-1615143600 -14400 0 AST}.. {-1609444800 -14400 0 AST}.. {-1566763200 -10800 1 ADT}.. {-1557090000 -14400 0 AST}.. {-1535486400 -10800 1 ADT}.. {-1524949200 -14400 0 AST}.. {-1504468800 -10800 1 ADT}.. {-1493413200 -14400 0 AST}.. {-1472414400 -10800 1 ADT}.. {-1461963600 -14400 0 AST}.. {-1440964800 -10800 1 ADT}.. {-1429390800 -14400 0 AST}.. {-1409515200 -10800 1 ADT}.. {-1396731600 -14400 0 AST}.. {-1376856000 -10800 1 ADT}.. {-1366491600 -14400 0 AST}.. {-1346616000 -10800 1 ADT}.. {-1333832400 -14400 0 AST}.. {-1313956800 -10800 1 ADT}.. {-1303678800 -14400 0 AST}.. {-1282507200 -10800 1 ADT}.. {-1272661200 -14400 0 AST}.. {-1251057600
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8729
                                                                                                                                                                                                                                                          Entropy (8bit):3.8227313494100867
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:BEsWduCtQA/gF6Y3Umjm67yLb5RCzhV28I:BBWACb/gF6Y3UmjBy7
                                                                                                                                                                                                                                                          MD5:564980AECB32F5778422EA15E8956879
                                                                                                                                                                                                                                                          SHA1:545209C95043721C1839CCE5FEFD1A6F2DE3FE5F
                                                                                                                                                                                                                                                          SHA-256:96B62BFBF0C05CF970245597C691F89EBF631175796459642A85287F131D0215
                                                                                                                                                                                                                                                          SHA-512:25FE5DAA55E3466EAE1CDC73918F189403C3360D4E82D72D745FA04A374DE04F479AA9811D6154FC70CC8EA620F18035EA6A3074116806D4405936FA017CE8E6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Havana) {.. {-9223372036854775808 -19768 0 LMT}.. {-2524501832 -19776 0 HMT}.. {-1402813824 -18000 0 CST}.. {-1311534000 -14400 1 CDT}.. {-1300996800 -18000 0 CST}.. {-933534000 -14400 1 CDT}.. {-925675200 -18000 0 CST}.. {-902084400 -14400 1 CDT}.. {-893620800 -18000 0 CST}.. {-870030000 -14400 1 CDT}.. {-862171200 -18000 0 CST}.. {-775681200 -14400 1 CDT}.. {-767822400 -18000 0 CST}.. {-744231600 -14400 1 CDT}.. {-736372800 -18000 0 CST}.. {-144702000 -14400 1 CDT}.. {-134251200 -18000 0 CST}.. {-113425200 -14400 1 CDT}.. {-102542400 -18000 0 CST}.. {-86295600 -14400 1 CDT}.. {-72907200 -18000 0 CST}.. {-54154800 -14400 1 CDT}.. {-41457600 -18000 0 CST}.. {-21495600 -14400 1 CDT}.. {-5774400 -18000 0 CST}.. {9954000 -14400 1 CDT}.. {25675200 -18000 0 CST}.. {41403600 -14400 1 CDT}.. {57729600 -18000 0 CST}.. {73458000 -14400 1 CD
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):616
                                                                                                                                                                                                                                                          Entropy (8bit):4.351214377567366
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86290e2mdH5NCtXwl3UXmMMmxL+voudQCvX70qKOV9kYNv:5Ie5k9WUQwuz/Vyu
                                                                                                                                                                                                                                                          MD5:E35A6C6E9DCF0CA34BFA2993CE445D6C
                                                                                                                                                                                                                                                          SHA1:4FF9C7EDBC73B1AE0815661571B7199379AF479C
                                                                                                                                                                                                                                                          SHA-256:C0A87DC3A474D25083F0CEA0C323D8E780D937453CAD23C98AF367D81AC2CA2D
                                                                                                                                                                                                                                                          SHA-512:56A728ABCD3EA91D2492E1331B3F76F31EF5675BCD95A692F9D94F91518B72569FD8DF1BB0515668E8A9BE0347018B391C65761D316903CA27C59883BBE0DE80
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Hermosillo) {.. {-9223372036854775808 -26632 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {-873828000 -25200 0 MST}.. {-661539600 -28800 0 PST}.. {28800 -25200 0 MST}.. {828867600 -21600 1 MDT}.. {846403200 -25200 0 MST}.. {860317200 -21600 1 MDT}.. {877852800 -25200 0 MST}.. {891766800 -21600 1 MDT}.. {909302400 -25200 0 MST}.. {915174000 -25200 0 MST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7230
                                                                                                                                                                                                                                                          Entropy (8bit):3.882344472808608
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:nys0KHK1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:nyBKHkN0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:7824B3F2D20F16A9DCC8E0F7DC45C1B8
                                                                                                                                                                                                                                                          SHA1:77014A0502DA1342EFA41B64C5613839B627354B
                                                                                                                                                                                                                                                          SHA-256:4B114545167326F066AB3A798180896B43AC6FDC3B80D32BCC917B5A4A2359EB
                                                                                                                                                                                                                                                          SHA-512:03F6A18C03E79E9177D16CD7AB75AC117197638370FA675BC2854A5A563021F865F3F0672B237B83098787AB9D419AC33D67F28324B1E25AD8560B5838F70807
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Indianapolis) {.. {-9223372036854775808 -20678 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-1577901600 -21600 0 CST}.. {-900259200 -18000 1 CDT}.. {-891795600 -21600 0 CST}.. {-883591200 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-747244800 -18000 1 CDT}.. {-733942800 -21600 0 CST}.. {-715795200 -18000 1 CDT}.. {-702493200 -21600 0 CST}.. {-684345600 -18000 1 CDT}.. {-671043600 -21600 0 CST}.. {-652896000 -18000 1 CDT}.. {-639594000 -21600 0 CST}.. {-620841600 -18000 1 CDT}.. {-608144400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8755
                                                                                                                                                                                                                                                          Entropy (8bit):3.8394539560522585
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:+q2KeNrdJ8SvAgahLi8hDlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:+FKUdJ8SvPaUqbA604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:8AF080A022DA0737E94742C50EAAC62E
                                                                                                                                                                                                                                                          SHA1:704F0565B53AA8A20F70B79A7958D4D07085E07A
                                                                                                                                                                                                                                                          SHA-256:F1253F5F3F5AACD1A5E1F4636DD4E083F4B2A8BD995CF3E684CDD384641849F1
                                                                                                                                                                                                                                                          SHA-512:26AAF6D24B2E2B60451E19A514533DFAEC74F01F9B1AEB9F86690669C14130D77AE1CBFB9FC9091E1CD1FC1CBC2799BB05026DB68768C3CCB960355C18D111ED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Knox) {.. {-9223372036854775808 -20790 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-725824800 -21600 0 CST}.. {-715795200 -18000 1 CDT}.. {-702493200 -21600 0 CST}.. {-684345600 -18000 1 CDT}.. {-671043600 -21600 0 CST}.. {-652896000 -18000 1 CDT}.. {-639594000 -21600 0 CST}.. {-620841600 -18000 1 CDT}.. {-608144400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1 CDT}.. {-513190800 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-463593600 -18000 1 CDT}.. {-447267600 -21600 0 CST}.. {-431539200 -18000 1 CDT}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7273
                                                                                                                                                                                                                                                          Entropy (8bit):3.8700915866109535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:7qvrv7+X1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:7Kv7+bN0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:C1A10440E6CCE4C5052E2510182D9AA7
                                                                                                                                                                                                                                                          SHA1:56D4F3CCA1245D626BADA74CF3F6BAE8034BF58D
                                                                                                                                                                                                                                                          SHA-256:675162381639598E7100E90663D42780F8EE1CB62BD6DA5B948B494F98C02FE3
                                                                                                                                                                                                                                                          SHA-512:96B71472AD38ECFC589F935D9F5F1C8D42C8E942D8772FB6A77F9B9C0E2BD7A07FA61729E57EC02356121518E33797A784679F8DED2FCA3FC79F5C114783DD57
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Marengo) {.. {-9223372036854775808 -20723 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-599594400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-463593600 -18000 1 CDT}.. {-450291600 -21600 0 CST}.. {-431539200 -18000 1 CDT}.. {-418237200 -21600 0 CST}.. {-400089600 -18000 1 CDT}.. {-386787600 -21600 0 CST}.. {-368640000 -18000 1 CDT}.. {-355338000 -21600 0 CST}.. {-337190400 -18000 1 CDT}.. {-323888400 -21600 0 CST}.. {-305740800 -18000 1 CDT}.. {-292438800 -21600 0 CST}.. {-273686400 -18000 0 EST}.. {-31518000 -18000 0 EST}.. {-21488400 -14400 1 EDT}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7611
                                                                                                                                                                                                                                                          Entropy (8bit):3.87971256165061
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:TqervJ8SUklggahyBRP0HY2iU7KKdFL6Aa2K4gSLf8e:TpvJ8SUklvaQN0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:A86042668CD478AFFC05D3383EDEE8FF
                                                                                                                                                                                                                                                          SHA1:6476526F94A247C0ECF3B2813F2C5A4FB93E457E
                                                                                                                                                                                                                                                          SHA-256:23B8FA75CE0A9555DFD84549723A12679FF7FC5FAA58E4B745BA3C547071FF53
                                                                                                                                                                                                                                                          SHA-512:07A5487A087108E6D6E88580865885CA6243EF04BE8263FC913F38CADB8EA016386E8BBAD39F65FD081F1A2F14316FEAF008855E9CF2019B169D9511916AFF67
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Petersburg) {.. {-9223372036854775808 -20947 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-473364000 -21600 0 CST}.. {-462996000 -18000 1 CDT}.. {-450291600 -21600 0 CST}.. {-431539200 -18000 1 CDT}.. {-418237200 -21600 0 CST}.. {-400089600 -18000 1 CDT}.. {-386787600 -21600 0 CST}.. {-368640000 -18000 1 CDT}.. {-355338000 -21600 0 CST}.. {-337190400 -18000 1 CDT}.. {-323888400 -21600 0 CST}.. {-305740800 -18000 1 CDT}.. {-292438800 -21600 0 CST}.. {-273686400 -18000 1 CDT}.. {-257965200 -21600 0 CST}.. {-242236800 -18000 1 CDT}.. {-226515600 -21600 0 CST}.. {-210787200 -18000 1 CDT}.. {-195066000 -21600 0 CST}.. {-179337600 -18000 1 CD
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7100
                                                                                                                                                                                                                                                          Entropy (8bit):3.8613085681914607
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:yqxrvJ8SUklLgzNA604qSScBgN+4ctDzIVQ/c/3hNxTh:yUvJ8SUkl8BA604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:E7FE9B7CFBC6505C446056967DEBC87B
                                                                                                                                                                                                                                                          SHA1:81ADAD89F040F62E87D2F26D1D98B3E52710F695
                                                                                                                                                                                                                                                          SHA-256:D368123DB703B55244700876906775837D408C274C5A5801D80B77EADB6D5853
                                                                                                                                                                                                                                                          SHA-512:9C0746DE18C80B548AA443D59BB9971BDC304975717C5FCDEBDE72828ACF408FA1D687F87C42E7B8D6D0284C9F792EA236BF79C815947BE773D07364B630AC99
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Tell_City) {.. {-9223372036854775808 -20823 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-462996000 -18000 1 CDT}.. {-450291600 -21600 0 CST}.. {-431539200 -18000 1 CDT}.. {-418237200 -21600 0 CST}.. {-400089600 -18000 1 CDT}.. {-386787600 -21600 0 CST}.. {-368640000 -18000 1 CDT}.. {-355338000 -21600 0 CST}.. {-337190400 -18000 1 CDT}.. {-323888400 -21600 0 CST}.. {-305740800 -18000 1 CDT}.. {-292438800 -21600 0 CST}.. {-273686400 -18000 1 CDT}.. {-257965200 -21600 0 CST}.. {-242236800 -18000 1 CDT}.. {-226515600 -21600 0 CST}.. {-210787200 -18000 1 CDT}.. {-195066000 -21600 0 CST}.. {-179337600 -18000 0 EST
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6563
                                                                                                                                                                                                                                                          Entropy (8bit):3.866646181493734
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:juqv01BRP0HY2iU7KKdFL6Aa2K4gSLf8e:CoKN0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:2CCFC3980C321ED8A852759C0BCCB12C
                                                                                                                                                                                                                                                          SHA1:A8BFE02E4E71B28EF8E284E808F6EDE7C231F8FF
                                                                                                                                                                                                                                                          SHA-256:0623233AA39A1A82038A56DF255ADF49E648777375B8499491C8897EBEA1CDF1
                                                                                                                                                                                                                                                          SHA-512:A4C77689BC9BF871C756D05BAC4157F0FD324D10AC7D15F3543344C6F8C7FC9218AB7ADFBCE70C8ECCDD6EC15FD7960503FC7A8223FECE6D4227BF0BB04190C7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Vevay) {.. {-9223372036854775808 -20416 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-495043200 -18000 0 EST}.. {-31518000 -18000 0 EST}.. {-21488400 -14400 1 EDT}.. {-5767200 -18000 0 EST}.. {9961200 -14400 1 EDT}.. {25682400 -18000 0 EST}.. {41410800 -14400 1 EDT}.. {57736800 -18000 0 EST}.. {73465200 -14400 1 EDT}.. {89186400 -18000 0 EST}.. {94712400 -18000 0 EST}.. {1136091600 -18000 0 EST}.. {1143961200 -14400 1 EDT}.. {1162101600 -18000 0 EST}.. {1173596400 -14400 1 EDT}.. {1194156000 -18000 0 EST}.. {1205046000 -14400 1 EDT}.. {1225605600 -18000 0 EST}.. {1236495600 -14400 1 EDT}.. {1257055200 -18000 0 EST}.. {1268550000 -144
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7226
                                                                                                                                                                                                                                                          Entropy (8bit):3.879195938909716
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:Vq8rdJ5UklpRBRP0HY2iU7KKdFL6Aa2K4gSLf8e:VbdJ5Uklp/N0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:56D1930F5FAE2456DEC6C9AB1B0233E1
                                                                                                                                                                                                                                                          SHA1:F6ED52EF769DF2C015C181BCFF3DC0E24497C768
                                                                                                                                                                                                                                                          SHA-256:B8452B6AA739A78AC6D03806463B03D4175639593E19FAA3CA4B0D0FB77F18C9
                                                                                                                                                                                                                                                          SHA-512:AFCFF383DB441DA9154B639A88700D0604F487A20E830146B14061E485A991AD8DC279AF8C0C2329265CF14C901207B9058157FAA1C039082EB7630916834156
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Vincennes) {.. {-9223372036854775808 -21007 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-747244800 -18000 1 CDT}.. {-733942800 -21600 0 CST}.. {-526492800 -18000 1 CDT}.. {-513190800 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-462996000 -18000 1 CDT}.. {-450291600 -21600 0 CST}.. {-431539200 -18000 1 CDT}.. {-418237200 -21600 0 CST}.. {-400089600 -18000 1 CDT}.. {-386787600 -21600 0 CST}.. {-368640000 -18000 1 CDT}.. {-355338000 -21600 0 CST}.. {-337190400 -18000 1 CDT}.. {-323888400 -21600 0 CST}.. {-305740800 -18000 1 CDT}.. {-289414800 -21600 0 CST}.. {-273686400 -18000 1 CDT
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7410
                                                                                                                                                                                                                                                          Entropy (8bit):3.8775722319777968
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:uq0KeKrv7c1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:unKxv7yN0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:880526DC23E7BDB00506D7EC2A885907
                                                                                                                                                                                                                                                          SHA1:DB3B13A2A4BF80E7B71C7F0604A0A80EF070B9BA
                                                                                                                                                                                                                                                          SHA-256:4B293FDB7680C4597B8C885333719214492ECF09BD5EA342D1EC15F2BF9C8605
                                                                                                                                                                                                                                                          SHA-512:42EEDC5EA28781D62A457F4843F38D0A3FEFCAD83BA01B07CEF0FA169C6440960E04BABD272C5E9AF2F4B0DBB2A786EF9221A48F084F16752E6D0EA66C31911E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Winamac) {.. {-9223372036854775808 -20785 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-747244800 -18000 1 CDT}.. {-733942800 -21600 0 CST}.. {-715795200 -18000 1 CDT}.. {-702493200 -21600 0 CST}.. {-684345600 -18000 1 CDT}.. {-671043600 -21600 0 CST}.. {-652896000 -18000 1 CDT}.. {-639594000 -21600 0 CST}.. {-620841600 -18000 1 CDT}.. {-608144400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1 CDT}.. {-513190800 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-463593600 -18000 1 CDT}.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):233
                                                                                                                                                                                                                                                          Entropy (8bit):4.7047837427916095
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y73GK7JHAIgp3GKZRN/2903GfJ4903GK8:MByMY3GK7Kp3GKnt2903GfJ4903GK8
                                                                                                                                                                                                                                                          MD5:DEE404D54FD707C4A27F464B5F19D135
                                                                                                                                                                                                                                                          SHA1:AD95D04738F6B15A93DED1DE6B5FA9F47C8E38CB
                                                                                                                                                                                                                                                          SHA-256:437DA148B94DBA4CEA402169878541DB9C3419ABAB6750D1C36625DD3053019E
                                                                                                                                                                                                                                                          SHA-512:421D6AF30F0C64EA6CB9F9DC4E7EF9E8EE5945F81A5E82A6D959D32AD69F325770DB6A07D8F52EFE7EE7F6C3AD4E1F34AA30A6B5E006C928119A54E746D6FE6B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Indianapolis)]} {.. LoadTimeZoneFile America/Indiana/Indianapolis..}..set TZData(:America/Indianapolis) $TZData(:America/Indiana/Indianapolis)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8053
                                                                                                                                                                                                                                                          Entropy (8bit):3.8653821039202727
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:/wIGaLV911sF7Lv/PCewtA8CzSPyDLbrcUia:/w5PlLv/PCenJzS6cy
                                                                                                                                                                                                                                                          MD5:6BD34D06717C5D9A3697242A5806A4D5
                                                                                                                                                                                                                                                          SHA1:B8A79C3F4F6A272D0E74C44DB0F3FDD326B1056E
                                                                                                                                                                                                                                                          SHA-256:0FFFE17A60FDBB958264704AC03D6F79A6754BDE18C54A663D3CFF9CFE7432F6
                                                                                                                                                                                                                                                          SHA-512:88B7A15013E2CB55ED6985A9D38B65047CF275B31F308B4556BCAD11E9BFF05D26274A3D1FF0F57BBFB08D748F80A321761B6FE0AC5149B01486448B26C558C4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Inuvik) {.. {-9223372036854775808 0 0 -00}.. {-536457600 -28800 0 PST}.. {73476000 -25200 1 PDT}.. {89197200 -28800 0 PST}.. {104925600 -25200 1 PDT}.. {120646800 -28800 0 PST}.. {136375200 -25200 1 PDT}.. {152096400 -28800 0 PST}.. {167824800 -25200 1 PDT}.. {183546000 -28800 0 PST}.. {199274400 -25200 1 PDT}.. {215600400 -28800 0 PST}.. {230724000 -25200 1 PDT}.. {247050000 -28800 0 PST}.. {262778400 -25200 1 PDT}.. {278499600 -28800 0 PST}.. {294228000 -21600 0 MDT}.. {309945600 -25200 0 MST}.. {315558000 -25200 0 MST}.. {325674000 -21600 1 MDT}.. {341395200 -25200 0 MST}.. {357123600 -21600 1 MDT}.. {372844800 -25200 0 MST}.. {388573200 -21600 1 MDT}.. {404899200 -25200 0 MST}.. {420022800 -21600 1 MDT}.. {436348800 -25200 0 MST}.. {452077200 -21600 1 MDT}.. {467798400 -25200 0 MST}.. {483526800 -21600 1 MDT}.. {499248000 -2
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8086
                                                                                                                                                                                                                                                          Entropy (8bit):3.827969920963878
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:72EtCt/cQ1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:72EIt/N0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:123F07049F1F120E2C5C8A32DF3ADFC4
                                                                                                                                                                                                                                                          SHA1:F02C606A8CB888BD082501E1191C604B17C387D1
                                                                                                                                                                                                                                                          SHA-256:E85ABCABEC22EFEB3DE45545FB1853AC5CBC1900DBEBE3C90E8A868281E64B86
                                                                                                                                                                                                                                                          SHA-512:A3F507D9B7CE0CF541A20C4B662B81CED097FC301D3DAD90DAFC3451F400768EA99ED725A56E8207E990AF31AB8136F5168854D1C37372847F36026C576136BC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Iqaluit) {.. {-9223372036854775808 0 0 -00}.. {-865296000 -14400 0 EWT}.. {-769395600 -14400 1 EPT}.. {-765396000 -18000 0 EST}.. {73465200 -14400 1 EDT}.. {89186400 -18000 0 EST}.. {104914800 -14400 1 EDT}.. {120636000 -18000 0 EST}.. {136364400 -14400 1 EDT}.. {152085600 -18000 0 EST}.. {167814000 -14400 1 EDT}.. {183535200 -18000 0 EST}.. {199263600 -14400 1 EDT}.. {215589600 -18000 0 EST}.. {230713200 -14400 1 EDT}.. {247039200 -18000 0 EST}.. {262767600 -14400 1 EDT}.. {278488800 -18000 0 EST}.. {294217200 -14400 1 EDT}.. {309938400 -18000 0 EST}.. {325666800 -14400 1 EDT}.. {341388000 -18000 0 EST}.. {357116400 -14400 1 EDT}.. {372837600 -18000 0 EST}.. {388566000 -14400 1 EDT}.. {404892000 -18000 0 EST}.. {420015600 -14400 1 EDT}.. {436341600 -18000 0 EST}.. {452070000 -14400 1 EDT}.. {467791200 -18000 0 EST}.. {483519600
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):847
                                                                                                                                                                                                                                                          Entropy (8bit):4.206296468996689
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5seRvZGjFS/uk1p/uue/udYR/u+zN5hi/uW9/uoUF0/u8Bb/u33RU/uMZ8/unuR3:5jUjFo1pFGzfAYFqB43RMER3
                                                                                                                                                                                                                                                          MD5:95B59E3EA2A270A34BDF98AA899203C8
                                                                                                                                                                                                                                                          SHA1:93599597797F4BAFE5C75179FB795058B1E3527D
                                                                                                                                                                                                                                                          SHA-256:4B9D5177CBA057CD53D53120A49B8A47ECCB00150018581A84851E9D5437D643
                                                                                                                                                                                                                                                          SHA-512:032BC07F9E92B756A0732AECC2DFEC4C89A58B3D6D3CA57A0F99F2AD1D51676804C7B6CE50EB3B37BB8A1EF382168AC83989D609D37C57308E29B51F1FDEFB1E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Jamaica) {.. {-9223372036854775808 -18430 0 LMT}.. {-2524503170 -18430 0 KMT}.. {-1827687170 -18000 0 EST}.. {126248400 -18000 0 EST}.. {126687600 -14400 1 EDT}.. {152085600 -18000 0 EST}.. {162370800 -14400 1 EDT}.. {183535200 -18000 0 EST}.. {199263600 -14400 1 EDT}.. {215589600 -18000 0 EST}.. {230713200 -14400 1 EDT}.. {247039200 -18000 0 EST}.. {262767600 -14400 1 EDT}.. {278488800 -18000 0 EST}.. {294217200 -14400 1 EDT}.. {309938400 -18000 0 EST}.. {325666800 -14400 1 EDT}.. {341388000 -18000 0 EST}.. {357116400 -14400 1 EDT}.. {372837600 -18000 0 EST}.. {388566000 -14400 1 EDT}.. {404892000 -18000 0 EST}.. {420015600 -14400 1 EDT}.. {436341600 -18000 0 EST}.. {441781200 -18000 0 EST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):211
                                                                                                                                                                                                                                                          Entropy (8bit):4.94277888588308
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7/MI6HAIgp/MIwRN/290pPGe90/MIz:MByMY/Myp/M9Rt290h390/M4
                                                                                                                                                                                                                                                          MD5:E020D4F9CB1AF91D373CD9F3C2247428
                                                                                                                                                                                                                                                          SHA1:0ADF2E9F8D9F8641E066764BA1BAF068F0332CE9
                                                                                                                                                                                                                                                          SHA-256:4A0495852CD4D0652B82FB57024645916DB8F192EEF9A82AFD580D87F4D496ED
                                                                                                                                                                                                                                                          SHA-512:03190F0E7EC35A358670B1617CB5C17EA3DD41195B2C4B748479D80ABAB4DB395293F688D94B87662D0469F6C5885CF7E7C9A995493A191905753F740DF659E1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Jujuy)]} {.. LoadTimeZoneFile America/Argentina/Jujuy..}..set TZData(:America/Jujuy) $TZData(:America/Argentina/Jujuy)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8682
                                                                                                                                                                                                                                                          Entropy (8bit):3.9620285142779728
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:/fCG0rHPC9+j1giaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:/aG0rq9DiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                                                                          MD5:8160A0D27EECEF40F6F34A06D5D02BE6
                                                                                                                                                                                                                                                          SHA1:7CAA64F83BAA0C23EE05A72BB1079AA552FA2F3D
                                                                                                                                                                                                                                                          SHA-256:5FBE6A1FA2D3DFE23C7378E425F32BEBCA44735DA25EA075A7E5CE24BFD4049D
                                                                                                                                                                                                                                                          SHA-512:59B8D04595007B45E582E6D17734999074CA67A93F5DF742EFE1EB78DB8ABD359D4C3B213B678C6A46040A13AAB709A994B6A532D720D3EF6FCA2730ABF4885E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Juneau) {.. {-9223372036854775808 54139 0 LMT}.. {-3225223727 -32261 0 LMT}.. {-2188954939 -28800 0 PST}.. {-883584000 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-757353600 -28800 0 PST}.. {-31507200 -28800 0 PST}.. {-21477600 -25200 1 PDT}.. {-5756400 -28800 0 PST}.. {9972000 -25200 1 PDT}.. {25693200 -28800 0 PST}.. {41421600 -25200 1 PDT}.. {57747600 -28800 0 PST}.. {73476000 -25200 1 PDT}.. {89197200 -28800 0 PST}.. {104925600 -25200 1 PDT}.. {120646800 -28800 0 PST}.. {126698400 -25200 1 PDT}.. {152096400 -28800 0 PST}.. {162381600 -25200 1 PDT}.. {183546000 -28800 0 PST}.. {199274400 -25200 1 PDT}.. {215600400 -28800 0 PST}.. {230724000 -25200 1 PDT}.. {247050000 -28800 0 PST}.. {262778400 -25200 1 PDT}.. {278499600 -28800 0 PST}.. {294228000 -25200 1 PDT}.. {309949
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9553
                                                                                                                                                                                                                                                          Entropy (8bit):3.853353361425414
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:tfTwKdrdJ9+StCt/cL1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:tfUKNdJ9+SItON0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:D721B38F1FFF1A6F5C02B72ECC06CDE5
                                                                                                                                                                                                                                                          SHA1:E70D99A9FC1DA9F30389129EE00FE20FA79D66A8
                                                                                                                                                                                                                                                          SHA-256:9EB1F2B19C44A55D6CC9FD1465BAF6535856941C067831E4B5E0494665014BF5
                                                                                                                                                                                                                                                          SHA-512:3C82A8C27026228F359FD96A4306F1BC337DE655FD1BA02C4399162E44DE59AD58CE569DA5AEA36E586C3BDEE7256420AABB84B44D277E244FE5AD771B4BE307
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Kentucky/Louisville) {.. {-9223372036854775808 -20582 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-1546279200 -21600 0 CST}.. {-1535904000 -18000 1 CDT}.. {-1525280400 -21600 0 CST}.. {-905097600 -18000 1 CDT}.. {-891795600 -21600 0 CST}.. {-883591200 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-747251940 -18000 1 CDT}.. {-744224400 -21600 0 CST}.. {-620841600 -18000 1 CDT}.. {-608144400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1 CDT}.. {-513190800 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-463593600 -18000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8558
                                                                                                                                                                                                                                                          Entropy (8bit):3.869494272122571
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:4F8qMahLi8hR1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:4F8HaUqJN0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:AED6497590DA305D16AC034979C8B1E9
                                                                                                                                                                                                                                                          SHA1:AD6F1788310A3A5A761873FEF1A32416B7DBCA89
                                                                                                                                                                                                                                                          SHA-256:1C6C7FB0AE628EB6BB305B51859C4E5594A6B0876C386ED9C1C3355E7CB37AE1
                                                                                                                                                                                                                                                          SHA-512:58D960AB5F2D9F8E4DD0171E5E36CE2E072F74A7AFDBC43F9340BBCF0CDC0D060AC895F9FCF551F4CC7EB6DBF2E9835C8C3D58E87CA4FBC98C720F51C462EDCD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Kentucky/Monticello) {.. {-9223372036854775808 -20364 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-63136800 -21600 0 CST}.. {-52934400 -18000 1 CDT}.. {-37213200 -21600 0 CST}.. {-21484800 -18000 1 CDT}.. {-5763600 -21600 0 CST}.. {9964800 -18000 1 CDT}.. {25686000 -21600 0 CST}.. {41414400 -18000 1 CDT}.. {57740400 -21600 0 CST}.. {73468800 -18000 1 CDT}.. {89190000 -21600 0 CST}.. {104918400 -18000 1 CDT}.. {120639600 -21600 0 CST}.. {126691200 -18000 1 CDT}.. {152089200 -21600 0 CST}.. {162374400 -18000 1 CDT}.. {183538800 -21600 0 CST}.. {199267200 -18000 1 CDT}.. {215593200 -21600 0 CST}.. {230716800 -18000
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):204
                                                                                                                                                                                                                                                          Entropy (8bit):4.8670778268802195
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y73GKaHAIgp3GKIN/2901iZ903GKT:MByMY3GKDp3GKIt290Q903GKT
                                                                                                                                                                                                                                                          MD5:50434016470AC512A8E2BEBA0BCEBC15
                                                                                                                                                                                                                                                          SHA1:F3541F6EE201FA33C66042F5C11A26434D37D42C
                                                                                                                                                                                                                                                          SHA-256:D66E77E6FF789D4D6CA13CDB204B977E1FE64BE9AFEE7B41F2C17ED8217FD025
                                                                                                                                                                                                                                                          SHA-512:EB1FF97050B7E067DCB68FF7C8F912C8A0C02144BB8E2EAA58C1136C6CC4A2B98C897DD23BB1E9C82D9AF6D028EE45227F97676CB34B6B830CDF5D707B990E57
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Knox)]} {.. LoadTimeZoneFile America/Indiana/Knox..}..set TZData(:America/Knox_IN) $TZData(:America/Indiana/Knox)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):204
                                                                                                                                                                                                                                                          Entropy (8bit):4.9362668992592456
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/2901Qv090ppv:MByMYbpwt290ev090b
                                                                                                                                                                                                                                                          MD5:FE9CEC6C50DF451B599B98AE8A434FF7
                                                                                                                                                                                                                                                          SHA1:60F997825766662B2C5415FBE4D65CEA6D326537
                                                                                                                                                                                                                                                          SHA-256:5AF9B28C48661FDC81762D249B716BA077F0A40ECF431D34A893BB7EABA57965
                                                                                                                                                                                                                                                          SHA-512:1311605021871BAFAF321AA48B352262C6BA42149101CCD4FDD4000435B2584AC564E0F76D481BB181767C010FD922BAA4E4EBB401AC2FF27B21874D89332872
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Kralendijk) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):218
                                                                                                                                                                                                                                                          Entropy (8bit):4.902526230255025
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/290WDm2OHphvoHvKZdcyFXmBVVON:MB86290ymdHphvCvKfcyy/ON
                                                                                                                                                                                                                                                          MD5:3BC04900A19D0152A31B353C6715A97B
                                                                                                                                                                                                                                                          SHA1:58A6D49E0B6FA00CBEAFD695D604D740AD63C54E
                                                                                                                                                                                                                                                          SHA-256:5488D98AA3C29D710C6AF92C42ACE36550A5BFF78C155CDF8769EE31F71CF033
                                                                                                                                                                                                                                                          SHA-512:65302935090F98A81443A1E1158911F57C3A1564564CD401CA72DDBF66D967DB564EF5AE8A4083D83984B9EF55AB53159010EFE2DB5D7A723F7EA61A1795322D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/La_Paz) {.. {-9223372036854775808 -16356 0 LMT}.. {-2524505244 -16356 0 CMT}.. {-1205954844 -12756 1 BST}.. {-1192307244 -14400 0 -04}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):460
                                                                                                                                                                                                                                                          Entropy (8bit):4.2444415392593875
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86290B2mdH4VCvvCOt/Os/OCQXR/uFfC3/O3e/uFbs/OX/OqF/O+8/OOS1F5/D:59etvqOVLOR/uGD/utsg38xSP5r
                                                                                                                                                                                                                                                          MD5:5F41E848D2DDE91261F45CB577B1B0A9
                                                                                                                                                                                                                                                          SHA1:DF284499CF57479ADE5E1D3DC01D6DCCF6AFDFE1
                                                                                                                                                                                                                                                          SHA-256:6E01002F264DF9A6FC247F95399F4F42DCCC7AB890B0C259DE93DCC97DEC89CE
                                                                                                                                                                                                                                                          SHA-512:2F5472F812734E892182632B8A34A4AD7B342541D0C3F1107BD95FFBE25D9351A0CDF5F58F35A1F37365DDF8A8A5D883C89C3CC40A9AD09D54CA152DC6BE1A09
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Lima) {.. {-9223372036854775808 -18492 0 LMT}.. {-2524503108 -18516 0 LMT}.. {-1938538284 -14400 0 -05}.. {-1002052800 -18000 0 -05}.. {-986756400 -14400 1 -05}.. {-971035200 -18000 0 -05}.. {-955306800 -14400 1 -05}.. {-939585600 -18000 0 -05}.. {512712000 -18000 0 -05}.. {544248000 -18000 0 -05}.. {638942400 -18000 0 -05}.. {765172800 -18000 0 -05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9726
                                                                                                                                                                                                                                                          Entropy (8bit):3.8515163794355916
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:/uX68CWSgG0U9bFzN6IkWq/WHQt/RY4yP:/uX68CWSgGVbGBt/M
                                                                                                                                                                                                                                                          MD5:4D4F198238E4E76753411896239041C3
                                                                                                                                                                                                                                                          SHA1:AD41D199DF0B794B5AB7F165C8A141787FAAC9A9
                                                                                                                                                                                                                                                          SHA-256:DA3F7572F04E6AE78B8F044761E6F48D37EE259A9C1FE15A67072CC64A299FDB
                                                                                                                                                                                                                                                          SHA-512:BA39D174B73B1D4B09E8AC07291BED0B9658A4330AE50881080F0E37C35BD8A6F55C49F1D649ED1F19CE47002435D8724048759DFC813BF9C2E9B06B581486FF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Los_Angeles) {.. {-9223372036854775808 -28378 0 LMT}.. {-2717640000 -28800 0 PST}.. {-1633269600 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-1601820000 -25200 1 PDT}.. {-1583679600 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-757353600 -28800 0 PST}.. {-687967140 -25200 1 PDT}.. {-662655600 -28800 0 PST}.. {-620838000 -25200 1 PDT}.. {-608137200 -28800 0 PST}.. {-589388400 -25200 1 PDT}.. {-576082800 -28800 0 PST}.. {-557938800 -25200 1 PDT}.. {-544633200 -28800 0 PST}.. {-526489200 -25200 1 PDT}.. {-513183600 -28800 0 PST}.. {-495039600 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463590000 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431535600 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {-400086000 -25200 1 PDT}.. {-386780400 -28800 0 PST}.. {-368636400 -25200 1 PDT}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):228
                                                                                                                                                                                                                                                          Entropy (8bit):4.911677030377383
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y71PiKp4o2HAIgp1PiKp4BvN/290hp4901PiKp44v:MByMYPyApPydt290P490Pyi
                                                                                                                                                                                                                                                          MD5:ACE87B25FE5604C83127A9F148A34C8C
                                                                                                                                                                                                                                                          SHA1:25C8D85B4740C53F40421D0DADCA95225EAB7829
                                                                                                                                                                                                                                                          SHA-256:F85C1253F4C1D3E85757D3DEA4FD3C61F1AA7BE6BAAE8CB8579278412905ACB2
                                                                                                                                                                                                                                                          SHA-512:AC0662B19F336474B146E06778E1FB43B941ABC8FD51BDB31B2640C94CCDFBE7659960EF4FD18329AFA7AD11316FC08D3CF33BB27931EA70AA7218667A8D0737
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Kentucky/Louisville)]} {.. LoadTimeZoneFile America/Kentucky/Louisville..}..set TZData(:America/Louisville) $TZData(:America/Kentucky/Louisville)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):207
                                                                                                                                                                                                                                                          Entropy (8bit):4.900350318979456
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290h48h490ppv:MByMYbpwt290/490b
                                                                                                                                                                                                                                                          MD5:83CE86174ADB5F276AABD26FE132BB55
                                                                                                                                                                                                                                                          SHA1:925E3F4A5DB1A2C33B3A537C8DBC9CFE309FA340
                                                                                                                                                                                                                                                          SHA-256:1E786229B84CE86DB6316B24C85F7CF4CFE66011F973053AD0E108BFCC9A9DE2
                                                                                                                                                                                                                                                          SHA-512:BA2AC5571D772B577735BC8E43FF8023228BC61A974DCCE0EAE20EC9B11FC757E56CABDAE00933A99834108114E598B7EC149BB017EB80BE18301A655F341A36
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Lower_Princes) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1539
                                                                                                                                                                                                                                                          Entropy (8bit):3.7453889877550512
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5QChlvEw6kSSx5H4a8tf3fkuoLdNYVZDNR8nd:OIlvEwJSSxdF8tfMuoLdNYVZJR8nd
                                                                                                                                                                                                                                                          MD5:EB0EDF4E075E3CF9F8EDF2B689C2FE54
                                                                                                                                                                                                                                                          SHA1:9713D7E8AA0E7164824657D00DE6C49483D2BD19
                                                                                                                                                                                                                                                          SHA-256:F65C5957D434A87324AAD35991E7666E426A20C40432540D9A3CB1EEE9141761
                                                                                                                                                                                                                                                          SHA-512:0A0D1E4E0BD7D854E8F139E6F7A9BBC66422B73F7A6C2E1F1B6D2CA400B24B3D220AB519B6AEAA743443E9A4B748709CDF2C276BF52C5382669B12734A469125
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Maceio) {.. {-9223372036854775808 -8572 0 LMT}.. {-1767217028 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):611
                                                                                                                                                                                                                                                          Entropy (8bit):4.303621439025158
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86290znTjmdHOYCvprv5EU/dLAyW+/uF+kX8/uF+RZ//dAWcP/QAWcx/uF+rbE:5GnPeOdvhxD1pLS+S8S+RVqzo4xS+3SJ
                                                                                                                                                                                                                                                          MD5:FB09D1F064C30F9E223FA119A8875098
                                                                                                                                                                                                                                                          SHA1:C66173FEB21761AEA649301D77FBB77ACF3A6FB1
                                                                                                                                                                                                                                                          SHA-256:F0F0CCE8DE92D848A62B56EF48E01D763B80153C077230C435D464CF1733BA38
                                                                                                                                                                                                                                                          SHA-512:BC3D841FF48FD0DE7C9ABF5DAE3A42C876BD4D7FBD6684B4513EC7ECC92D938A7133BCC873AD46E453DD1863E843E5C7DD14FFDB41B593E90BEB5CD8F7E66202
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Managua) {.. {-9223372036854775808 -20708 0 LMT}.. {-2524500892 -20712 0 MMT}.. {-1121105688 -21600 0 CST}.. {105084000 -18000 0 EST}.. {161758800 -21600 0 CST}.. {290584800 -18000 1 CDT}.. {299134800 -21600 0 CST}.. {322034400 -18000 1 CDT}.. {330584400 -21600 0 CST}.. {694260000 -18000 0 EST}.. {717310800 -21600 0 CST}.. {725868000 -18000 0 EST}.. {852094800 -21600 0 CST}.. {1113112800 -18000 1 CDT}.. {1128229200 -21600 0 CST}.. {1146384000 -18000 1 CDT}.. {1159682400 -21600 0 CST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1166
                                                                                                                                                                                                                                                          Entropy (8bit):3.7842934576858482
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5GnqeKwnSRs//SFs/pS9/MHSW/WOSr/nSso/TSL/SSU/iS5X/LcSi/xScd/ZlSQz:5mSeSFESoSQSrSsCSeSPS1cSQSQlSsSQ
                                                                                                                                                                                                                                                          MD5:E42719A9B0165490BB9E0E899EFB3643
                                                                                                                                                                                                                                                          SHA1:2991D7EC31F47E32D2C8DB89A0F87D814122DD1B
                                                                                                                                                                                                                                                          SHA-256:DC54E6D4FE14458B0462FA0E15B960FD4290930ADC0D13453BF49B436ED8C143
                                                                                                                                                                                                                                                          SHA-512:F75024E27A2D679A667EA70EC948F983C7B823FDA5962DD88697D61147A6C2B1499E58BA8B01170653C4D025900491AE8E21925500DE39EACBAF883F7E62D874
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Manaus) {.. {-9223372036854775808 -14404 0 LMT}.. {-1767211196 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201200 -1
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):201
                                                                                                                                                                                                                                                          Entropy (8bit):4.900738604616686
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290zzJ/90ppv:MByMYbpwt290zzN90b
                                                                                                                                                                                                                                                          MD5:8C60DE8E522FE5D51EACD643FD8EA132
                                                                                                                                                                                                                                                          SHA1:2E09A71DF340ECA6F7AEBD978070D56A627049EC
                                                                                                                                                                                                                                                          SHA-256:5C26D7CE93F91CC4F5ED87E9388B1B180EF9D84681044FD23CC01A628A1284CA
                                                                                                                                                                                                                                                          SHA-512:D2D522D041AFA638542F6FF00F5F40325E3F117C5035BA71F676B4956B054542C67A753055D17E2E2EEA925F13EACC0969D01EC18E40D274D8EA408F92777EA2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Marigot) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):251
                                                                                                                                                                                                                                                          Entropy (8bit):4.849143012086458
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/290zlEDm2OHfueoHv9dMIqR5lRfT/VVFUFkmR/lAov:MB86290zimdHfnCv9dMIqR5lVb/uFkmD
                                                                                                                                                                                                                                                          MD5:CFE10EE56115D3A5F44E047B3661D8ED
                                                                                                                                                                                                                                                          SHA1:03F598CFC9AEDE2F588339B439B2361F2EBDE34F
                                                                                                                                                                                                                                                          SHA-256:D411FB42798E93B106275EC0E054F8F3C4E9FB49431C656448739C7F20C46EDE
                                                                                                                                                                                                                                                          SHA-512:25D6760FDF2F1B0DD91A41D29BDB7048FAE27A03F7B9D9C955ECF4C32E8402836D007B39FE62B93E7BEA017681A0C8AFC1C4CAFD823B0A6C41EDAF09DDF3435D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Martinique) {.. {-9223372036854775808 -14660 0 LMT}.. {-2524506940 -14660 0 FFMT}.. {-1851537340 -14400 0 AST}.. {323841600 -10800 1 ADT}.. {338958000 -14400 0 AST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6745
                                                                                                                                                                                                                                                          Entropy (8bit):3.8432520851585372
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:aD5NA604qSScBgN+4ctDzIVQ/c/3hNxTh:aDbA604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:FC4A24AE95BA6E36285F09AB2FCEE56F
                                                                                                                                                                                                                                                          SHA1:54ED1CD69247064B5EC775E907790D19E93A4626
                                                                                                                                                                                                                                                          SHA-256:59C658CEA1BF5392A8F16295A09A74230EFB52EF7BF783E493E9A9C1799036F2
                                                                                                                                                                                                                                                          SHA-512:2E8E65C487090DC8EE90F8575360A00E74C134CE34E83D4296E2CC32B773F9F0151F4049BFD1BEEAFE7B441E8684AF9FB50287E42FBD5182E4051D1FC39932E3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Matamoros) {.. {-9223372036854775808 -23400 0 LMT}.. {-1514743200 -21600 0 CST}.. {568015200 -21600 0 CST}.. {576057600 -18000 1 CDT}.. {594198000 -21600 0 CST}.. {599637600 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {891763200 -18000 1 CDT}.. {909298800 -21600 0 CST}.. {923212800 -18000 1 CDT}.. {941353200 -21600 0 CST}.. {954662400 -18000 1 CDT}.. {972802800 -21600 0 CST}.. {989136000 -18000 1 CDT}.. {1001833200 -21600 0 CST}.. {1018166400 -18000 1 CDT}.. {1035702000 -21600 0 CST}.. {1049616000 -18000 1 CDT}.. {1067151600 -21600 0 CST}.. {1081065600 -18000 1 CDT}.. {1099206000 -21600 0 CST}.. {1112515200 -18000 1 CDT}.. {1130655600 -21600 0 CST}.. {1143964800 -18000 1 CDT}.. {1162105200 -21600 0 CST}.. {1175414400 -18000 1 CDT}.. {1193554800 -21600 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2067
                                                                                                                                                                                                                                                          Entropy (8bit):3.990817847620547
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5GtXed9WUQwuz/V/NF01YmM/parZ375+XiB+:5sNUIdFS1YrpaV5+yB+
                                                                                                                                                                                                                                                          MD5:43467194416FCF6F0D67AD2456D78646
                                                                                                                                                                                                                                                          SHA1:1FDF02EF7354D9DB71F545D32AE52D018E99D801
                                                                                                                                                                                                                                                          SHA-256:8140084EA9D6A478C34A114D9E216DC05450ECBE4809B2CDA194B40452E2AA0F
                                                                                                                                                                                                                                                          SHA-512:EB5CD3E95779391F096EE9A7B16920C6C9E8A90F38C7A3CBE2B0E123D088A127C5BBE21F5883DCDAD4FBB2410ED052EDE3D4F1E260483D97FEBB7BA7022874C1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Mazatlan) {.. {-9223372036854775808 -25540 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {-873828000 -25200 0 MST}.. {-661539600 -28800 0 PST}.. {28800 -25200 0 MST}.. {828867600 -21600 1 MDT}.. {846403200 -25200 0 MST}.. {860317200 -21600 1 MDT}.. {877852800 -25200 0 MST}.. {891766800 -21600 1 MDT}.. {909302400 -25200 0 MST}.. {923216400 -21600 1 MDT}.. {941356800 -25200 0 MST}.. {954666000 -21600 1 MDT}.. {972806400 -25200 0 MST}.. {989139600 -21600 1 MDT}.. {1001836800 -25200 0 MST}.. {1018170000 -21600 1 MDT}.. {1035705600 -25200 0 MST}.. {1049619600 -21600 1 MDT}.. {1067155200 -25200 0 MST}.. {1081069200 -21600 1 MDT}.. {1099209600 -25200 0 MST}.. {1112518800 -21600 1 MDT}.. {1130659200 -2520
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):219
                                                                                                                                                                                                                                                          Entropy (8bit):4.812188311941308
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7/MeHAIgp/MSvYovN/290zpH+90/MX:MByMY/M/p/MSA6t290zpe90/MX
                                                                                                                                                                                                                                                          MD5:2A3BFEEFBB684FB3B420A6B53B588BDC
                                                                                                                                                                                                                                                          SHA1:CC5C0BB90D847CCBB45688A8DA460AD575D64617
                                                                                                                                                                                                                                                          SHA-256:D6B308A1619F2DE450DACBFEF0E11B237DF7375A80C90899DD02B827688CB4B8
                                                                                                                                                                                                                                                          SHA-512:4A35C80D3454E039383FFEB06DC84933B3201BE2487C42A448AF3DA5ABAEEB9882263C011CDD3194E121EC1C31FC80120BF7829F280A79996E376CFA828EE215
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Mendoza)]} {.. LoadTimeZoneFile America/Argentina/Mendoza..}..set TZData(:America/Mendoza) $TZData(:America/Argentina/Mendoza)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8410
                                                                                                                                                                                                                                                          Entropy (8bit):3.8311875423131534
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:6quShLi8hbZlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:6lSUqtfA604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:C74D31382279219F805D2B138C58FBF7
                                                                                                                                                                                                                                                          SHA1:06E2FED0A3BDF62F3D390A4054B6A2D7C1863DD3
                                                                                                                                                                                                                                                          SHA-256:B0863F8B66F0848020651B69E7997307D62209259AE653FDC1A0FAFC8E793068
                                                                                                                                                                                                                                                          SHA-512:7B42CBDC119651E2B2EE8B8F934801D3147A8B72EE060A0D0EA1C0C12CA9ABD03F1A102A85BF8E7424B45620151CE107D16A9173F4AA7597EDB3109840C1B2AE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Menominee) {.. {-9223372036854775808 -21027 0 LMT}.. {-2659759773 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-747244800 -18000 1 CDT}.. {-733942800 -21600 0 CST}.. {-116438400 -18000 1 CDT}.. {-100112400 -21600 0 CST}.. {-21484800 -18000 0 EST}.. {104914800 -21600 0 CST}.. {104918400 -18000 1 CDT}.. {120639600 -21600 0 CST}.. {126691200 -18000 1 CDT}.. {152089200 -21600 0 CST}.. {162374400 -18000 1 CDT}.. {183538800 -21600 0 CST}.. {199267200 -18000 1 CDT}.. {215593200 -21600 0 CST}.. {230716800 -18000 1 CDT}.. {247042800 -21600 0 CST}.. {262771200 -18000 1 CDT}.. {278492400 -21600 0 CST}.. {294220800 -18000 1 CDT}.. {309942000 -2160
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1877
                                                                                                                                                                                                                                                          Entropy (8bit):3.9636871490767147
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5bu36fELf0On9uhcinzPPoUlWQnH7eelN5Lh9LY5Lj:1qehpYtj
                                                                                                                                                                                                                                                          MD5:34909341A29FF048D83B707D12A728A5
                                                                                                                                                                                                                                                          SHA1:A4D4EC31681DB5F9DA899E20C6789D10827E6D86
                                                                                                                                                                                                                                                          SHA-256:ADE65ADDEEA027D1BE70DC7C12513B61FDF36289021E66982D527C7FEE2A2D19
                                                                                                                                                                                                                                                          SHA-512:57EED40425680CE2C05D961D3F21EE2E0D204E1FD6D3DB5F1EF7AC349AA269F9397D4E2121BD13BC3DE34205564FBE009CEEB5ADE4052EA742CBA15A91F5822B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Merida) {.. {-9223372036854775808 -21508 0 LMT}.. {-1514743200 -21600 0 CST}.. {377935200 -18000 0 EST}.. {407653200 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {891763200 -18000 1 CDT}.. {909298800 -21600 0 CST}.. {923212800 -18000 1 CDT}.. {941353200 -21600 0 CST}.. {954662400 -18000 1 CDT}.. {972802800 -21600 0 CST}.. {989136000 -18000 1 CDT}.. {1001833200 -21600 0 CST}.. {1018166400 -18000 1 CDT}.. {1035702000 -21600 0 CST}.. {1049616000 -18000 1 CDT}.. {1067151600 -21600 0 CST}.. {1081065600 -18000 1 CDT}.. {1099206000 -21600 0 CST}.. {1112515200 -18000 1 CDT}.. {1130655600 -21600 0 CST}.. {1143964800 -18000 1 CDT}.. {1162105200 -21600 0 CST}.. {1175414400 -18000 1 CDT}.. {1193554800 -21600 0 CST}.. {1207468800 -18000 1 CDT}.. {1225004400 -21600 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6705
                                                                                                                                                                                                                                                          Entropy (8bit):3.985641709481311
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:4DCG0haiaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:42G0IiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                                                                          MD5:4999FE49C1640402CB432BC1EB667479
                                                                                                                                                                                                                                                          SHA1:2ED0044927A66856090793ED6E5FF634617C8C40
                                                                                                                                                                                                                                                          SHA-256:2574831391092AD44D7B2806EEF30D59CE3BAE872111917DD39EC51EFDD62E5F
                                                                                                                                                                                                                                                          SHA-512:39DE1D24037F3FFA3101BBAA885939074E596479F68013CDA9CE53A061EA704F63FB55C15B68B66B0E29E3F07ADC0BDC2D78A2D289277E75D2EF95F54988DB74
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Metlakatla) {.. {-9223372036854775808 54822 0 LMT}.. {-3225223727 -31578 0 LMT}.. {-2188955622 -28800 0 PST}.. {-883584000 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-757353600 -28800 0 PST}.. {-31507200 -28800 0 PST}.. {-21477600 -25200 1 PDT}.. {-5756400 -28800 0 PST}.. {9972000 -25200 1 PDT}.. {25693200 -28800 0 PST}.. {41421600 -25200 1 PDT}.. {57747600 -28800 0 PST}.. {73476000 -25200 1 PDT}.. {89197200 -28800 0 PST}.. {104925600 -25200 1 PDT}.. {120646800 -28800 0 PST}.. {126698400 -25200 1 PDT}.. {152096400 -28800 0 PST}.. {162381600 -25200 1 PDT}.. {183546000 -28800 0 PST}.. {199274400 -25200 1 PDT}.. {215600400 -28800 0 PST}.. {230724000 -25200 1 PDT}.. {247050000 -28800 0 PST}.. {262778400 -25200 1 PDT}.. {278499600 -28800 0 PST}.. {294228000 -25200 1 PDT}.. {30
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2261
                                                                                                                                                                                                                                                          Entropy (8bit):3.9546083289866267
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5CBUBUI+n36fELf5On9uhcinzPPoUlWQnH7eelN5Lh9LY5Lj:EB7qehpYtj
                                                                                                                                                                                                                                                          MD5:7A67EA7FF5AC0E9B088298007A9370F4
                                                                                                                                                                                                                                                          SHA1:531583F67E0C6ABA95B5A664A555BF40BF743CE8
                                                                                                                                                                                                                                                          SHA-256:E83DB749E6AA87FD56829C2810D0F93A4194E3EE2CB0BDC12114B1EF55E92E96
                                                                                                                                                                                                                                                          SHA-512:2C9035B415E36A769782FCFA15D79E5FEACA232439D1442407C8CD8C144EE9991030D9D58D2AD54CF6C0840BF78C81921B82BECBC74ABBD0DAC627F77772F52F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Mexico_City) {.. {-9223372036854775808 -23796 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {-975261600 -18000 1 CDT}.. {-963169200 -21600 0 CST}.. {-917114400 -18000 1 CDT}.. {-907354800 -21600 0 CST}.. {-821901600 -18000 1 CWT}.. {-810068400 -21600 0 CST}.. {-627501600 -18000 1 CDT}.. {-612990000 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {891763200 -18000 1 CDT}.. {909298800 -21600 0 CST}.. {923212800 -18000 1 CDT}.. {941353200 -21600 0 CST}.. {954662400 -18000 1 CDT}.. {972802800 -21600 0 CST}.. {989136000 -18000 1 CDT}.. {1001836800 -21600 0 CST}.. {1014184800 -21600 0 CST}.. {1018166400 -18000 1 CDT}.. {10357020
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7080
                                                                                                                                                                                                                                                          Entropy (8bit):3.5382250054538535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:KUViR+iORv7bw1aW5AnMyxH5e+fHbxMfOp6D7bF8qMmqyiqV1mjZe7JhlgXY7FWN:Y2l5qJZS
                                                                                                                                                                                                                                                          MD5:42921A574FC60D8489DCD493240FDF0D
                                                                                                                                                                                                                                                          SHA1:B45B09D6FD7ECA8DF6D3D3F9B136D88DDDAE8E44
                                                                                                                                                                                                                                                          SHA-256:BF086CC54807E13D0D7AC5294C429A4C16BB9562D1861B55FE758CA843400277
                                                                                                                                                                                                                                                          SHA-512:2E53EB257A5097C4B2995458369267007CBBBC70E69A26FBCB8E8F925ACF800C389489ABABC095D16E4EF088E0C33D9596EDBE2B2798783EFCE62CAF82CA9F70
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Miquelon) {.. {-9223372036854775808 -13480 0 LMT}.. {-1847650520 -14400 0 AST}.. {326001600 -10800 0 -03}.. {536468400 -10800 0 -02}.. {544597200 -7200 1 -02}.. {562132800 -10800 0 -02}.. {576046800 -7200 1 -02}.. {594187200 -10800 0 -02}.. {607496400 -7200 1 -02}.. {625636800 -10800 0 -02}.. {638946000 -7200 1 -02}.. {657086400 -10800 0 -02}.. {671000400 -7200 1 -02}.. {688536000 -10800 0 -02}.. {702450000 -7200 1 -02}.. {719985600 -10800 0 -02}.. {733899600 -7200 1 -02}.. {752040000 -10800 0 -02}.. {765349200 -7200 1 -02}.. {783489600 -10800 0 -02}.. {796798800 -7200 1 -02}.. {814939200 -10800 0 -02}.. {828853200 -7200 1 -02}.. {846388800 -10800 0 -02}.. {860302800 -7200 1 -02}.. {877838400 -10800 0 -02}.. {891752400 -7200 1 -02}.. {909288000 -10800 0 -02}.. {923202000 -7200 1 -02}.. {941342400 -10800 0 -02}.. {954651600 -7200
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10507
                                                                                                                                                                                                                                                          Entropy (8bit):3.8204583916930557
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:X9+FPHyXFRsivcQYM+T7Z/xVQzxmtBWIXrObx29x8sLxcGMe++wzlrfFjxKvnpNM:gF6L0d0F2TzNc/1cYUH+CC
                                                                                                                                                                                                                                                          MD5:80B88F57B837CD2478815796618A6AC6
                                                                                                                                                                                                                                                          SHA1:CC2BE0213E9F0D3B307A8311D7A1013582E8A338
                                                                                                                                                                                                                                                          SHA-256:D977D045DE5CDAEB41189B91963E03EF845CA4B45E496649B4CB541EE1B5DD22
                                                                                                                                                                                                                                                          SHA-512:9410CBD706CAABFFF88DFF75235597D844B45A061EBD796F6708D7CEAB680273571A17935B7CCFC7C466ABF293C286D0886F47880E692F74C4E8BFB41729C73C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Moncton) {.. {-9223372036854775808 -15548 0 LMT}.. {-2715882052 -18000 0 EST}.. {-2131642800 -14400 0 AST}.. {-1632074400 -10800 1 ADT}.. {-1615143600 -14400 0 AST}.. {-1167595200 -14400 0 AST}.. {-1153681200 -10800 1 ADT}.. {-1145822400 -14400 0 AST}.. {-1122231600 -10800 1 ADT}.. {-1114372800 -14400 0 AST}.. {-1090782000 -10800 1 ADT}.. {-1082923200 -14400 0 AST}.. {-1059332400 -10800 1 ADT}.. {-1051473600 -14400 0 AST}.. {-1027882800 -10800 1 ADT}.. {-1020024000 -14400 0 AST}.. {-996433200 -10800 1 ADT}.. {-988574400 -14400 0 AST}.. {-965674800 -10800 1 ADT}.. {-955396800 -14400 0 AST}.. {-934743600 -10800 1 ADT}.. {-923947200 -14400 0 AST}.. {-904503600 -10800 1 ADT}.. {-891892800 -14400 0 AST}.. {-883598400 -14400 0 AST}.. {-880221600 -10800 1 AWT}.. {-769395600 -10800 1 APT}.. {-765399600 -14400 0 AST}.. {-757368000 -14400 0 AST
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1940
                                                                                                                                                                                                                                                          Entropy (8bit):3.9628147491173964
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5JZKy36fELf0On9uhcinzPPoUlWQnH7eelN5Lh9LY5Lj:XwDqehpYtj
                                                                                                                                                                                                                                                          MD5:4AE2B33D9DACE0E582FA456B361C50B7
                                                                                                                                                                                                                                                          SHA1:5D62287F072F3687EF130BB1A9DD97BB2ABCF91C
                                                                                                                                                                                                                                                          SHA-256:F5A66A403BF40BE7EAB188F3CEC8D7DB700F60084F7B856AB87E0AA4A0F2C0B6
                                                                                                                                                                                                                                                          SHA-512:39BE803FD47709A1120FC8E09DB9B294DE41F69C7DD86AAB03AD8D0878B160B21D82B16398125559B792DAE99D5D917AE466C536001FEC1E618B68ACA9A80322
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Monterrey) {.. {-9223372036854775808 -24076 0 LMT}.. {-1514743200 -21600 0 CST}.. {568015200 -21600 0 CST}.. {576057600 -18000 1 CDT}.. {594198000 -21600 0 CST}.. {599637600 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {891763200 -18000 1 CDT}.. {909298800 -21600 0 CST}.. {923212800 -18000 1 CDT}.. {941353200 -21600 0 CST}.. {954662400 -18000 1 CDT}.. {972802800 -21600 0 CST}.. {989136000 -18000 1 CDT}.. {1001833200 -21600 0 CST}.. {1018166400 -18000 1 CDT}.. {1035702000 -21600 0 CST}.. {1049616000 -18000 1 CDT}.. {1067151600 -21600 0 CST}.. {1081065600 -18000 1 CDT}.. {1099206000 -21600 0 CST}.. {1112515200 -18000 1 CDT}.. {1130655600 -21600 0 CST}.. {1143964800 -18000 1 CDT}.. {1162105200 -21600 0 CST}.. {1175414400 -18000 1 CDT}.. {1193554800 -21600 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2936
                                                                                                                                                                                                                                                          Entropy (8bit):3.6410670126139046
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5JgQkS4SaEcSyS0sZSUS2kSVSXSulSASX5kAXJMsCXrUari3akaWCa3M+lafpI6L:X5kH4c9GT0E01jm5keJMRXrUEi3akaWO
                                                                                                                                                                                                                                                          MD5:D78DEBC7C0B15B31635DDC34C49248BC
                                                                                                                                                                                                                                                          SHA1:DB2FF76DB3A79BE52E2DFD4C7B8B6592946772F9
                                                                                                                                                                                                                                                          SHA-256:214F97A3BCB2378CCE23D280EA6A3B691604F82E383628F666BE585BB8494932
                                                                                                                                                                                                                                                          SHA-512:E5FCD0B54F61910E70B1D0EE9911C5B4AFF850F16B651A01D69A63A97880913B0BAB99B0D864C4E613594734FA72CCA0E9607B1ADB6E75957C790990114FD0A4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Montevideo) {.. {-9223372036854775808 -13491 0 LMT}.. {-1942690509 -13491 0 MMT}.. {-1567455309 -14400 0 -04}.. {-1459627200 -10800 0 -0330}.. {-1443819600 -12600 0 -0330}.. {-1428006600 -10800 1 -0330}.. {-1412283600 -12600 0 -0330}.. {-1396470600 -10800 1 -0330}.. {-1380747600 -12600 0 -0330}.. {-1141590600 -10800 1 -0330}.. {-1128286800 -12600 0 -0330}.. {-1110141000 -10800 1 -0330}.. {-1096837200 -12600 0 -0330}.. {-1078691400 -10800 1 -0330}.. {-1065387600 -12600 0 -0330}.. {-1047241800 -10800 1 -0330}.. {-1033938000 -12600 0 -0330}.. {-1015187400 -10800 1 -0330}.. {-1002488400 -12600 0 -0330}.. {-983737800 -10800 1 -0330}.. {-971038800 -12600 0 -0330}.. {-954707400 -10800 1 -0330}.. {-938984400 -12600 0 -0330}.. {-920838600 -10800 1 -0330}.. {-907534800 -12600 0 -0330}.. {-896819400 -10800 1 -0330}.. {-853621200 -9000 0 -03}.. {-84
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.748877320903638
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qMKLRXnXHAIg20qMKLRE6RL/2IAcGEzQ21h4IAcH:SlSWB9vsM3y7RQtHAIgpRQPN/290zQgp
                                                                                                                                                                                                                                                          MD5:9130CD86BD6417DB877BF9D8F3080CE1
                                                                                                                                                                                                                                                          SHA1:76C37982C37FE54ED539AC14B5A513817E42937C
                                                                                                                                                                                                                                                          SHA-256:97F48948EF5108FE1F42D548EA47C88D4B51BF1896EE92634C7ED55555B06DBD
                                                                                                                                                                                                                                                          SHA-512:EE036350AF95414392BD93DFF528F67D9A93EB192A30056ECBC3D2396AB4B2938B3C096C3EC2BC739294D4C4B7261C427B0AAEB9559F5381CB7F375892781820
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Toronto)]} {.. LoadTimeZoneFile America/Toronto..}..set TZData(:America/Montreal) $TZData(:America/Toronto)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):204
                                                                                                                                                                                                                                                          Entropy (8bit):4.878534808314885
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290zQ1HK90ppv:MByMYbpwt290zQ490b
                                                                                                                                                                                                                                                          MD5:CB5988A2508285B42C2BD487B8F9D6E1
                                                                                                                                                                                                                                                          SHA1:EAD740A566245B682CE5E284D389DFAE66DF05D9
                                                                                                                                                                                                                                                          SHA-256:6C3EE46983A3DAA91C9ADF4B18D6B4B80F1505B0057569B66D5B465D4C09B9C1
                                                                                                                                                                                                                                                          SHA-512:48796213A67F0E3BC56B54CE4D8BE098E74BA5808C9A1082D9381CB729ADFA2ACB9CE9E39A3244B3901405761C97AEE28D44C3BF7239ECC71175C62E152029C4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Montserrat) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):188
                                                                                                                                                                                                                                                          Entropy (8bit):4.785765433607229
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qMKLRXnXHAIg20qMKLRE6RL/2IAcGEwEzEeIAcGu:SlSWB9vsM3y7RQtHAIgpRQPN/290xzEf
                                                                                                                                                                                                                                                          MD5:F7DAD684104D917E0F29F6951EA627AC
                                                                                                                                                                                                                                                          SHA1:E57B5CA730D90C5865CF32FEC4872F71E033D21C
                                                                                                                                                                                                                                                          SHA-256:A889810B8BB42CD206D8F8961164AD03CCFBB1924D583075489F78AFA10EAF67
                                                                                                                                                                                                                                                          SHA-512:8284F2A357A32B2F5A211904F65E3B5C37B77C9BF38C85DFA0A95A73457F3076EC12F09BC767B4D0B8FC86BF69D01A17A7BF685BAB72F3E519A397D050DA0C3B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Toronto)]} {.. LoadTimeZoneFile America/Toronto..}..set TZData(:America/Nassau) $TZData(:America/Toronto)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11373
                                                                                                                                                                                                                                                          Entropy (8bit):3.8110553140357086
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:HeohzORhK1a8phYvNoStCt/cL1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:+uORhK1a8phYloSItON0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:385C3BDD3E41E5E75CEF0658322B5CDE
                                                                                                                                                                                                                                                          SHA1:0334C21C8316ED2EE16FC98B1E8867D5E0916C00
                                                                                                                                                                                                                                                          SHA-256:7BA7DA179AA7DF26AC25E7ACCD9BD83784174445285A0D9CCBD7D6A9AA34F4BC
                                                                                                                                                                                                                                                          SHA-512:764B680FB8414B5AC8FB110247C19B1004A4453DD2BAC94BF3CFD80281FF3679A5B1D212238509165E022269503ED14A54B0EF73AF7014344752E6A627657D1F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/New_York) {.. {-9223372036854775808 -17762 0 LMT}.. {-2717650800 -18000 0 EST}.. {-1633280400 -14400 1 EDT}.. {-1615140000 -18000 0 EST}.. {-1601830800 -14400 1 EDT}.. {-1583690400 -18000 0 EST}.. {-1577905200 -18000 0 EST}.. {-1570381200 -14400 1 EDT}.. {-1551636000 -18000 0 EST}.. {-1536512400 -14400 1 EDT}.. {-1523210400 -18000 0 EST}.. {-1504458000 -14400 1 EDT}.. {-1491760800 -18000 0 EST}.. {-1473008400 -14400 1 EDT}.. {-1459706400 -18000 0 EST}.. {-1441558800 -14400 1 EDT}.. {-1428256800 -18000 0 EST}.. {-1410109200 -14400 1 EDT}.. {-1396807200 -18000 0 EST}.. {-1378659600 -14400 1 EDT}.. {-1365357600 -18000 0 EST}.. {-1347210000 -14400 1 EDT}.. {-1333908000 -18000 0 EST}.. {-1315155600 -14400 1 EDT}.. {-1301853600 -18000 0 EST}.. {-1283706000 -14400 1 EDT}.. {-1270404000 -18000 0 EST}.. {-1252256400 -14400 1 EDT}.. {-123895440
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.799414617322291
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qMKLRXnXHAIg20qMKLRE6RL/2IAcGEwMueh4IAcH:SlSWB9vsM3y7RQtHAIgpRQPN/2905u+p
                                                                                                                                                                                                                                                          MD5:B01CC44E5139066F87ADFF16728B98BF
                                                                                                                                                                                                                                                          SHA1:4464E187AFF336C9137094308C270BB822974DF1
                                                                                                                                                                                                                                                          SHA-256:55C37BF1A579A22A790ADE6585CE95BEC02DA356E84D2EF7832C422A4484FF9D
                                                                                                                                                                                                                                                          SHA-512:A45166FFE444982593CBAC3E683D25D9EDB070DB6CD059A83D1C52099F409FFBFE6EA68D255AD000AF142BF8C8D100271531852263677184597877B7BF318847
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Toronto)]} {.. LoadTimeZoneFile America/Toronto..}..set TZData(:America/Nipigon) $TZData(:America/Toronto)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8680
                                                                                                                                                                                                                                                          Entropy (8bit):3.965662913874442
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:OrBvOs5vzC9+j1giaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:OrBvOsM9DiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                                                                          MD5:9A5F536932FED5A93E2C3DEB81960CD1
                                                                                                                                                                                                                                                          SHA1:8E78396D280DD3A9564CEFC7FB722437F3C4D003
                                                                                                                                                                                                                                                          SHA-256:8E971C9560CCE548B46626D072E62AB0F4C9682BF6A6ABFB4D0E8D63745402FE
                                                                                                                                                                                                                                                          SHA-512:60CFDBCE87F9CD7F27E071D66B97E60F62E56F413DC867BC809490B30D00045D0757710D6B5724148E2A28BD1E45FB662391820E6350D998002BF67B16776645
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Nome) {.. {-9223372036854775808 46702 0 LMT}.. {-3225223727 -39698 0 LMT}.. {-2188947502 -39600 0 NST}.. {-883573200 -39600 0 NST}.. {-880196400 -36000 1 NWT}.. {-769395600 -36000 1 NPT}.. {-765374400 -39600 0 NST}.. {-757342800 -39600 0 NST}.. {-86878800 -39600 0 BST}.. {-31496400 -39600 0 BST}.. {-21466800 -36000 1 BDT}.. {-5745600 -39600 0 BST}.. {9982800 -36000 1 BDT}.. {25704000 -39600 0 BST}.. {41432400 -36000 1 BDT}.. {57758400 -39600 0 BST}.. {73486800 -36000 1 BDT}.. {89208000 -39600 0 BST}.. {104936400 -36000 1 BDT}.. {120657600 -39600 0 BST}.. {126709200 -36000 1 BDT}.. {152107200 -39600 0 BST}.. {162392400 -36000 1 BDT}.. {183556800 -39600 0 BST}.. {199285200 -36000 1 BDT}.. {215611200 -39600 0 BST}.. {230734800 -36000 1 BDT}.. {247060800 -39600 0 BST}.. {262789200 -36000 1 BDT}.. {278510400 -39600 0 BST}.. {29423880
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1397
                                                                                                                                                                                                                                                          Entropy (8bit):3.78056049136398
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5TenykFxCFbF3YCFE2FBCFDFr9CFaFPBCFoF2CFTFKCFDuF1CF2F1CFWFhCFGF3a:5quY9EmFYBosNZNW/bWsBzgCccq7JYN9
                                                                                                                                                                                                                                                          MD5:B4F4530FCE4BF5690042A2DA40413D56
                                                                                                                                                                                                                                                          SHA1:52D5F2102485F5B326C888A287ED83CA18833BBC
                                                                                                                                                                                                                                                          SHA-256:9011C76295E6B17CC1973876B497BEE21B9E6562FB25DF66140F811A1FFA9765
                                                                                                                                                                                                                                                          SHA-512:08CAF75226D190D9FF0AA62AD84B13F1BF9047338A690847DF5B448BDB731A877F3E186298AFD704F4F4E133FF3F3128B098F9D90AE9A8E726AE52F84A7DA2E3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Noronha) {.. {-9223372036854775808 -7780 0 LMT}.. {-1767217820 -7200 0 -02}.. {-1206961200 -3600 1 -02}.. {-1191366000 -7200 0 -02}.. {-1175378400 -3600 1 -02}.. {-1159830000 -7200 0 -02}.. {-633823200 -3600 1 -02}.. {-622072800 -7200 0 -02}.. {-602287200 -3600 1 -02}.. {-591836400 -7200 0 -02}.. {-570751200 -3600 1 -02}.. {-560214000 -7200 0 -02}.. {-539128800 -3600 1 -02}.. {-531356400 -7200 0 -02}.. {-191368800 -3600 1 -02}.. {-184201200 -7200 0 -02}.. {-155167200 -3600 1 -02}.. {-150073200 -7200 0 -02}.. {-128901600 -3600 1 -02}.. {-121129200 -7200 0 -02}.. {-99957600 -3600 1 -02}.. {-89593200 -7200 0 -02}.. {-68421600 -3600 1 -02}.. {-57970800 -7200 0 -02}.. {499744800 -3600 1 -02}.. {511232400 -7200 0 -02}.. {530589600 -3600 1 -02}.. {540262800 -7200 0 -02}.. {562125600 -3600 1 -02}.. {571194000 -7200 0 -02}.. {592970400 -
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8557
                                                                                                                                                                                                                                                          Entropy (8bit):3.8810445182855253
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:WEktwmGaLV911sF9A604qSScBgN+4ctDzIVQ/c/3hNxTh:WBwDPPA604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:10AF9E9461DD03DA4F0AF0595EB36E6C
                                                                                                                                                                                                                                                          SHA1:57AC9BDE3AC665E49D9D2463A4BFA38C053A4A54
                                                                                                                                                                                                                                                          SHA-256:D0D8B108453265B60F525A4EC04DE9555087CD6AC5DDBA980B3A96CF0FCD68D1
                                                                                                                                                                                                                                                          SHA-512:B6DC7D2709A19B911E086C988DB8346F42DBF7601D9E51E3093C6AF897570E43E5F1C101FE88BC5251F3DCC3B532DB22FFE8A12A4D0151BC52AF3E6DDEA7D23A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/North_Dakota/Beulah) {.. {-9223372036854775808 -24427 0 LMT}.. {-2717643600 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126694800 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {230720400 -21600 1
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8557
                                                                                                                                                                                                                                                          Entropy (8bit):3.867423227197841
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:ZEktwmGaLV9tZlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:ZBwD6fA604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:33C03AD65753D7ADB45FC4899B504D1A
                                                                                                                                                                                                                                                          SHA1:ED719BB67A64DB49901BA38A945A6BA998646B8D
                                                                                                                                                                                                                                                          SHA-256:ABC2B6C97D9E9FBA37AC582ADBA2CE996890D090060E083405D75CDAED9EABE0
                                                                                                                                                                                                                                                          SHA-512:69592E8A370C8A5173827500CDDF8190AB44EA87CD7E0C416055CB7958B13A737801EA6B0FFE6032CB3F14F05001BF9DA83E4AEB20F385019B2985ECE7ACB40E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/North_Dakota/Center) {.. {-9223372036854775808 -24312 0 LMT}.. {-2717643600 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126694800 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {230720400 -21600 1
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8560
                                                                                                                                                                                                                                                          Entropy (8bit):3.879452555978431
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:GEktwmGaLV9nlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:GBwD2fA604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:3D3DC12209293086FD843738A4FE87FB
                                                                                                                                                                                                                                                          SHA1:8103DFA18B5F3F36AF0B53FA350E0F2D300E6289
                                                                                                                                                                                                                                                          SHA-256:8803FF7C81C933B57178B9D3C502FB4268D9AA594A3C638A7F17AF60B12D300D
                                                                                                                                                                                                                                                          SHA-512:39BB939780A71B817F82D2B7F56815D33926D150525161051A9950E5A98BA9184670AFC884A1C69D56EADBD6198E3082975448EFBA5FE8A336DB071E6BAB8EF2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/North_Dakota/New_Salem) {.. {-9223372036854775808 -24339 0 LMT}.. {-2717643600 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126694800 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {230720400 -2160
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7352
                                                                                                                                                                                                                                                          Entropy (8bit):3.563055036198918
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:0ixKXpbzvZ+FxAqe12voJ0euJFNgIHc/QEeF5Z1V8tCSfifK3facf+RQKW+FgL07:0L13/ML5t7P
                                                                                                                                                                                                                                                          MD5:70177C30ABA03AC9589E05674E54C782
                                                                                                                                                                                                                                                          SHA1:5D2D7F26663AC9CC45B9AB00BCBC950CEF6F5201
                                                                                                                                                                                                                                                          SHA-256:2F1F88823E80642137AC807059D11527FF873729CB9CB058B471612906BCD510
                                                                                                                                                                                                                                                          SHA-512:8E9A97188F2DA401B25155A94BF1D96797C58843E88A24D3AB4EC750801470284141FE4A6B51D0196568EBA63CEAF98D83F38C4DA19510E86EF43EF686CF5E4F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Nuuk) {.. {-9223372036854775808 -12416 0 LMT}.. {-1686083584 -10800 0 -03}.. {323845200 -7200 0 -02}.. {338950800 -10800 0 -03}.. {354675600 -7200 1 -02}.. {370400400 -10800 0 -03}.. {386125200 -7200 1 -02}.. {401850000 -10800 0 -03}.. {417574800 -7200 1 -02}.. {433299600 -10800 0 -03}.. {449024400 -7200 1 -02}.. {465354000 -10800 0 -03}.. {481078800 -7200 1 -02}.. {496803600 -10800 0 -03}.. {512528400 -7200 1 -02}.. {528253200 -10800 0 -03}.. {543978000 -7200 1 -02}.. {559702800 -10800 0 -03}.. {575427600 -7200 1 -02}.. {591152400 -10800 0 -03}.. {606877200 -7200 1 -02}.. {622602000 -10800 0 -03}.. {638326800 -7200 1 -02}.. {654656400 -10800 0 -03}.. {670381200 -7200 1 -02}.. {686106000 -10800 0 -03}.. {701830800 -7200 1 -02}.. {717555600 -10800 0 -03}.. {733280400 -7200 1 -02}.. {749005200 -10800 0 -03}.. {764730000 -7200 1 -0
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6874
                                                                                                                                                                                                                                                          Entropy (8bit):3.876618891121635
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:Se1c7Lv/PlrSScBgN+4ctDzIVQ/c/3hNxTh:oLv/PlrSBgI7DBch
                                                                                                                                                                                                                                                          MD5:95520E69610949A1FC42FD5FC44FE934
                                                                                                                                                                                                                                                          SHA1:38FCB8AA9C4CDC8687537B61F3B0350C67035414
                                                                                                                                                                                                                                                          SHA-256:94E803FCD69256C8228DC399F6A57A380F872426BF17E2D4D900C23D5E287810
                                                                                                                                                                                                                                                          SHA-512:11D6F604AA44CA6232B2D695D2D6A58F07F8357CE4095DE8C0F705770B632FC6BEE3F7227F398F29579BDA1C1129121F60D0A045F05DFEF042BC14B50D6D3C5A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Ojinaga) {.. {-9223372036854775808 -25060 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {820476000 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {883634400 -21600 0 CST}.. {891766800 -21600 0 MDT}.. {909302400 -25200 0 MST}.. {923216400 -21600 1 MDT}.. {941356800 -25200 0 MST}.. {954666000 -21600 1 MDT}.. {972806400 -25200 0 MST}.. {989139600 -21600 1 MDT}.. {1001836800 -25200 0 MST}.. {1018170000 -21600 1 MDT}.. {1035705600 -25200 0 MST}.. {1049619600 -21600 1 MDT}.. {1067155200 -25200 0 MST}.. {1081069200 -21600 1 MDT}.. {1099209600 -25200 0 MST}.. {1112518800 -21600 1 MDT}.. {1130659200 -25200 0 MST}.. {1143968400 -21
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):186
                                                                                                                                                                                                                                                          Entropy (8bit):4.970379147398626
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2IAcGEu5YfMXGm2OHGf8xYoHv5BidhZvFsc1HRX1va0v:SlSWB9eg/290ZDm2OHDxYoHv5GhZd93p
                                                                                                                                                                                                                                                          MD5:AA408A43079EC8933DE271BE3DA2B502
                                                                                                                                                                                                                                                          SHA1:421A867DB3FD4779C5F759D0B657D8EB5FB2218B
                                                                                                                                                                                                                                                          SHA-256:990213DDE00ADCEB74C8D1ECAF81B9C77963E4AB1F35767F7349236FC8E917DF
                                                                                                                                                                                                                                                          SHA-512:1FB740527555A8E128E05709D05720A249BCBA4B6434D00226C07426E6283AA48973F75268F36E6044F0F0650E012781C8E5519B7EA916C625BBF018B29E9961
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Panama) {.. {-9223372036854775808 -19088 0 LMT}.. {-2524502512 -19176 0 CMT}.. {-1946918424 -18000 0 EST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):193
                                                                                                                                                                                                                                                          Entropy (8bit):4.9032016816709225
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y73oHAIgp3FAN/290QX/4903V:MByMY3Jp3FAt290QX/4903V
                                                                                                                                                                                                                                                          MD5:86E07D2675D8D9D40684EC5AF45C3D88
                                                                                                                                                                                                                                                          SHA1:EA4DBBDBAC1AFFDE8BE46447359C4E6AED682D03
                                                                                                                                                                                                                                                          SHA-256:650A845BD9CEC7270438CBEA1A19D281B890019242AD782A60AF167BD1A0650D
                                                                                                                                                                                                                                                          SHA-512:E61060B18C20EC57E4DECFC464A2BB122A2C7A8C76A0B6F7BB36AE71B46E3DA072ECD2442C3149297E25B81121C7C7C10B017C131D33590BD321E16BE391BF66
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Iqaluit)]} {.. LoadTimeZoneFile America/Iqaluit..}..set TZData(:America/Pangnirtung) $TZData(:America/Iqaluit)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):253
                                                                                                                                                                                                                                                          Entropy (8bit):4.784405839512086
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/290olofDm2OHekeoHXFIV/1Vw/9vVOzFZg/VVFAKV:MB86290oloLmdHeVCXqV/k/9v4zW/OW
                                                                                                                                                                                                                                                          MD5:BFCE7E2618D6935031D6941AD6DDD8E3
                                                                                                                                                                                                                                                          SHA1:1953CD224FB2363B10372C0476760F3FB020CB00
                                                                                                                                                                                                                                                          SHA-256:B3EE44B3526BEDFC25B806371D3C465FDBD6CC647F30BF093750651E4A0C1BE4
                                                                                                                                                                                                                                                          SHA-512:31262DF034E084DA4CDB57B99178594C29129F61F3535E5D8245B8BB4AB6BF314307B0F5E58B74C349684CD761C9CDE44EB10407FB135BA6427D3D1E9DA99B40
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Paramaribo) {.. {-9223372036854775808 -13240 0 LMT}.. {-1861906760 -13252 0 PMT}.. {-1104524348 -13236 0 PMT}.. {-765317964 -12600 0 -0330}.. {465449400 -10800 0 -03}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):496
                                                                                                                                                                                                                                                          Entropy (8bit):4.444598497301421
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86290OXmdH514YCvb8o1W4S9xRvhhHRVxORBYUNv:5tekdvYP1x52yq
                                                                                                                                                                                                                                                          MD5:062ECA57C0B795780240CD7AFE70BDA0
                                                                                                                                                                                                                                                          SHA1:89D71A11DD8D4E000F7FADBDDC77C4C1DC1195F7
                                                                                                                                                                                                                                                          SHA-256:DFA0EC91804B789A1A7E1B1977710435D2589A5B54C1579C8E1F5BF96D2FD007
                                                                                                                                                                                                                                                          SHA-512:7D123AA872E0B8286A26E338AE0F8E0D7A6F0F2EA8B1EBEC6DBB59477C812985CB246AD397D0901A58FDB7FF14171CF60169DC15C538B95C58BD2D46106A7A4D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Phoenix) {.. {-9223372036854775808 -26898 0 LMT}.. {-2717643600 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-820519140 -25200 0 MST}.. {-796841940 -25200 0 MST}.. {-94669200 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-56221200 -25200 0 MST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6613
                                                                                                                                                                                                                                                          Entropy (8bit):3.8549788442269395
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5Ux+E2p3T6ZqrNSMEBPMcywh4NF5zCC7IOTWa1HW1241UWK9BDL+3XC4BMrS2LxP:KOfS0HY2iU7KKdFL6Aa2K4gSLf8e
                                                                                                                                                                                                                                                          MD5:A720323DF122C70C1530788DB24700BA
                                                                                                                                                                                                                                                          SHA1:20674BD7D84CC686ABBB5D6B36B520A5E9C813ED
                                                                                                                                                                                                                                                          SHA-256:A89C580899AD2FF8DF45A783BB90D501DC32C28B92931CA18ABD13453E76244B
                                                                                                                                                                                                                                                          SHA-512:02B71E537B9FDAF1B68E381F0007CCBBA53EB70719ED38F51B56C5BFA64C7E3D9797053C9DE3A920E5CAFA09BBC062FCED62B5D6B9213AFA8286B95DEDAB0532
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Port-au-Prince) {.. {-9223372036854775808 -17360 0 LMT}.. {-2524504240 -17340 0 PPMT}.. {-1670483460 -18000 0 EST}.. {421218000 -14400 1 EDT}.. {436334400 -18000 0 EST}.. {452062800 -14400 1 EDT}.. {467784000 -18000 0 EST}.. {483512400 -14400 1 EDT}.. {499233600 -18000 0 EST}.. {514962000 -14400 1 EDT}.. {530683200 -18000 0 EST}.. {546411600 -14400 1 EDT}.. {562132800 -18000 0 EST}.. {576050400 -14400 1 EDT}.. {594194400 -18000 0 EST}.. {607500000 -14400 1 EDT}.. {625644000 -18000 0 EST}.. {638949600 -14400 1 EDT}.. {657093600 -18000 0 EST}.. {671004000 -14400 1 EDT}.. {688543200 -18000 0 EST}.. {702453600 -14400 1 EDT}.. {719992800 -18000 0 EST}.. {733903200 -14400 1 EDT}.. {752047200 -18000 0 EST}.. {765352800 -14400 1 EDT}.. {783496800 -18000 0 EST}.. {796802400 -14400 1 EDT}.. {814946400 -18000 0 EST}.. {828856800 -14400 1 EDT}
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):207
                                                                                                                                                                                                                                                          Entropy (8bit):4.919510214047913
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290e7490ppv:MByMYbpwt290190b
                                                                                                                                                                                                                                                          MD5:4AB394CB233B101627136EB5E070CF9B
                                                                                                                                                                                                                                                          SHA1:F00600CD2DB10FE157C3696F665B9759EEA85F99
                                                                                                                                                                                                                                                          SHA-256:A4952380C89A6903FFE5BF8707B94B1BB72568FFD03DB04BF4D98E38AC82EEB7
                                                                                                                                                                                                                                                          SHA-512:58F4AD08FA10F1884FA641C4EA778C0FC013EABBD68DF5DE04D5B301227396260C3D669DB33DD6A6B33F1550C24BBD7777D756DF0D61CEEAF5EC6541EDFA296C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Port_of_Spain) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):201
                                                                                                                                                                                                                                                          Entropy (8bit):4.866417687745155
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7thteSHAIgpth9RN/290msh490th4:MByMYdIp7t290v490I
                                                                                                                                                                                                                                                          MD5:6B570E79FA2AA7D6CB1E56A11EE0A37C
                                                                                                                                                                                                                                                          SHA1:396A2C9BBE4F264DD5A4F2E44D3E63C57F52186B
                                                                                                                                                                                                                                                          SHA-256:52921EEA2A1925DF06CEA4638ED4128FAAA8FBA40ED4E0741650B419E5152DCB
                                                                                                                                                                                                                                                          SHA-512:FA75A179664BED02A0F5BC1B7C3DD5F3E986544A151634BA4C4401476F5999714C89E240D9AF805484D1BEC04A1A562157FAEECA1603C4FF8CFFB424B9DEB560
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Rio_Branco)]} {.. LoadTimeZoneFile America/Rio_Branco..}..set TZData(:America/Porto_Acre) $TZData(:America/Rio_Branco)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1051
                                                                                                                                                                                                                                                          Entropy (8bit):3.851275104153641
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5Xe4QJnSRs//SFs/pS9/MHSW/WOSr/nSso/TSL/SSU/iS5X/LcSi/xScd/ZlSQ/8:5kSeSFESoSQSrSsCSeSPS1cSQSQlSsSX
                                                                                                                                                                                                                                                          MD5:03046BA6F8344C32AD7A22748DC871AB
                                                                                                                                                                                                                                                          SHA1:AB9ED078D80AE99EF6DE4BF34AC45359B82D1284
                                                                                                                                                                                                                                                          SHA-256:E6E6F6753E7D443052A64D4DB07B8D443CE13A573946E7D0A19CDD4BBA4A2F04
                                                                                                                                                                                                                                                          SHA-512:620953BB4C8CF203262EC0C1F807543D24B9894C3B531AE57F7CEF630452CC9AC7CA41D43A6D8891F9CF17594E9EE34CF501F8508E7C0669A8E5EF9C70B6EAA3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Porto_Velho) {.. {-9223372036854775808 -15336 0 LMT}.. {-1767210264 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {5712012
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):283
                                                                                                                                                                                                                                                          Entropy (8bit):4.781646667761219
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/290piDm2OH9VoHvMlFoeVVF70ZVVFUFkzk/lLJpR/lAov:MB862908mdHvCvMlGe/J0Z/uFkzk/lL1
                                                                                                                                                                                                                                                          MD5:E2E2E0D6677FFF2E37BBFC3522F2A9AA
                                                                                                                                                                                                                                                          SHA1:4C1C93E14FBC00B8B1E78B8D9631599164305EB1
                                                                                                                                                                                                                                                          SHA-256:2981248A9F14EBFC8791EC5453170376CBD549557E495EA0E331CC18556C958E
                                                                                                                                                                                                                                                          SHA-512:F056B03EB9945823F5284C840E06E298DD2DE854F1555CD16D0BB19D962B73EF34A05683E6369B0D89CB7C3F7D082C312CCA6F8C6A0BB53F5C75FE4A863FCD95
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Puerto_Rico) {.. {-9223372036854775808 -15865 0 LMT}.. {-2233035335 -14400 0 AST}.. {-873057600 -10800 0 AWT}.. {-769395600 -10800 1 APT}.. {-765399600 -14400 0 AST}.. {-757368000 -14400 0 AST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3729
                                                                                                                                                                                                                                                          Entropy (8bit):3.6253057710886956
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:2RPW7xUQjzoMUBI0nuUoDKlHslPlgiot7JC/Xk8NWse4r4g5xCEmSdLkUsZOn+ZW:247xUQjzoMUBI0nuUoDK6lPlgiot7JCV
                                                                                                                                                                                                                                                          MD5:D4ECD2A380E55A10FB97AB1D29C619F3
                                                                                                                                                                                                                                                          SHA1:AAAFF44590F08623BE6F61EA6EFF6488C99A73BF
                                                                                                                                                                                                                                                          SHA-256:4E626BD8B9182E56ADA1E9276585E945957431EA9BEA949CE071305E4E3C70A2
                                                                                                                                                                                                                                                          SHA-512:677EE7093A53B48DE526C5877DB7128E8746831FE0DC44A38EB84050757E6017C9471EEF9AFCCEEEB5794D1608E486840804C01BD6276EA53F3C7823B05ED62B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Punta_Arenas) {.. {-9223372036854775808 -17020 0 LMT}.. {-2524504580 -16965 0 SMT}.. {-1892661435 -18000 0 -05}.. {-1688410800 -16965 0 SMT}.. {-1619205435 -14400 0 -04}.. {-1593806400 -16965 0 SMT}.. {-1335986235 -18000 0 -05}.. {-1335985200 -14400 1 -05}.. {-1317585600 -18000 0 -05}.. {-1304362800 -14400 1 -05}.. {-1286049600 -18000 0 -05}.. {-1272826800 -14400 1 -05}.. {-1254513600 -18000 0 -05}.. {-1241290800 -14400 1 -05}.. {-1222977600 -18000 0 -05}.. {-1209754800 -14400 1 -05}.. {-1191355200 -18000 0 -05}.. {-1178132400 -14400 0 -04}.. {-870552000 -18000 0 -05}.. {-865278000 -14400 0 -04}.. {-736632000 -14400 1 -04}.. {-718056000 -18000 0 -05}.. {-713649600 -14400 0 -04}.. {-36619200 -10800 1 -04}.. {-23922000 -14400 0 -04}.. {-3355200 -10800 1 -04}.. {7527600 -14400 0 -04}.. {24465600 -10800 1 -04}.. {37767600 -14400 0 -04}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):196
                                                                                                                                                                                                                                                          Entropy (8bit):4.926514352074701
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7pYHAIgppuRN/290ly90pl:MByMY/pcRt290w90X
                                                                                                                                                                                                                                                          MD5:552FBD2FBAD42F79C7993124D9CCC54B
                                                                                                                                                                                                                                                          SHA1:9029B7CCE8A5AD0F14C05FFBCDA4CA225DEC1708
                                                                                                                                                                                                                                                          SHA-256:FEC74A3FCBD9B99FDFF24B54223DA187958697CBE756A54592F6171C69F1403F
                                                                                                                                                                                                                                                          SHA-512:96315C32C1D0DEF804A560022DA12B3C63200A680F2A37D1B03E1C9EA413842EB6051E1C2315AE4E7C374280AD0E59832F834A8D6D66E259EF62735A77917ECE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Winnipeg)]} {.. LoadTimeZoneFile America/Winnipeg..}..set TZData(:America/Rainy_River) $TZData(:America/Winnipeg)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8029
                                                                                                                                                                                                                                                          Entropy (8bit):3.8280748194159004
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:fkLi8h4ZlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:f3qOfA604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:397E26B4DD207F18A08463C63313908C
                                                                                                                                                                                                                                                          SHA1:AE5894CD53A1F6A4671E63F427E190071ABED13D
                                                                                                                                                                                                                                                          SHA-256:AC78DB0895B016F81C09676F32B69BF38CA216283E7D2F5E594E41DF9BCB5530
                                                                                                                                                                                                                                                          SHA-512:8EC8BC32E1F5C790040C40219E478F7768B8ECE253ADB28DBEB1061FE159F2552852A70FFC29337F614C3CD9E64D8BA5E2AFF7462E8007099E3DA60EFC37B246
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Rankin_Inlet) {.. {-9223372036854775808 0 0 -00}.. {-410227200 -21600 0 CST}.. {73468800 -18000 1 CDT}.. {89190000 -21600 0 CST}.. {104918400 -18000 1 CDT}.. {120639600 -21600 0 CST}.. {136368000 -18000 1 CDT}.. {152089200 -21600 0 CST}.. {167817600 -18000 1 CDT}.. {183538800 -21600 0 CST}.. {199267200 -18000 1 CDT}.. {215593200 -21600 0 CST}.. {230716800 -18000 1 CDT}.. {247042800 -21600 0 CST}.. {262771200 -18000 1 CDT}.. {278492400 -21600 0 CST}.. {294220800 -18000 1 CDT}.. {309942000 -21600 0 CST}.. {325670400 -18000 1 CDT}.. {341391600 -21600 0 CST}.. {357120000 -18000 1 CDT}.. {372841200 -21600 0 CST}.. {388569600 -18000 1 CDT}.. {404895600 -21600 0 CST}.. {420019200 -18000 1 CDT}.. {436345200 -21600 0 CST}.. {452073600 -18000 1 CDT}.. {467794800 -21600 0 CST}.. {483523200 -18000 1 CDT}.. {499244400 -21600 0 CST}.. {514972
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1420
                                                                                                                                                                                                                                                          Entropy (8bit):3.78262494063765
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5aLexyGcChlrLPsw6kSS3h5R14eH8tf3GvIkuoYVZaI1kR8nd:5eTChlvEw6kSSx5H4a8tf3fkuoYVZDm+
                                                                                                                                                                                                                                                          MD5:4D12651CEE804EB9F29567CB37F12031
                                                                                                                                                                                                                                                          SHA1:54B2613475B8BDB1DBCCA53A4895DA021F66BDC0
                                                                                                                                                                                                                                                          SHA-256:A36AD4614FC9A2A433712B555156EDE03980B88EB91D8DC7E8B10451D6D7F7D3
                                                                                                                                                                                                                                                          SHA-512:E6690F6B6DF613C8B7289A2DB71FBC9B87B997707A6C3B4B45BDE8F347082AE8C69F212BAACE50F3C04E325ABE0976AF1F61107BDF8A15D5B88F11FAE11A9D00
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Recife) {.. {-9223372036854775808 -8376 0 LMT}.. {-1767217224 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1781
                                                                                                                                                                                                                                                          Entropy (8bit):4.034282439637634
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86290hjmdHfCv24Q1NAvHaE+YB+Q4kRcMxIeRUVX/SEQd1rRR9xRv0+Ro/wPjp:5EjeavTGOtAVvSRBpx0yq1epwD+yz+
                                                                                                                                                                                                                                                          MD5:14B29B4391B643E5707096ADCC33C57E
                                                                                                                                                                                                                                                          SHA1:B3F875ABB79C634C74307B7CB7B276B13AEE11D1
                                                                                                                                                                                                                                                          SHA-256:50105E788288CF4C680B29BBDCDE94D8713A5361B38C6C469FD97CF05503FF7D
                                                                                                                                                                                                                                                          SHA-512:D92A51547DF2C1AB6E6CDEFF34C07B755D3F6BB5E7DD1907693E7658EDE4D2BADC5DEFDB658ADD0F8D8F14B3B87CEA17BC00DAC364C5CB7ACBF8778C245276A9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Regina) {.. {-9223372036854775808 -25116 0 LMT}.. {-2030202084 -25200 0 MST}.. {-1632063600 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1251651600 -21600 1 MDT}.. {-1238349600 -25200 0 MST}.. {-1220202000 -21600 1 MDT}.. {-1206900000 -25200 0 MST}.. {-1188752400 -21600 1 MDT}.. {-1175450400 -25200 0 MST}.. {-1156698000 -21600 1 MDT}.. {-1144000800 -25200 0 MST}.. {-1125248400 -21600 1 MDT}.. {-1111946400 -25200 0 MST}.. {-1032714000 -21600 1 MDT}.. {-1016992800 -25200 0 MST}.. {-1001264400 -21600 1 MDT}.. {-986148000 -25200 0 MST}.. {-969814800 -21600 1 MDT}.. {-954093600 -25200 0 MST}.. {-937760400 -21600 1 MDT}.. {-922039200 -25200 0 MST}.. {-906310800 -21600 1 MDT}.. {-890589600 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-748450800 -21600 1 MDT}.. {-732729600 -25200 0 MST
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8025
                                                                                                                                                                                                                                                          Entropy (8bit):3.824511748400596
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:ykLi8h4Z80NA604qSScBgN+4ctDzIVQ/c/3hNxTh:y3qOzA604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:61326BB0D4D85BEF7F5849DFC86D19CD
                                                                                                                                                                                                                                                          SHA1:6AC04482473EE17DC94E9B3AF6F1AA75EBB7A82E
                                                                                                                                                                                                                                                          SHA-256:38C8868ACD122C3C60224EE384DFC15BC37D774C68D8463C58762F208FA2FEC9
                                                                                                                                                                                                                                                          SHA-512:563D3A888F41A0A28EFA458F9195D5FE3C53FE9163119E2941E7E8D4D354D3B2E4B1231AFCA07A21EFDB24365677BDA4B27E5CFC9BFC3BC800D204B22450EBED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Resolute) {.. {-9223372036854775808 0 0 -00}.. {-704937600 -21600 0 CST}.. {73468800 -18000 1 CDT}.. {89190000 -21600 0 CST}.. {104918400 -18000 1 CDT}.. {120639600 -21600 0 CST}.. {136368000 -18000 1 CDT}.. {152089200 -21600 0 CST}.. {167817600 -18000 1 CDT}.. {183538800 -21600 0 CST}.. {199267200 -18000 1 CDT}.. {215593200 -21600 0 CST}.. {230716800 -18000 1 CDT}.. {247042800 -21600 0 CST}.. {262771200 -18000 1 CDT}.. {278492400 -21600 0 CST}.. {294220800 -18000 1 CDT}.. {309942000 -21600 0 CST}.. {325670400 -18000 1 CDT}.. {341391600 -21600 0 CST}.. {357120000 -18000 1 CDT}.. {372841200 -21600 0 CST}.. {388569600 -18000 1 CDT}.. {404895600 -21600 0 CST}.. {420019200 -18000 1 CDT}.. {436345200 -21600 0 CST}.. {452073600 -18000 1 CDT}.. {467794800 -21600 0 CST}.. {483523200 -18000 1 CDT}.. {499244400 -21600 0 CST}.. {514972800
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1112
                                                                                                                                                                                                                                                          Entropy (8bit):3.8413073465060457
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5Ybe/k5Yss/uuD/uVK/uNC/uvFe/uxJs/u74O/u83C/uc8J/uhF8/uNHs/ulU6Gs:505YsMw57XJh4CxUF/A6GTrtSUDwr
                                                                                                                                                                                                                                                          MD5:7E23FDE0E158E8ED2E7536EDE70D2588
                                                                                                                                                                                                                                                          SHA1:319052BE076DC79F130E807D68B11CCAA0636340
                                                                                                                                                                                                                                                          SHA-256:28082D20872B61D6098D31D1C40F12464A946A933CD9AF74475C5AF384210890
                                                                                                                                                                                                                                                          SHA-512:BE078ED12F05AB5CEE5D77212EB76A01A1BC52EEAA17E3B91D93B88D75E5281B6AF164E712A9AB0F57A21B3CDB20F6FCCADB73CAC4745B5D2E665D18F9F06B55
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Rio_Branco) {.. {-9223372036854775808 -16272 0 LMT}.. {-1767209328 -18000 0 -05}.. {-1206950400 -14400 1 -05}.. {-1191355200 -18000 0 -05}.. {-1175367600 -14400 1 -05}.. {-1159819200 -18000 0 -05}.. {-633812400 -14400 1 -05}.. {-622062000 -18000 0 -05}.. {-602276400 -14400 1 -05}.. {-591825600 -18000 0 -05}.. {-570740400 -14400 1 -05}.. {-560203200 -18000 0 -05}.. {-539118000 -14400 1 -05}.. {-531345600 -18000 0 -05}.. {-191358000 -14400 1 -05}.. {-184190400 -18000 0 -05}.. {-155156400 -14400 1 -05}.. {-150062400 -18000 0 -05}.. {-128890800 -14400 1 -05}.. {-121118400 -18000 0 -05}.. {-99946800 -14400 1 -05}.. {-89582400 -18000 0 -05}.. {-68410800 -14400 1 -05}.. {-57960000 -18000 0 -05}.. {499755600 -14400 1 -05}.. {511243200 -18000 0 -05}.. {530600400 -14400 1 -05}.. {540273600 -18000 0 -05}.. {562136400 -14400 1 -05}.. {57120480
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):219
                                                                                                                                                                                                                                                          Entropy (8bit):4.801485647578614
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7/MSHAIgp/M1ovN/290rI5290/M7:MByMY/M7p/M16t290r190/M7
                                                                                                                                                                                                                                                          MD5:90830F3B1F91FE48AC2944C7C92A3F6E
                                                                                                                                                                                                                                                          SHA1:777377AE4959DDD2B472EB6041A23A5B93D64BB6
                                                                                                                                                                                                                                                          SHA-256:0117D33D4F326AA536162D36A02439FBD5F2EB3B4F540B5BA91ED7747DDAC180
                                                                                                                                                                                                                                                          SHA-512:20A371E4550E402AFEB83EF19EFFF6B3C0D7A68DCAA06AD894D04DB63B7096560E701C45B455B23A98BB20FE3B590F920219152415CA506AEDA427BB1381B826
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Cordoba)]} {.. LoadTimeZoneFile America/Argentina/Cordoba..}..set TZData(:America/Rosario) $TZData(:America/Argentina/Cordoba)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):194
                                                                                                                                                                                                                                                          Entropy (8bit):4.869058214823402
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7ekHAIgpeON/290tX2U490eBn:MByMYMpJt290c90m
                                                                                                                                                                                                                                                          MD5:F4E62378AA05771D348AA6DA516CD386
                                                                                                                                                                                                                                                          SHA1:07FCA813693F7944CBCBB128F2F2FE32929D37A2
                                                                                                                                                                                                                                                          SHA-256:3B4C2F3A5B9CD22A73F05187C032723D07BB53C9946D04D35E1BA1CB90CA0A62
                                                                                                                                                                                                                                                          SHA-512:E9F6CEB824D656CA25A72BF8EB4347A22E1A8E40410F01E0C2EDE19ACAF32D76540399796B3EBC7781C8B5D48C1A6B2C856CA06158AE37D95C95CF0567DFA2E5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Tijuana)]} {.. LoadTimeZoneFile America/Tijuana..}..set TZData(:America/Santa_Isabel) $TZData(:America/Tijuana)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1079
                                                                                                                                                                                                                                                          Entropy (8bit):3.8200568741699223
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5zeUdunSRs//SFs/pS9/MHSW/WOSr/nSso/TSL/SSU/iS5X/LcSi/xScd/ZlSQ/h:52SeSFESoSQSrSsCSeSPS1cSQSQlSsSU
                                                                                                                                                                                                                                                          MD5:7F2658032008F2C1308F121C2EBF2479
                                                                                                                                                                                                                                                          SHA1:B6F24E818B4424C0DEF818C103D1DA5359958932
                                                                                                                                                                                                                                                          SHA-256:4A397BD937DE1D7E6A941D18001B34D4CD195AEFD08951C30C7EE8E48656AA0E
                                                                                                                                                                                                                                                          SHA-512:F78853AA75F58A85555DD79E08A7487E5161854650DBF480189790D855738FEDCBDA936870067DE40FE000861008A9E9AAF61DF02B6B30B96038C61B5E1F1C1D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Santarem) {.. {-9223372036854775808 -13128 0 LMT}.. {-1767212472 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201200
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8871
                                                                                                                                                                                                                                                          Entropy (8bit):3.5351636359890537
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:2Xv/lxUQjzoMUBI0nuUoDK6lPlgiot7JC/k8NWse4r4g5xCEmMQUs8nCxvisEbzu:2fD9TzDC9g32+E
                                                                                                                                                                                                                                                          MD5:81FC6AFF68B1CF2EA57ED13A42B35BE1
                                                                                                                                                                                                                                                          SHA1:5889E502FBDCBCDFE9E7053625FFFBAD61FFE256
                                                                                                                                                                                                                                                          SHA-256:77CED11337F43241D57C10BA752C7104A7AF8727992E7B90A3C5D62AA15E81C7
                                                                                                                                                                                                                                                          SHA-512:7756CBAF76966F3D45883B725B791A8DD60E8329F6FE19C12029C6FEBC90D7322765A0A8BA26FC586443A902B372D0C0189426A8F99B2B535BB8F1EE74796B44
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Santiago) {.. {-9223372036854775808 -16965 0 LMT}.. {-2524504635 -16965 0 SMT}.. {-1892661435 -18000 0 -05}.. {-1688410800 -16965 0 SMT}.. {-1619205435 -14400 0 -04}.. {-1593806400 -16965 0 SMT}.. {-1335986235 -18000 0 -05}.. {-1335985200 -14400 1 -05}.. {-1317585600 -18000 0 -05}.. {-1304362800 -14400 1 -05}.. {-1286049600 -18000 0 -05}.. {-1272826800 -14400 1 -05}.. {-1254513600 -18000 0 -05}.. {-1241290800 -14400 1 -05}.. {-1222977600 -18000 0 -05}.. {-1209754800 -14400 1 -05}.. {-1191355200 -18000 0 -05}.. {-1178132400 -14400 0 -04}.. {-870552000 -18000 0 -05}.. {-865278000 -14400 0 -04}.. {-740520000 -10800 1 -03}.. {-736635600 -14400 1 -04}.. {-718056000 -18000 0 -05}.. {-713649600 -14400 0 -04}.. {-36619200 -10800 1 -04}.. {-23922000 -14400 0 -04}.. {-3355200 -10800 1 -04}.. {7527600 -14400 0 -04}.. {24465600 -10800 1 -04}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):616
                                                                                                                                                                                                                                                          Entropy (8bit):4.330655351784895
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86290/StmdHhvCvuCY/h/uFkS/5MVvMrW//MVvMrpx/m0XVvMr4UB/47VvMr/d:5+seQvuCY5/u/REfk+xxdbUBQpu652GO
                                                                                                                                                                                                                                                          MD5:FAD0621010889164ADC4472003C9391F
                                                                                                                                                                                                                                                          SHA1:C4EE0B8D6925338D17D5745DE9D45FA3C628DFC5
                                                                                                                                                                                                                                                          SHA-256:2217E72B11A90F2D679C175DE3CC0F2FED4C280C9FF9707CFFAF118BF9A06A4B
                                                                                                                                                                                                                                                          SHA-512:90E8E5A109CD72458C7796CF0324F63E543CCD63D13A09A3DD28EDC8B2793C964C18E79FDF0C5067C5A481B7FB03E8413139C32F59DA07E9D7893378ABBBD2B3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Santo_Domingo) {.. {-9223372036854775808 -16776 0 LMT}.. {-2524504824 -16800 0 SDMT}.. {-1159773600 -18000 0 EST}.. {-100119600 -14400 1 EDT}.. {-89668800 -18000 0 EST}.. {-5770800 -16200 1 -0430}.. {4422600 -18000 0 EST}.. {25678800 -16200 1 -0430}.. {33193800 -18000 0 EST}.. {57733200 -16200 1 -0430}.. {64816200 -18000 0 EST}.. {89182800 -16200 1 -0430}.. {96438600 -18000 0 EST}.. {120632400 -16200 1 -0430}.. {127974600 -18000 0 EST}.. {152082000 -14400 0 AST}.. {975823200 -14400 0 AST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2900
                                                                                                                                                                                                                                                          Entropy (8bit):3.6548008349990755
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5uFChlvEwR9xSSx5H4a8tf3fku+da2XUd23t8VZDG8+w/ghBPWTRz908a9zRgwun:cFIlvEwZSSxdF8tfMu+da2kdCt8VZy8n
                                                                                                                                                                                                                                                          MD5:F6B732A862659EB131C2E6FEC00E9734
                                                                                                                                                                                                                                                          SHA1:49517DF63BC5B6FEC875CE9477BBF84F4072FA31
                                                                                                                                                                                                                                                          SHA-256:0E7BA1C5A3FA3DABDAA226BFE1E8D797A3835EA554828881AB5E365EDA09B92E
                                                                                                                                                                                                                                                          SHA-512:670A5B604B5EA0F5FA15083BC1EA115B7EFD449F9EAC4518E109493591893DD3627AFC6628E0EDD1953E932E2A7AD9B5A379526548677158EC445366E4ED7166
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Sao_Paulo) {.. {-9223372036854775808 -11188 0 LMT}.. {-1767214412 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-195429600 -7200 1 -02}.. {-189381600 -7200 0 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7143
                                                                                                                                                                                                                                                          Entropy (8bit):3.5885930582268815
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:9OgtbdF7TI7nYUYXg9W/OAcv7vuShytWi0PnvLrqPoKR2XszXckXtoAQKW+FgL07:PJi3/ML5t7P
                                                                                                                                                                                                                                                          MD5:059960925B7DA716564823D787E0B738
                                                                                                                                                                                                                                                          SHA1:9AEBDB8FA3A2179F6B3B4C7FE66FB6D9C4FFAD74
                                                                                                                                                                                                                                                          SHA-256:699AA4926F63CD8DB41B71E7692CCB67920638CA4911437FF9922147558BCF68
                                                                                                                                                                                                                                                          SHA-512:5BE3F35271879692961EC834B79D0AEF94F34F1398BDE75BD226C758EC55D740229E9F433CEBD0494B3DA8ADA0357455D30B1BE6A6EDD0743F5E23CB718E3BAD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Scoresbysund) {.. {-9223372036854775808 -5272 0 LMT}.. {-1686090728 -7200 0 -02}.. {323841600 -3600 0 -01}.. {338961600 -7200 0 -02}.. {354679200 0 0 +00}.. {370400400 -3600 0 -01}.. {386125200 0 1 +00}.. {401850000 -3600 0 -01}.. {417574800 0 1 +00}.. {433299600 -3600 0 -01}.. {449024400 0 1 +00}.. {465354000 -3600 0 -01}.. {481078800 0 1 +00}.. {496803600 -3600 0 -01}.. {512528400 0 1 +00}.. {528253200 -3600 0 -01}.. {543978000 0 1 +00}.. {559702800 -3600 0 -01}.. {575427600 0 1 +00}.. {591152400 -3600 0 -01}.. {606877200 0 1 +00}.. {622602000 -3600 0 -01}.. {638326800 0 1 +00}.. {654656400 -3600 0 -01}.. {670381200 0 1 +00}.. {686106000 -3600 0 -01}.. {701830800 0 1 +00}.. {717555600 -3600 0 -01}.. {733280400 0 1 +00}.. {749005200 -3600 0 -01}.. {764730000 0 1 +00}.. {780454800 -3600 0 -01}.. {796179600 0 1 +00}.. {8
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):187
                                                                                                                                                                                                                                                          Entropy (8bit):4.888573146674231
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx06RGFfXHAIg206RORL/2IAcGEtOFBx+IAcGE6RB:SlSWB9vsM3y7+SPHAIgp+ON/290tO09Z
                                                                                                                                                                                                                                                          MD5:2FF74846ADF32AA3A9418376775B7F25
                                                                                                                                                                                                                                                          SHA1:130D7548DFFEBCE74969962E335B40299D7C5C54
                                                                                                                                                                                                                                                          SHA-256:BF4FAB3AE72CC7FA4F9E34CF0551A85C54A084CD826DF5D9CC684DE6188E84DB
                                                                                                                                                                                                                                                          SHA-512:9E52C017E595EEF1C68C8A1943416A9109D7DB4C32D25F83D05213C4200869A50E2E726894E39ECA364C558BB7F5566F6150CEA5D3CB14D1DEAE28C3D8C810E0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Denver)]} {.. LoadTimeZoneFile America/Denver..}..set TZData(:America/Shiprock) $TZData(:America/Denver)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8651
                                                                                                                                                                                                                                                          Entropy (8bit):3.959337076866423
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:IGCG0hPC9+j1giaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:I5G0A9DiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                                                                          MD5:7CCB6902749079A0496F1E2E2137448E
                                                                                                                                                                                                                                                          SHA1:3D0ED7BF1C26659F6794E26AE3869F8AB925B6DF
                                                                                                                                                                                                                                                          SHA-256:ABB08435CAE80119068A85984BFFE9C1596F4FB90F07CC01124C907E5162C189
                                                                                                                                                                                                                                                          SHA-512:0B5B2DCECC70F357DB6D590AB63E600C572EA6B3F430565EFEB29777B1901AAC55CACC7495C668F739201076B180402141BC1B2ED2357E9B4DFBABF3B122AB44
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Sitka) {.. {-9223372036854775808 53927 0 LMT}.. {-3225223727 -32473 0 LMT}.. {-2188954727 -28800 0 PST}.. {-883584000 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-757353600 -28800 0 PST}.. {-31507200 -28800 0 PST}.. {-21477600 -25200 1 PDT}.. {-5756400 -28800 0 PST}.. {9972000 -25200 1 PDT}.. {25693200 -28800 0 PST}.. {41421600 -25200 1 PDT}.. {57747600 -28800 0 PST}.. {73476000 -25200 1 PDT}.. {89197200 -28800 0 PST}.. {104925600 -25200 1 PDT}.. {120646800 -28800 0 PST}.. {126698400 -25200 1 PDT}.. {152096400 -28800 0 PST}.. {162381600 -25200 1 PDT}.. {183546000 -28800 0 PST}.. {199274400 -25200 1 PDT}.. {215600400 -28800 0 PST}.. {230724000 -25200 1 PDT}.. {247050000 -28800 0 PST}.. {262778400 -25200 1 PDT}.. {278499600 -28800 0 PST}.. {294228000 -25200 1 PDT}.. {3099492
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):207
                                                                                                                                                                                                                                                          Entropy (8bit):4.932842207797733
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290txP90ppv:MByMYbpwt2907P90b
                                                                                                                                                                                                                                                          MD5:CBFA61DBF6F7459CF8D517402B29998E
                                                                                                                                                                                                                                                          SHA1:A562B29C9470DBD25480966B0462433124BA4164
                                                                                                                                                                                                                                                          SHA-256:353CDBD46BA8C7472A93E9E800A69105801F6784B22EC50A59294CDC3BE40E18
                                                                                                                                                                                                                                                          SHA-512:00B333EAA2C32EDDA8F06457AD0E10013A0147B20F504F4F1096656F731A7C1896D5ABD83E7EDBD5D4E7DA587EE9BFA796539EB1E9F4056D75D1FDF203251150
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/St_Barthelemy) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11289
                                                                                                                                                                                                                                                          Entropy (8bit):3.8713946894934614
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:PmxVjd1cO8f7/EjUhSicN6zvfwb+8YbTE0M0J:PmrcOI7/EjiskY01J
                                                                                                                                                                                                                                                          MD5:8F068899DA75663128320633E1881333
                                                                                                                                                                                                                                                          SHA1:E9161B45D7B11A2DD6E9679AC080E84EC51561E3
                                                                                                                                                                                                                                                          SHA-256:E2917204B0C843C32051BB371CF6D0AD272C02720B9C0D913AC072C8ABE1EC64
                                                                                                                                                                                                                                                          SHA-512:2200E9B9D816157330ADAEA7383635876E5A37329B1AF9613D38BCFBE8143835837A25132A94E44A61DB8058ED98B1A33F295EA64BC1F4CE30966D52BB0B673D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/St_Johns) {.. {-9223372036854775808 -12652 0 LMT}.. {-2713897748 -12652 0 NST}.. {-1664130548 -9052 1 NDT}.. {-1650137348 -12652 0 NST}.. {-1640982548 -12652 0 NST}.. {-1632076148 -9052 1 NDT}.. {-1615145348 -12652 0 NST}.. {-1609446548 -12652 0 NST}.. {-1598650148 -9052 1 NDT}.. {-1590100148 -12652 0 NST}.. {-1567286948 -9052 1 NDT}.. {-1551565748 -12652 0 NST}.. {-1535837348 -9052 1 NDT}.. {-1520116148 -12652 0 NST}.. {-1503782948 -9052 1 NDT}.. {-1488666548 -12652 0 NST}.. {-1472333348 -9052 1 NDT}.. {-1457216948 -12652 0 NST}.. {-1440883748 -9052 1 NDT}.. {-1425767348 -12652 0 NST}.. {-1409434148 -9052 1 NDT}.. {-1394317748 -12652 0 NST}.. {-1377984548 -9052 1 NDT}.. {-1362263348 -12652 0 NST}.. {-1346534948 -9052 1 NDT}.. {-1330813748 -12652 0 NST}.. {-1314480548 -9052 1 NDT}.. {-1299364148 -12652 0 NST}.. {-1283030948 -9052 1 ND
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):202
                                                                                                                                                                                                                                                          Entropy (8bit):4.907031043022691
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290tMp490ppv:MByMYbpwt290g490b
                                                                                                                                                                                                                                                          MD5:D521F2D9B28C5374FC3BD540C6B6F40D
                                                                                                                                                                                                                                                          SHA1:39A3D86CB71F742F33B02F50B316638815B3CD4E
                                                                                                                                                                                                                                                          SHA-256:EDB9457A7C64E47062BDC6458FD3BCFCD6C37820F1A2BC89DFE99ED77355011F
                                                                                                                                                                                                                                                          SHA-512:05C1BE92550A962904ED3BB7DECCAC16FCB54D258F24F2AEDF755FCC44E4FEF5F86AB663945809F5D7AFA64178E807BBDAE77048270ED516DFF2C7720A746D52
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/St_Kitts) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):202
                                                                                                                                                                                                                                                          Entropy (8bit):4.9037013606484905
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290tY90ppv:MByMYbpwt290a90b
                                                                                                                                                                                                                                                          MD5:9392E5A7BD198B0308F9271E4C7E59B2
                                                                                                                                                                                                                                                          SHA1:A902440920A0318BC930957C74804A9A51EF7818
                                                                                                                                                                                                                                                          SHA-256:6727A509BB937CB3446D41B57826DE70C7028E96F088AB5B7F803BEAA18279E8
                                                                                                                                                                                                                                                          SHA-512:6DA1EAC390E72905DF1A14D82362B499D20FAD6D85F3DF116AE01E566D5D19C6D16E56DA72C458BB6143345EF45F35A53B245488C641D80BFBA200B16A59719E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/St_Lucia) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):203
                                                                                                                                                                                                                                                          Entropy (8bit):4.919272465019375
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290tXIMFJ490ppv:MByMYbpwt290tJ490b
                                                                                                                                                                                                                                                          MD5:49D0C8DAFCA053C9967EDCC4C0A484B1
                                                                                                                                                                                                                                                          SHA1:7B4999D4B9AD93306BD411DF2946D741EC597770
                                                                                                                                                                                                                                                          SHA-256:974AEED3D79124B50265C83D84F23CBE4F0328D00C75F42DD3ABC5D4C0A78DE1
                                                                                                                                                                                                                                                          SHA-512:378E3657B26C5A039FF82ECCAC7797FF45CBC6479596629B3048164EE4E035F4ECFC557AA9EAF6848E78999B4FF8C63E53C7163BDF6F626ED6111004490D6F80
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/St_Thomas) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):204
                                                                                                                                                                                                                                                          Entropy (8bit):4.909053768717241
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290tzb+Q90ppv:MByMYbpwt290xyQ90b
                                                                                                                                                                                                                                                          MD5:6CFB23E7164605CDE380FB7C4D88DF11
                                                                                                                                                                                                                                                          SHA1:CC513B29AD7B59E600DBCBC97927EB632558F657
                                                                                                                                                                                                                                                          SHA-256:6B19404D295964EF66F47802836BB728FCE8E6481115797C0B5F200C354D7C8A
                                                                                                                                                                                                                                                          SHA-512:728987D0925B6E12E8A220920BEDF94180880E78F3F08F6AC740E6304B22D446846068CEA499F61E7032ADB2E700CE31954921D478C9A8B6CB599E05A6292EA3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/St_Vincent) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):874
                                                                                                                                                                                                                                                          Entropy (8bit):4.253846650171654
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86290hEbmdHLCvYX4Q19xRv0+RmwPj+uLkQOzL3+ORL4FXgenM7RSslKA1PyKp:5zeOvT4xuyqoYaAxt7l
                                                                                                                                                                                                                                                          MD5:C91F801CC5E9F78B966D1DF2259C38A8
                                                                                                                                                                                                                                                          SHA1:D29C970CBFC74684D46AAAD543B73B520775632C
                                                                                                                                                                                                                                                          SHA-256:939B25C9412B9E25D73F552E87826999FC8C929770E66491D1E4530046D3E758
                                                                                                                                                                                                                                                          SHA-512:093378E61DE9310F9C48170CBB0FDBD3C79E184DA1489F759B20BCE410006A9D5A793C82E79A46E0AFF0DAA47D9DBAFD605959E491BA9ED4E55D26F293642D32
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Swift_Current) {.. {-9223372036854775808 -25880 0 LMT}.. {-2030201320 -25200 0 MST}.. {-1632063600 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-747241200 -21600 0 MDT}.. {-732729600 -25200 0 MST}.. {-715791600 -21600 1 MDT}.. {-702489600 -25200 0 MST}.. {-684342000 -21600 1 MDT}.. {-671040000 -25200 0 MST}.. {-652892400 -21600 1 MDT}.. {-639590400 -25200 0 MST}.. {-631126800 -25200 0 MST}.. {-400086000 -21600 1 MDT}.. {-384364800 -25200 0 MST}.. {-337186800 -21600 1 MDT}.. {-321465600 -25200 0 MST}.. {-305737200 -21600 1 MDT}.. {-292435200 -25200 0 MST}.. {-273682800 -21600 1 MDT}.. {-260985600 -25200 0 MST}.. {73472400 -21600 0 CST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):341
                                                                                                                                                                                                                                                          Entropy (8bit):4.638828647226646
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2903fDm2OHskeoHxbV1ULhgdrV/uF+IcmJ3/uF+ivi9/uF+SNv:MB862903LmdHsVCn1ULSB/uF+QV/uF+q
                                                                                                                                                                                                                                                          MD5:4C4034ABAB9E4804CCB23E51694044C9
                                                                                                                                                                                                                                                          SHA1:7DB24CE83AB2C07E6F6784D27C4E3AC0F149D080
                                                                                                                                                                                                                                                          SHA-256:1F0503579B0DDDBAF88814A278127D9CD7019EDD3C35F4CBFC0EF11C0EDAFE5B
                                                                                                                                                                                                                                                          SHA-512:0BC366CD3AB2E1388D11770DC8DEC1FC94C48FDC846ABB6C487828BF9FF15CD9A1C15B33E08F6E48B7F4A6F2AD1617FF12B359784CA4C32256D72422E6825105
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Tegucigalpa) {.. {-9223372036854775808 -20932 0 LMT}.. {-1538503868 -21600 0 CST}.. {547020000 -18000 1 CDT}.. {559717200 -21600 0 CST}.. {578469600 -18000 1 CDT}.. {591166800 -21600 0 CST}.. {1146981600 -18000 1 CDT}.. {1154926800 -21600 0 CST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6890
                                                                                                                                                                                                                                                          Entropy (8bit):3.8331465442823704
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:mJInJuFW4ng2CEBJuQaeEy9P19OBYEi/B51B7/Bm6BTd69xK7KjhVbHyR3h1gOZM:miFCC
                                                                                                                                                                                                                                                          MD5:D93B62D5F7EEBC28AC047BED2307CAE8
                                                                                                                                                                                                                                                          SHA1:8B3E02240A01B5AA42D30E86005E880916432227
                                                                                                                                                                                                                                                          SHA-256:7FB0CBB101D3B6FBB6B9DAD5446BBF9E6AEC65EC38472739E604F68F6AA9AB7B
                                                                                                                                                                                                                                                          SHA-512:3648106F4DF84CFD94AAD4E9430F8D3BBCB38A9196DE9A59246DFBBC170FADBF106DD1FD08FE2E4F7319BFFB1C2607E4F5D563C222CED8267483D1A0C388CCE5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Thule) {.. {-9223372036854775808 -16508 0 LMT}.. {-1686079492 -14400 0 AST}.. {670399200 -10800 1 ADT}.. {686120400 -14400 0 AST}.. {701848800 -10800 1 ADT}.. {717570000 -14400 0 AST}.. {733903200 -10800 1 ADT}.. {752043600 -14400 0 AST}.. {765352800 -10800 1 ADT}.. {783493200 -14400 0 AST}.. {796802400 -10800 1 ADT}.. {814942800 -14400 0 AST}.. {828856800 -10800 1 ADT}.. {846392400 -14400 0 AST}.. {860306400 -10800 1 ADT}.. {877842000 -14400 0 AST}.. {891756000 -10800 1 ADT}.. {909291600 -14400 0 AST}.. {923205600 -10800 1 ADT}.. {941346000 -14400 0 AST}.. {954655200 -10800 1 ADT}.. {972795600 -14400 0 AST}.. {986104800 -10800 1 ADT}.. {1004245200 -14400 0 AST}.. {1018159200 -10800 1 ADT}.. {1035694800 -14400 0 AST}.. {1049608800 -10800 1 ADT}.. {1067144400 -14400 0 AST}.. {1081058400 -10800 1 ADT}.. {1099198800 -14400 0 AST}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):193
                                                                                                                                                                                                                                                          Entropy (8bit):4.838326820531248
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7RQtHAIgpRQPN/2903MA90RQk:MByMYzp4t2903MA90D
                                                                                                                                                                                                                                                          MD5:D68B69B05D8743977BA4815B8AFE8E92
                                                                                                                                                                                                                                                          SHA1:364796989B6DD0110F1D85A8844419EB49772EC0
                                                                                                                                                                                                                                                          SHA-256:845101F85A6DAF9DEB58A075473F9E541A0B68461677779B1461DE59E3FA3D18
                                                                                                                                                                                                                                                          SHA-512:DEAA60DDF1521C269D7D386A7FCC40C8FAFB00EEA6764E6B23F4C65B8F6F596B3D5D2D3F6F7B1C22016C530B8789839F8052FDE1C2794C9F9C700C46DC8A3AEE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Toronto)]} {.. LoadTimeZoneFile America/Toronto..}..set TZData(:America/Thunder_Bay) $TZData(:America/Toronto)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8755
                                                                                                                                                                                                                                                          Entropy (8bit):3.8521303835918115
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:CuS6mjvZk53mtw+N6IkWq/WHQlb/RYRWVIKr7cRRL:26jFOzN6IkWq/WHQt/RY4yP
                                                                                                                                                                                                                                                          MD5:2F9983FE6248F3BF18ADE00192F4B458
                                                                                                                                                                                                                                                          SHA1:73F7302C914E442FC50DD4BFF3C57FD310E6455C
                                                                                                                                                                                                                                                          SHA-256:D7C5CB477A591931FF03C794C84EDB2319760C0B70047B325382F211E28648E3
                                                                                                                                                                                                                                                          SHA-512:B1F66008F2B62D4E1B59ED1A78A9E4F5D06BE074EB3B2466BDE3C9ED98DE96AD03FACDB8EDA6EE8F8EE890860DE6011F2BB364DE8C1276B31F37C9C525F4EC3F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Tijuana) {.. {-9223372036854775808 -28084 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1451667600 -28800 0 PST}.. {-1343062800 -25200 0 MST}.. {-1234803600 -28800 0 PST}.. {-1222963200 -25200 1 PDT}.. {-1207242000 -28800 0 PST}.. {-873820800 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-761677200 -28800 0 PST}.. {-686073600 -25200 1 PDT}.. {-661539600 -28800 0 PST}.. {-504892800 -28800 0 PST}.. {-495039600 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463590000 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431535600 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {-400086000 -25200 1 PDT}.. {-386780400 -28800 0 PST}.. {-368636400 -25200 1 PDT}.. {-355330800 -28800 0 PST}.. {-337186800 -25200 1 PDT}.. {-323881200 -28800 0 PST}.. {-305737200 -25200 1 PDT}.. {-292431600 -28800 0 PST}.. {-283968000 -28800 0 PST}.. {189331200 -28800 0 PST}.. {19
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11248
                                                                                                                                                                                                                                                          Entropy (8bit):3.8074559535773345
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:lBqTMRnK1a8phYTXEItON0HY2iUmUFLqU:lBqTMRnK1aWhYTPtgod
                                                                                                                                                                                                                                                          MD5:8907D214D511F1D3D95C79D4AC6CA687
                                                                                                                                                                                                                                                          SHA1:7B43858C6519424615D8E6E2E6F0049D69E18E2F
                                                                                                                                                                                                                                                          SHA-256:05C99D02D1F30E578CC3F1B0C1A30432953C8D7469BF23CEDA82E4450446C9F2
                                                                                                                                                                                                                                                          SHA-512:6DDAF81D1065A293B87201C79BC0FBFE912B1EC11C6A6D74DC8515CCA90F00E7CC0ABDD0DDC9E8DA3539E1036674D0AEE58386ADE3F0C8E3BA00F553C3F65B54
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Toronto) {.. {-9223372036854775808 -19052 0 LMT}.. {-2366736148 -18000 0 EST}.. {-1632070800 -14400 1 EDT}.. {-1615140000 -18000 0 EST}.. {-1609441200 -18000 0 EST}.. {-1601753400 -14400 1 EDT}.. {-1583697600 -18000 0 EST}.. {-1567357200 -14400 1 EDT}.. {-1554667200 -18000 0 EST}.. {-1534698000 -14400 1 EDT}.. {-1524074400 -18000 0 EST}.. {-1503248400 -14400 1 EDT}.. {-1492365600 -18000 0 EST}.. {-1471798800 -14400 1 EDT}.. {-1460916000 -18000 0 EST}.. {-1440954000 -14400 1 EDT}.. {-1428861600 -18000 0 EST}.. {-1409504400 -14400 1 EDT}.. {-1397412000 -18000 0 EST}.. {-1378054800 -14400 1 EDT}.. {-1365962400 -18000 0 EST}.. {-1346605200 -14400 1 EDT}.. {-1333908000 -18000 0 EST}.. {-1315155600 -14400 1 EDT}.. {-1301853600 -18000 0 EST}.. {-1283706000 -14400 1 EDT}.. {-1270404000 -18000 0 EST}.. {-1252256400 -14400 1 EDT}.. {-1238954400
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):201
                                                                                                                                                                                                                                                          Entropy (8bit):4.864308662322047
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290RRKl290ppv:MByMYbpwt290V90b
                                                                                                                                                                                                                                                          MD5:21D152A2359A4EFDE6DCC304F16096F3
                                                                                                                                                                                                                                                          SHA1:961B3CFB351615604981114A115D396D1F2006A2
                                                                                                                                                                                                                                                          SHA-256:46A236EC38F3A122D414208328A462B2A937392ECC6C55F673FB7A402F118D96
                                                                                                                                                                                                                                                          SHA-512:04A2AD6DDC2E7B0D3F95DA1C731FF553F8CBC0DD6BDFC36FB2EDCE755612103E3B4EA6F3AB7FE63CA60976538EFABF40827539DFC35B7E83129BD48471FE514B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Tortola) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9815
                                                                                                                                                                                                                                                          Entropy (8bit):3.8481935495337356
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:sOR864CjSAG5a9bFzN6IkWq/WHQt/RY4yP:sO664CjSAGYbGBt/M
                                                                                                                                                                                                                                                          MD5:9423BC81647BC4C37888860CE0518BBB
                                                                                                                                                                                                                                                          SHA1:37E6E6554576D1DD36C3494EAF0BD169003D870D
                                                                                                                                                                                                                                                          SHA-256:00B5FB8F37DFF43925C501AEAB039F39F058E002572C4203286317046CC1D700
                                                                                                                                                                                                                                                          SHA-512:1830CA2B62B7CA6EEB5A924D2148925DF7DD87A7B93B21F4F023E4678EF42DC20BFF57F702923E10F4382FE6757323D21414D094E99FEEB43316DE4A7E5A909E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Vancouver) {.. {-9223372036854775808 -29548 0 LMT}.. {-2713880852 -28800 0 PST}.. {-1632060000 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-747237600 -25200 1 PDT}.. {-733935600 -28800 0 PST}.. {-715788000 -25200 1 PDT}.. {-702486000 -28800 0 PST}.. {-684338400 -25200 1 PDT}.. {-671036400 -28800 0 PST}.. {-652888800 -25200 1 PDT}.. {-639586800 -28800 0 PST}.. {-620834400 -25200 1 PDT}.. {-608137200 -28800 0 PST}.. {-589384800 -25200 1 PDT}.. {-576082800 -28800 0 PST}.. {-557935200 -25200 1 PDT}.. {-544633200 -28800 0 PST}.. {-526485600 -25200 1 PDT}.. {-513183600 -28800 0 PST}.. {-495036000 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463586400 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431532000 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {-4
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):200
                                                                                                                                                                                                                                                          Entropy (8bit):4.914983069791254
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290RXgr490ppv:MByMYbpwt290xg090b
                                                                                                                                                                                                                                                          MD5:9F7DA15BE387B8F7DEC5DFFE069F3505
                                                                                                                                                                                                                                                          SHA1:D298B963B0048E9ECA3BC7B85248506AB1388479
                                                                                                                                                                                                                                                          SHA-256:561D9D04B0CE0F96A9C351C7D5C30AA1D5A42A3D70066CD9AF0DA6CBC5388DBE
                                                                                                                                                                                                                                                          SHA-512:606C2A918633C74BD2954D39B00EFA2CD9DA852BC7034F129A04258A65DC74942FA0826E9BC6E4433926E7F1375612554B04845077E434D0CD3BD15832DC6B95
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Virgin) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3033
                                                                                                                                                                                                                                                          Entropy (8bit):3.9639668937226795
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5CeFvmpn4nRfngnjSX8N8wIwEg7MkwY7Twbg7Uwr70vwHg7b6wa7gAHwc7/wzZgn:5BmC2apj/AOZFCARCeQbvb5wxMN6Ix
                                                                                                                                                                                                                                                          MD5:D4414DB00736994A19AD0FEACC77AE71
                                                                                                                                                                                                                                                          SHA1:A4B97A44BEA1FF0A76F21A21B4D63DFEDC093DC2
                                                                                                                                                                                                                                                          SHA-256:247049F795FDFDF7A9B3957EF6B1482540092AEC49147B7479E61551B6A31F47
                                                                                                                                                                                                                                                          SHA-512:A026D9F2AC297037266462B582162BE4B3715A3A2CF4E13B210149F498026DCE63809F71A803C6B33DDD44B18B6E5520E9D9F84635D8A786FBFB325227FDFE60
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Whitehorse) {.. {-9223372036854775808 -32412 0 LMT}.. {-2188997988 -32400 0 YST}.. {-1632056400 -28800 1 YDT}.. {-1615125600 -32400 0 YST}.. {-1596978000 -28800 1 YDT}.. {-1583164800 -32400 0 YST}.. {-880203600 -28800 1 YWT}.. {-769395600 -28800 1 YPT}.. {-765381600 -32400 0 YST}.. {-157734000 -32400 0 YST}.. {-147884400 -25200 1 YDDT}.. {-131554800 -32400 0 YST}.. {-121273200 -28800 0 PST}.. {315561600 -28800 0 PST}.. {325677600 -25200 1 PDT}.. {341398800 -28800 0 PST}.. {357127200 -25200 1 PDT}.. {372848400 -28800 0 PST}.. {388576800 -25200 1 PDT}.. {404902800 -28800 0 PST}.. {420026400 -25200 1 PDT}.. {436352400 -28800 0 PST}.. {452080800 -25200 1 PDT}.. {467802000 -28800 0 PST}.. {483530400 -25200 1 PDT}.. {499251600 -28800 0 PST}.. {514980000 -25200 1 PDT}.. {530701200 -28800 0 PST}.. {544615200 -25200 1 PDT}.. {562150800 -288
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9695
                                                                                                                                                                                                                                                          Entropy (8bit):3.8209220355628766
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:pOEhc8/rvNZONqXXyIjNA604qSScBgN+4ctDzIVQ/c/3hNxTh:pY8DvbO+A604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:E8DB00D2B99B308018F4F5E48AC47C3A
                                                                                                                                                                                                                                                          SHA1:8841467CB264DC9F87FABAADBE90EE2C8DACC80F
                                                                                                                                                                                                                                                          SHA-256:F3FC5F6D93D1D9EB0F3DED33873F33C47F841797D96439966F8E0A5A189941FA
                                                                                                                                                                                                                                                          SHA-512:5D684B07332ED53F9F8CB71FFF3B6D0F848426A5E4D9E7DA84E49E358C666F1C3BB9CF21352D939B35B558FC691839E24BC84656317F73C768B474AF5AC480EB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Winnipeg) {.. {-9223372036854775808 -23316 0 LMT}.. {-2602258284 -21600 0 CST}.. {-1694368800 -18000 1 CDT}.. {-1681671600 -21600 0 CST}.. {-1632067200 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1029686400 -18000 1 CDT}.. {-1018198800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-746035200 -18000 1 CDT}.. {-732733200 -21600 0 CST}.. {-715795200 -18000 1 CDT}.. {-702493200 -21600 0 CST}.. {-684345600 -18000 1 CDT}.. {-671043600 -21600 0 CST}.. {-652896000 -18000 1 CDT}.. {-639594000 -21600 0 CST}.. {-620755200 -18000 1 CDT}.. {-607626000 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1 CDT}.. {-513190800 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8683
                                                                                                                                                                                                                                                          Entropy (8bit):3.957710943557426
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:po1acs6yyyxC9+j1giaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:p4acsW9DiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                                                                          MD5:18EC35FCEC15CE9304818E22222411EF
                                                                                                                                                                                                                                                          SHA1:F4A04B3E2B5F55C9582F578C3142E706C4EB6BD6
                                                                                                                                                                                                                                                          SHA-256:79B44F245D86A4EC299D1A9A2EDB2AB92D50AB5A7C1C03759D283AC4070F9005
                                                                                                                                                                                                                                                          SHA-512:40AC47AC278DF22C7ECFF568456E7C3767B38701B9A2E2639C2201DC53CDD794CF7521BCB773A8AF2A8D4A034D3BBD35BF9788FB5B4E4D51A7A139B3B3353479
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Yakutat) {.. {-9223372036854775808 52865 0 LMT}.. {-3225223727 -33535 0 LMT}.. {-2188953665 -32400 0 YST}.. {-883580400 -32400 0 YST}.. {-880203600 -28800 1 YWT}.. {-769395600 -28800 1 YPT}.. {-765381600 -32400 0 YST}.. {-757350000 -32400 0 YST}.. {-31503600 -32400 0 YST}.. {-21474000 -28800 1 YDT}.. {-5752800 -32400 0 YST}.. {9975600 -28800 1 YDT}.. {25696800 -32400 0 YST}.. {41425200 -28800 1 YDT}.. {57751200 -32400 0 YST}.. {73479600 -28800 1 YDT}.. {89200800 -32400 0 YST}.. {104929200 -28800 1 YDT}.. {120650400 -32400 0 YST}.. {126702000 -28800 1 YDT}.. {152100000 -32400 0 YST}.. {162385200 -28800 1 YDT}.. {183549600 -32400 0 YST}.. {199278000 -28800 1 YDT}.. {215604000 -32400 0 YST}.. {230727600 -28800 1 YDT}.. {247053600 -32400 0 YST}.. {262782000 -28800 1 YDT}.. {278503200 -32400 0 YST}.. {294231600 -28800 1 YDT}.. {30995
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):196
                                                                                                                                                                                                                                                          Entropy (8bit):4.860140868038404
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y77G2HAIgp7bN/290nCJ/h4907Wv:MByMY7GXp7bt290nw4907Wv
                                                                                                                                                                                                                                                          MD5:7F1D0FFA4000B0C28EF0E4FF2E2BCE80
                                                                                                                                                                                                                                                          SHA1:8FC906A8E370F103EC6737F613F037F8D67561D5
                                                                                                                                                                                                                                                          SHA-256:B95DB5099C5C96966056E292F0C8BA590A5D1A2417CC939CB7AC39A097B99B28
                                                                                                                                                                                                                                                          SHA-512:BA99FFFDB1CDE6DBE63027F494A6070487F75BD074B1768C10BD2DEC8805B3EB8A224164D1CE86A0BE583E4E6C453BAE8E40C8C1224248C83634423B79ECF7E9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Edmonton)]} {.. LoadTimeZoneFile America/Edmonton..}..set TZData(:America/Yellowknife) $TZData(:America/Edmonton)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):628
                                                                                                                                                                                                                                                          Entropy (8bit):4.077288238381896
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862LcUmdHE5QMFi+KdTVPZIwX8ks3mAY1+:5oUeEodZxIU8ksWAYs
                                                                                                                                                                                                                                                          MD5:57BCAE9521644BB14F858D3A6083F973
                                                                                                                                                                                                                                                          SHA1:87DE492C432373015588743EDEC3F109BAA9F824
                                                                                                                                                                                                                                                          SHA-256:76B4CAA9BACB90ADD9F1778CD266E30C4EE28BC5EE566AA674C6E1A97BD8BA5E
                                                                                                                                                                                                                                                          SHA-512:0B69F3D7E926CE086E63E659289EAD0C8BB693BB3AC49D60D585EF056BAE0158BE398172DFB322B8236BB73083D6766551369599DEB37B2BD42532835C72656B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Casey) {.. {-9223372036854775808 0 0 -00}.. {-31536000 28800 0 +08}.. {1255802400 39600 0 +11}.. {1267714800 28800 0 +08}.. {1319738400 39600 0 +11}.. {1329843600 28800 0 +08}.. {1477065600 39600 0 +11}.. {1520701200 28800 0 +08}.. {1538856000 39600 0 +11}.. {1552752000 28800 0 +08}.. {1570129200 39600 0 +11}.. {1583596800 28800 0 +08}.. {1601740860 39600 0 +11}.. {1615640400 28800 0 +08}.. {1633190460 39600 0 +11}.. {1647090000 28800 0 +08}.. {1664640060 39600 0 +11}.. {1678291200 28800 0 +08}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):324
                                                                                                                                                                                                                                                          Entropy (8bit):4.360007144607037
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2L0mDm2OHEfwz0/MVSYyF/KZ7VoX/MVSYyF/VpVQVF9RXhNXSMVSYy6:MB862LVmdHEIjsF/KZOksF/Vp6v9RRFl
                                                                                                                                                                                                                                                          MD5:97AA556F7EF06786B76316133794F4E9
                                                                                                                                                                                                                                                          SHA1:B3CDA284DE80987B954E2CC9BFA3ED33462CDD4F
                                                                                                                                                                                                                                                          SHA-256:2F36D2E13D7E251322B7A7B30F39645393525CEB49A2B5C26F27797F2AAF4D7F
                                                                                                                                                                                                                                                          SHA-512:14C6F17252C2AC89D86FE00BD8A8934D627C85478B0AB08AB6237988922D18616B00878498FFFC0E1978308BC6D775E2DC3ADCEF827AB0A06B214BE4DDABAB52
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Davis) {.. {-9223372036854775808 0 0 -00}.. {-409190400 25200 0 +07}.. {-163062000 0 0 -00}.. {-28857600 25200 0 +07}.. {1255806000 18000 0 +05}.. {1268251200 25200 0 +07}.. {1319742000 18000 0 +05}.. {1329854400 25200 0 +07}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):214
                                                                                                                                                                                                                                                          Entropy (8bit):4.938579775653117
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yci/452HAIgObi/4oA6N/2L0/3Zp5/4pv:MByMdNXiU5t2Lkwv
                                                                                                                                                                                                                                                          MD5:CC22302B9FAE52E36A2A35C0361E774B
                                                                                                                                                                                                                                                          SHA1:45CFD95A5821C4C4FDF2E1519F08029FF0BE664B
                                                                                                                                                                                                                                                          SHA-256:96F2AB9A9FFCD10598FDF105F68460CC4B4EBC1F18054D1BC8E39DF6AD24D1AC
                                                                                                                                                                                                                                                          SHA-512:FC9084D7B16EAA985681762F2658D32C77EE186D8D3C7225093CC5CB4A6AEB74A3D0A41A904EB6C8AEF7DB110A89497BAFAF811BBC26103F96E5E1D4D4E1002A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Port_Moresby)]} {.. LoadTimeZoneFile Pacific/Port_Moresby..}..set TZData(:Antarctica/DumontDUrville) $TZData(:Pacific/Port_Moresby)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8447
                                                                                                                                                                                                                                                          Entropy (8bit):3.850137279218428
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:s1qigkx6WsYyS391QiAmcO38EJ8i/V9cYgCqMEjKeIZ3wQb25Ly04:s1q05h1QiAmcOM6e0pj
                                                                                                                                                                                                                                                          MD5:81C612A1544910544173687C416841C6
                                                                                                                                                                                                                                                          SHA1:4A707B403F0B9556A3D3D50B08BE0F56660F3F0B
                                                                                                                                                                                                                                                          SHA-256:C4EA7F1C0B5A0FAE653419F1C6D058BDDD745A3CDBA11900005C157DF23DDC01
                                                                                                                                                                                                                                                          SHA-512:122E2DC3D8D61CCDB83E03C9487DD29AABE7AB3F71FE4F6315209AF0BBCFD01FBDC3A1E3F6D910FB0D690378DF852170A9819D8C1EF96BE6BC8C0811BFB453A9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Macquarie) {.. {-9223372036854775808 0 0 -00}.. {-2214259200 36000 0 AEST}.. {-1680508800 39600 1 AEDT}.. {-1669892400 39600 0 AEDT}.. {-1665388800 36000 0 AEST}.. {-1601719200 0 0 -00}.. {-94730400 36000 0 AEST}.. {-71136000 39600 1 AEDT}.. {-55411200 36000 0 AEST}.. {-37267200 39600 1 AEDT}.. {-25776000 36000 0 AEST}.. {-5817600 39600 1 AEDT}.. {5673600 36000 0 AEST}.. {25632000 39600 1 AEDT}.. {37728000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {89136000 39600 1 AEDT}.. {100022400 36000 0 AEST}.. {120585600 39600 1 AEDT}.. {131472000 36000 0 AEST}.. {152035200 39600 1 AEDT}.. {162921600 36000 0 AEST}.. {183484800 39600 1 AEDT}.. {194976000 36000 0 AEST}.. {215539200 39600 1 AEDT}.. {226425600 36000 0 AEST}.. {246988800 39600 1 AEDT}.. {257875200 36000 0 AEST}.. {278438400 39600 1 AEDT}.. {28932480
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):180
                                                                                                                                                                                                                                                          Entropy (8bit):4.7511104559982
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2L0GRHEzyeyFNMXGm2OHvavFeVU/VPKVVFSTVF9svUX0VQr:SlSWB9eg/2L0zyfXDm2OHEVy/Ur9s/Vg
                                                                                                                                                                                                                                                          MD5:7A2AD9BD8F8DEE5C600CABF2D5E9D07B
                                                                                                                                                                                                                                                          SHA1:CF5D230A29946B7FA3ECD8EB99F1EF1BF0FA5B50
                                                                                                                                                                                                                                                          SHA-256:ACA533B8BC82296373EDEC82F6E0AA45A34D817C7C18FF5E8E94B81C0BD30259
                                                                                                                                                                                                                                                          SHA-512:95F8FA68735E88AB15C403191928FA4AA5D1628453BE64B87EE7E8DF9F35FB5DA74A3CED5F5289A13D84A8A12BBB86734E578059CA8B6405399CFF5E33C9384C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Mawson) {.. {-9223372036854775808 0 0 -00}.. {-501206400 21600 0 +06}.. {1255809600 18000 0 +05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):195
                                                                                                                                                                                                                                                          Entropy (8bit):4.880387042335617
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3ycqXHAIgObOvRN/2L0z6/fy:MByMdTiYt2LrK
                                                                                                                                                                                                                                                          MD5:88EE32AE5C538AEBFDE2D1D944ED5B2B
                                                                                                                                                                                                                                                          SHA1:55E7234E6FFF298182A6C8889A9F506CDCE7C959
                                                                                                                                                                                                                                                          SHA-256:E9D99293C5B275D8E0D7B066084177EDF670D5B52B81E87608BAB02025F33155
                                                                                                                                                                                                                                                          SHA-512:45A3EA146CA719BA6F22E99EAA57AC1DED1C762E19BDFBA176E5FEAC36EC58586F771572DD16ACE09E660F97DEB91A701BA1B1F1AEF3BD8688F3451C0772420A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Auckland)]} {.. LoadTimeZoneFile Pacific/Auckland..}..set TZData(:Antarctica/McMurdo) $TZData(:Pacific/Auckland)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2613
                                                                                                                                                                                                                                                          Entropy (8bit):3.6082359166067905
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5fzJS6S4wRSenSOaf7HSKSkSqS7STslSmSMSCSxygSiXS/SrS+S9SfShS7SoSlSL:jdeRtnxaf7HlPlgiot7JC/Xk8NWse4rf
                                                                                                                                                                                                                                                          MD5:BDFA5908E735F866FEC16F6B481AD385
                                                                                                                                                                                                                                                          SHA1:524AEE21BB97D923A8812A5722AF2FEA43B4D971
                                                                                                                                                                                                                                                          SHA-256:1637381A20E9D5C6A530F110BDB08D9515E675C9206F000407D8511074948E61
                                                                                                                                                                                                                                                          SHA-512:3D65C7941BA15A698264848F9B6F43ED5B63D4CF86D495334E8E1DC381D63435E9424BBBC389229693D20044FDB8425A7CC805AB5EA055F59D3E0DD4C7AC2A28
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Palmer) {.. {-9223372036854775808 0 0 -00}.. {-157766400 -14400 0 -04}.. {-152654400 -14400 0 -04}.. {-132955200 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-101419200 -10800 1 -04}.. {-86821200 -14400 0 -04}.. {-71092800 -10800 1 -04}.. {-54766800 -14400 0 -04}.. {-39038400 -10800 1 -04}.. {-23317200 -14400 0 -04}.. {-7588800 -10800 0 -03}.. {128142000 -7200 1 -03}.. {136605600 -10800 0 -03}.. {389070000 -14400 0 -04}.. {403070400 -10800 1 -04}.. {416372400 -14400 0 -04}.. {434520000 -10800 1 -04}.. {447822000 -14400 0 -04}.. {466574400 -10800 1 -04}.. {479271600 -14400 0 -04}.. {498024000 -10800 1 -04}.. {510721200 -14400 0 -04}.. {529473600 -10800 1 -04}.. {545194800 -14400 0 -04}.. {560923200 -10800 1 -04}.. {574225200 -14400 0 -04}.. {592372800 -10800 1 -04}.. {605674800 -14400 0 -04}.. {624427200 -10800 1 -04}.. {63712
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):151
                                                                                                                                                                                                                                                          Entropy (8bit):4.829975802206526
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2L0GRHEsKRsMXGm2OHvavFN/H3VVFVGAvFv:SlSWB9eg/2L0rRsDm2OHEN/VVFAKV
                                                                                                                                                                                                                                                          MD5:C330982049AA053DA62B926627D2F2FA
                                                                                                                                                                                                                                                          SHA1:050CE68265F1A183F0173C825AC59EAE8B6AB9EB
                                                                                                                                                                                                                                                          SHA-256:943F10D8E836773F0B7ACD13ED8422C0B27813C7BBE0B09B57697D1D70D21ECE
                                                                                                                                                                                                                                                          SHA-512:DE9953D0E505D6B110C0CC4E756B5B0311646C9CA4703A33B92147D36CFB4C288D73851E6766CE1432F41AB51B5D0A1D58680BDB4E28F067E1D36F670B4A192E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Rothera) {.. {-9223372036854775808 0 0 -00}.. {218246400 -10800 0 -03}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):198
                                                                                                                                                                                                                                                          Entropy (8bit):4.906125935761354
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3ycqXHAIgObOvRN/2L0tlo+ply:MByMdTiYt2LMq+p8
                                                                                                                                                                                                                                                          MD5:8095A3749DBDE05377836D74A4EEFE33
                                                                                                                                                                                                                                                          SHA1:6987CA972B63AE26A65654961588D51D3EF2166C
                                                                                                                                                                                                                                                          SHA-256:88057832175BB642B23FC99F788A2F78A24005CF1F84A7B1B5E8C84FB8F4D4C1
                                                                                                                                                                                                                                                          SHA-512:9066104C9C16D2AB88523D651C74CE268468E093A497D128D0D12A986BD62DBC1388A56ED1737C2AFACF04185CF06FD0EE66797A3390B2F0E1EB08A4D92AAFAD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Auckland)]} {.. LoadTimeZoneFile Pacific/Auckland..}..set TZData(:Antarctica/South_Pole) $TZData(:Pacific/Auckland)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):178
                                                                                                                                                                                                                                                          Entropy (8bit):4.871844665431957
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8t14XHAIgNsM13oOARL/2L0GRHEtWlFBQWFK81Fn:SlSWB9vsM3yN14HAIgaM1YOAN/2L0tQB
                                                                                                                                                                                                                                                          MD5:CA52057130DCF506D11A7CC069F4FBA3
                                                                                                                                                                                                                                                          SHA1:2C38B7E7872BB41C3569DFCB539C3EC3AAE24FDD
                                                                                                                                                                                                                                                          SHA-256:2488805DE4FEA42305689F679F1AE2D80B1E934E657FEA329AD39A82DAC63022
                                                                                                                                                                                                                                                          SHA-512:B19D409870939C8F0834C6C028239E010EE5128DFA6E97D4903BECA229B04FE530EA376B936767D9BFE21709720C1791289D8E3622B17C18F2680B0670794A02
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Riyadh)]} {.. LoadTimeZoneFile Asia/Riyadh..}..set TZData(:Antarctica/Syowa) $TZData(:Asia/Riyadh)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5370
                                                                                                                                                                                                                                                          Entropy (8bit):3.5134546899897146
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:YveRdmbxnKIJqU9XThVIsopb8BcrFgoZVlzeEG+PtJ:UeRdmNnKIIajfopb3FVVJ
                                                                                                                                                                                                                                                          MD5:442F495C36B31CA5D7A9BEFF12105AEF
                                                                                                                                                                                                                                                          SHA1:B3F6CA5B4A5756F9B2C09A27198F7A651CC6032D
                                                                                                                                                                                                                                                          SHA-256:6FD5AB8B7B308CDCEA4B747A81D8675988AE218813C91714FC4CA97919CEBEA5
                                                                                                                                                                                                                                                          SHA-512:C6EAECC26D67D218615EBB5602639DAB62A2578BD9683553D765DC1AC5580627D29B6F911388F5F1BFC284278EA4EBECE94630D3C6B95FF9EF93D3D61A3C2028
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Troll) {.. {-9223372036854775808 0 0 -00}.. {1108166400 0 0 +00}.. {1111885200 7200 1 +02}.. {1130634000 0 0 +00}.. {1143334800 7200 1 +02}.. {1162083600 0 0 +00}.. {1174784400 7200 1 +02}.. {1193533200 0 0 +00}.. {1206838800 7200 1 +02}.. {1224982800 0 0 +00}.. {1238288400 7200 1 +02}.. {1256432400 0 0 +00}.. {1269738000 7200 1 +02}.. {1288486800 0 0 +00}.. {1301187600 7200 1 +02}.. {1319936400 0 0 +00}.. {1332637200 7200 1 +02}.. {1351386000 0 0 +00}.. {1364691600 7200 1 +02}.. {1382835600 0 0 +00}.. {1396141200 7200 1 +02}.. {1414285200 0 0 +00}.. {1427590800 7200 1 +02}.. {1445734800 0 0 +00}.. {1459040400 7200 1 +02}.. {1477789200 0 0 +00}.. {1490490000 7200 1 +02}.. {1509238800 0 0 +00}.. {1521939600 7200 1 +02}.. {1540688400 0 0 +00}.. {1553994000 7200 1 +02}.. {1572138000 0 0 +00}.. {1585443600 7200 1 +02}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):234
                                                                                                                                                                                                                                                          Entropy (8bit):4.519920980071167
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2L0XcMFPDm2OHEsVFXC/MVSYyF/3jaRzMVSYyF/yFZ/VQVV:MB862LEcEbmdHEsVFZsF/OR4sF/Cx6r
                                                                                                                                                                                                                                                          MD5:4266896558FEF8B0D95D887C8521C381
                                                                                                                                                                                                                                                          SHA1:104E3B69CD5EC870C419F3DC92F6060CF548B4B0
                                                                                                                                                                                                                                                          SHA-256:08D7BA1193B13481DE933A5BA747F1129B66DCDE7867E5F9EB6E5BA72F1143EF
                                                                                                                                                                                                                                                          SHA-512:A4AD3B1D7D23774B6313E945CCB30EA1EF252414BD5E4CB7DCA292FE665FE08403F59B677644DA2BE58AEA41C56A4279336B516B62974F33AC17E702328FDD8C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Vostok) {.. {-9223372036854775808 0 0 -00}.. {-380073600 25200 0 +07}.. {760035600 0 0 -00}.. {783648000 25200 0 +07}.. {1702839600 18000 0 +05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):187
                                                                                                                                                                                                                                                          Entropy (8bit):4.947168975083595
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/y+YF3vXHAIgoq8yFRRL/2XbeLo4cA4FH/h8QahV:SlSWB9vsM3ymhVoPHAIgoh6N/2XbUyAH
                                                                                                                                                                                                                                                          MD5:A4F076D7D716467B78EA382FA222CB38
                                                                                                                                                                                                                                                          SHA1:21D7FBA308ADC652F541A0336929B862F7B1BD0B
                                                                                                                                                                                                                                                          SHA-256:25462B656D240DA6B01C1A630FAC04B25DD65C799B659BE1C8BD3AB62610966F
                                                                                                                                                                                                                                                          SHA-512:1B6BD455E533D5BDC7F3506561A9CA804B1F9CA5CC0665AAB0FC083106AB32FF149DD5FFF62EF7BABAD87E3274F264446D492FB8BE160C9C7F281C7060BF1F61
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Arctic/Longyearbyen) $TZData(:Europe/Berlin)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):171
                                                                                                                                                                                                                                                          Entropy (8bit):4.829666491766117
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8t14XHAIgNsM13oOARL/2WFK4h4WFK81Fn:SlSWB9vsM3yN14HAIgaM1YOAN/2wKs46
                                                                                                                                                                                                                                                          MD5:60D7F3194F19179E0CF0F561F9C40EE6
                                                                                                                                                                                                                                                          SHA1:B079EC49485CFBFFB7A5BE6149319B75684258E9
                                                                                                                                                                                                                                                          SHA-256:8FCDDB246932BAED880B70C0CA867057E7989AEA55EDDC174430E1055CD1058D
                                                                                                                                                                                                                                                          SHA-512:0BDC86B1D473D4875C6F7C092F955D0999E6C1F2EF83CFC7726A3C5BFEB0F5CB8E00B1F0CBC1F91F806EC635C472927504DF681A32DAC55EF372DA16FEA9EF40
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Riyadh)]} {.. LoadTimeZoneFile Asia/Riyadh..}..set TZData(:Asia/Aden) $TZData(:Asia/Riyadh)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1667
                                                                                                                                                                                                                                                          Entropy (8bit):3.727394465632045
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5qehddmvOt81FCuLqecDngO6jPvTpYy5T4TXvKT10SvPFu+a+CK/Eu3CWuD0VobJ:5YvdJqxiF0rvK50Sv9fGS8r
                                                                                                                                                                                                                                                          MD5:E6DE3AE4C3662697E2BA887090E559D4
                                                                                                                                                                                                                                                          SHA1:2EF20F4001BE922598A6EB889A2F6B51DA148B32
                                                                                                                                                                                                                                                          SHA-256:DF50667B065C9E7C37C384D65ACA67D8FD171095187EEE83D0CC470540A291C0
                                                                                                                                                                                                                                                          SHA-512:707CF114E1A95328A4C78F7EBD7567566F8BE6E2114D9014339A2CC1D299359BBFDF5FF47C9644D8D7AE283C818204EE363A1F728ABCB24716F9EA98A8E86922
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Almaty) {.. {-9223372036854775808 18468 0 LMT}.. {-1441170468 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 18000 0 +05}.. {670366800 21600 1 +05}.. {686091600 18000 0 +05}.. {695768400 21600 0 +06}.. {701812800 25200 1 +06}.. {717537600 21600 0 +06}.. {733262400 25200 1 +06}.. {748987200 21600 0 +06}.. {764712
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2682
                                                                                                                                                                                                                                                          Entropy (8bit):3.7873260611521915
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5MUNHl0Nhb9bGA9jSb0PWtsjOuH7Ay2n3yy7QYoTZg703q4oPuJ9/YXjpdaOP9kA:Fz0T52akyId7+xOXdkwqeIFcR
                                                                                                                                                                                                                                                          MD5:7E70BD44FBF5BF70E3C5246D3A83A49B
                                                                                                                                                                                                                                                          SHA1:10A28B0A3189DF347CF9853C024E9467CAC56DBA
                                                                                                                                                                                                                                                          SHA-256:B70AABECACD3F62AF506DF395AB44F47F2CA091522B04EC87AC1407172DD1BFA
                                                                                                                                                                                                                                                          SHA-512:766565F837EB777749B2C8AAE6C73A2274A772CEF12E7C2E30A89809FEF1E9ED6B067DF044A4676AA4BE76A64A904692C3887336BF01BA4D5D9A5020FB792938
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Amman) {.. {-9223372036854775808 8624 0 LMT}.. {-1230776624 7200 0 EET}.. {108165600 10800 1 EEST}.. {118270800 7200 0 EET}.. {136591200 10800 1 EEST}.. {149806800 7200 0 EET}.. {168127200 10800 1 EEST}.. {181342800 7200 0 EET}.. {199749600 10800 1 EEST}.. {215643600 7200 0 EET}.. {231285600 10800 1 EEST}.. {244501200 7200 0 EET}.. {262735200 10800 1 EEST}.. {275950800 7200 0 EET}.. {481154400 10800 1 EEST}.. {496962000 7200 0 EET}.. {512949600 10800 1 EEST}.. {528670800 7200 0 EET}.. {544399200 10800 1 EEST}.. {560120400 7200 0 EET}.. {575848800 10800 1 EEST}.. {592174800 7200 0 EET}.. {610581600 10800 1 EEST}.. {623624400 7200 0 EET}.. {641167200 10800 1 EEST}.. {655074000 7200 0 EET}.. {671839200 10800 1 EEST}.. {685918800 7200 0 EET}.. {702856800 10800 1 EEST}.. {717973200 7200 0 EET}.. {733701600 10800 1 EEST}.. {749422800
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2086
                                                                                                                                                                                                                                                          Entropy (8bit):3.7698340044911616
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5DeEdVrEOeFt7YFpR2kHmxCcUdBbcHDLV2vpXt25A0UeRr9ydzkMfF6USRWk9UuV:5ZejsFLrcZwvJt2F+doTr9Q3G80
                                                                                                                                                                                                                                                          MD5:6EFC35043BDCA4AB61D72E931DB954E6
                                                                                                                                                                                                                                                          SHA1:F0B4E76C154DC773073E41AA8E94030E972A986A
                                                                                                                                                                                                                                                          SHA-256:D9DF64FDA4638F7604624B0F68A885D5ABADB1DE12AF1AF5581C2AF7DD971562
                                                                                                                                                                                                                                                          SHA-512:16AE582B113D6960C73B64620A8AF20F9D436AA4B3EC8E881617AED3389EB4357931882103F162F19EE8202953A7E6FB4FDD6D7760FB7621F4DB9D229AD13F17
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Anadyr) {.. {-9223372036854775808 42596 0 LMT}.. {-1441194596 43200 0 +12}.. {-1247572800 46800 0 +14}.. {354884400 50400 1 +14}.. {370692000 46800 0 +13}.. {386420400 43200 0 +13}.. {386424000 46800 1 +13}.. {402231600 43200 0 +12}.. {417960000 46800 1 +13}.. {433767600 43200 0 +12}.. {449582400 46800 1 +13}.. {465314400 43200 0 +12}.. {481039200 46800 1 +13}.. {496764000 43200 0 +12}.. {512488800 46800 1 +13}.. {528213600 43200 0 +12}.. {543938400 46800 1 +13}.. {559663200 43200 0 +12}.. {575388000 46800 1 +13}.. {591112800 43200 0 +12}.. {606837600 46800 1 +13}.. {622562400 43200 0 +12}.. {638287200 46800 1 +13}.. {654616800 43200 0 +12}.. {670341600 39600 0 +12}.. {670345200 43200 1 +12}.. {686070000 39600 0 +11}.. {695746800 43200 0 +13}.. {701791200 46800 1 +13}.. {717516000 43200 0 +12}.. {733240800 46800 1 +13}.. {748965
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1665
                                                                                                                                                                                                                                                          Entropy (8bit):3.7149890651919644
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5uvFlvNhQQvmRKqv0fvzQIovWdvEGvDaDvs5vZlovKWyvNSvTqvIkhYwr:sFBNKs6b03zB0WJEuDa7sFZiKWaN6TiF
                                                                                                                                                                                                                                                          MD5:A72FB1FE01C93BD7E0A8136635C72639
                                                                                                                                                                                                                                                          SHA1:2383CF839F50784D4BF8B7EDDB324C80E2DDD0DC
                                                                                                                                                                                                                                                          SHA-256:96B510AF9B8C6BC1DFA84E9ED5E072F3FD484EEB66BBEBC7B6826ED859ED9027
                                                                                                                                                                                                                                                          SHA-512:061FECE3C750C0229638DD8AF38FB3E8E48E59E0DE1B13BCFE46483A7A170B71B9BCB0D6F110B6B2EF68510FA940F9066F14CBD59829E222D6644D3657CE1893
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Aqtau) {.. {-9223372036854775808 12064 0 LMT}.. {-1441164064 14400 0 +04}.. {-1247544000 18000 0 +05}.. {370724400 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990800 18000 0 +05}.. {7647156
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1666
                                                                                                                                                                                                                                                          Entropy (8bit):3.721746335201775
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5FUvalvNhQQvmRKqv0fvzQIovWdvEGvDaDvs5vZlovKWyvNSvTqvIQvyovklvqQR:PwaBNKs6b03zB0WJEuDa7sFZiKWaN6Tt
                                                                                                                                                                                                                                                          MD5:E278B985BD2515DBCAED8CB741BE9208
                                                                                                                                                                                                                                                          SHA1:BC9F5E72C430661D7ED1AF04571CE5D0F73DD18D
                                                                                                                                                                                                                                                          SHA-256:991638FA2AB2A2F7A091A23D78D99306EE73A740F1A03FBAC448EDCAB55A0E38
                                                                                                                                                                                                                                                          SHA-512:9951DB729B837647CC4B3D2E605525DCCBAFFD39D76460331BF62235DCAE5E4470CDA578F940B1739AABFEC55D293FF60D79AE0EFDFE1EB64E84571881FDEA6A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Aqtobe) {.. {-9223372036854775808 13720 0 LMT}.. {-1441165720 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):878
                                                                                                                                                                                                                                                          Entropy (8bit):3.937249024843323
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5ggeRMdIQvNcDvNhQQvmRKqvzQfv7PQIovWxrvEGvDWdDvs5v/RlovKTob3CGcr:5gbkvNSvNhQQvmRKqv0fvzQIovWdvEGD
                                                                                                                                                                                                                                                          MD5:259179C7A1CA04F9F3A373B6C8FCB8C5
                                                                                                                                                                                                                                                          SHA1:D042DF8EFD8EC1473B45B1131BD5EB714F1B2C17
                                                                                                                                                                                                                                                          SHA-256:13745BFA25E6E2D8D0FABAE42CB7C37CF9F974CFB343D4FE84E4E2D64A25926B
                                                                                                                                                                                                                                                          SHA-512:703BEAD5A1E5B3816D98057A08A87C2139F418787F38561FE35175B84E2005365727F85D1B949CC5DF464B207A7D01BB65FB1A632E73DDA523E843B82D76FBBD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ashgabat) {.. {-9223372036854775808 14012 0 LMT}.. {-1441166012 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +05}.. {370720800 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):182
                                                                                                                                                                                                                                                          Entropy (8bit):4.801820439218014
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8xEYM4DyXHAIgN/ZEYovFvWARL/2WFKUNSH+WFKYEQ:SlSWB9vsM3yR+HAIgH8VWAN/2wKUNSeq
                                                                                                                                                                                                                                                          MD5:5193EF7ADB646798801245BC50C8DDA6
                                                                                                                                                                                                                                                          SHA1:83ED851CBC60EFB330A8FC119E1BED5B4C0BA630
                                                                                                                                                                                                                                                          SHA-256:2C752F641B98E3C05B14AE31330D1F198DAA4A7E354BA9670C7754926BFB891A
                                                                                                                                                                                                                                                          SHA-512:E940E1BE67A9AC895F3D060B1CB34797A429147A9DC2AC0F1162D37D86661EF217EDABA720F0AE3796186FE801229210AC785BB4511CBBE5A41791D236101D8C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Ashgabat)]} {.. LoadTimeZoneFile Asia/Ashgabat..}..set TZData(:Asia/Ashkhabad) $TZData(:Asia/Ashgabat)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1666
                                                                                                                                                                                                                                                          Entropy (8bit):3.7265766742957402
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:55TvFlvNhQQvmRKqv0fvzQIovWdvEGvDaDvs5vZlovKWyvNSvTqvIQvyovklvqQJ:XrFBNKs6b03zB0WJEuDa7sFZiKWaN6Tl
                                                                                                                                                                                                                                                          MD5:0236793F90ABC6F68718DDBB44AF5E2F
                                                                                                                                                                                                                                                          SHA1:A5EFAEEF9B9159E748A3FED231F8A978E400482E
                                                                                                                                                                                                                                                          SHA-256:4B7B118E6AE72D41740CF0CB2BD8E970700758DCBC0DD6F298199D841DF8408E
                                                                                                                                                                                                                                                          SHA-512:851C7A9C110790454312BB9C5B5D3C426365EEF4673191B9ABB2E4A32301894C5FB1ADCBE2A4C67BEE416AD63FB8BED85F94EF9BF42473DA4BFFA7824935A1D5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Atyrau) {.. {-9223372036854775808 12464 0 LMT}.. {-1441164464 10800 0 +03}.. {-1247540400 18000 0 +05}.. {370724400 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990800 18000 0 +05}.. {764715
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1702
                                                                                                                                                                                                                                                          Entropy (8bit):3.7261419515679393
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5/eVvyGiHD6UC4UrUomFMmUZcjbUKNFcUEUvUOpU8MYUWCUlbf/U9bUiUUybUQUF:5m8G9mFdnNF1FfsTuvQXHCe
                                                                                                                                                                                                                                                          MD5:690013310A46BD1AE250A5E019353809
                                                                                                                                                                                                                                                          SHA1:0DF434C7EEB707DC071007FAB112F4DEB37E936F
                                                                                                                                                                                                                                                          SHA-256:D20B75D2604C3B742C1629C5EE02CFF6783E472249982B272B68F2A6DE9BDC38
                                                                                                                                                                                                                                                          SHA-512:FF8C33E55E4F006C38D3FD37A1AD3E1200718CA374ECBEAE8255C7635912F0BB23A59A600BF7130D5660A24C515F726E8440D0D908E560CB59F74059638E6AA2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Baghdad) {.. {-9223372036854775808 10660 0 LMT}.. {-2524532260 10656 0 BMT}.. {-1641005856 10800 0 +03}.. {389048400 14400 0 +03}.. {402264000 10800 0 +03}.. {417906000 14400 1 +03}.. {433800000 10800 0 +03}.. {449614800 14400 1 +03}.. {465422400 10800 0 +03}.. {481150800 14400 1 +03}.. {496792800 10800 0 +03}.. {512517600 14400 1 +03}.. {528242400 10800 0 +03}.. {543967200 14400 1 +03}.. {559692000 10800 0 +03}.. {575416800 14400 1 +03}.. {591141600 10800 0 +03}.. {606866400 14400 1 +03}.. {622591200 10800 0 +03}.. {638316000 14400 1 +03}.. {654645600 10800 0 +03}.. {670464000 14400 1 +03}.. {686275200 10800 0 +03}.. {702086400 14400 1 +03}.. {717897600 10800 0 +03}.. {733622400 14400 1 +03}.. {749433600 10800 0 +03}.. {765158400 14400 1 +03}.. {780969600 10800 0 +03}.. {796694400 14400 1 +03}.. {812505600 10800 0 +03}.. {82831
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):171
                                                                                                                                                                                                                                                          Entropy (8bit):4.784355129067593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8hkXHAIgNvZORL/2WFKENUKMFB/4WFKKB:SlSWB9vsM3yBkHAIgPON/2wKENUr/4wT
                                                                                                                                                                                                                                                          MD5:1B5E0D449DAEF469D586A853CB3073AD
                                                                                                                                                                                                                                                          SHA1:FD735B0472B31644E787767B82B737CC39EC4175
                                                                                                                                                                                                                                                          SHA-256:3D437037FBF2BBDF969C8E71967080947F24860D431B39F5D8F23151316ABCD5
                                                                                                                                                                                                                                                          SHA-512:2A2DC33D4258A5E1AE59172883F3B11723798ED35CF5AF1B8BA81A8807DC6F8222C8044D82B152EF6AF43E7350FEB2625D4406C6C7DD309CE65810EA3D3286B6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Qatar)]} {.. LoadTimeZoneFile Asia/Qatar..}..set TZData(:Asia/Bahrain) $TZData(:Asia/Qatar)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2149
                                                                                                                                                                                                                                                          Entropy (8bit):3.6155622322573713
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5/eFdqlykbocXcwJUE5iu8JmFebARoc9lVNk7/9bq8dq16b3C9UPBUTIEjvZJ+76:5RsUf8mFpNWFny1ZGMte3aivUKo
                                                                                                                                                                                                                                                          MD5:294DFC98F67AC00A188EC3D3B87C501C
                                                                                                                                                                                                                                                          SHA1:93C434CD9AA170E35AD676C88EE09986A94EC02A
                                                                                                                                                                                                                                                          SHA-256:873E8F08B87610D0DAFE239D32345248A4595C6B13D1DA83EC214D78E88FA12C
                                                                                                                                                                                                                                                          SHA-512:5346082CCA733724C0D2C36B768467E59BA9ED6452B6CF1BA923AF4F0D2BC05C67DB49E804CA81DAD449D30D0835026D708D9AB632D02FDA1EA1A0BF717111DE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Baku) {.. {-9223372036854775808 11964 0 LMT}.. {-1441163964 10800 0 +03}.. {-405140400 14400 0 +04}.. {354916800 18000 1 +04}.. {370724400 14400 0 +04}.. {386452800 18000 1 +04}.. {402260400 14400 0 +04}.. {417988800 18000 1 +04}.. {433796400 14400 0 +04}.. {449611200 18000 1 +04}.. {465343200 14400 0 +04}.. {481068000 18000 1 +04}.. {496792800 14400 0 +04}.. {512517600 18000 1 +04}.. {528242400 14400 0 +04}.. {543967200 18000 1 +04}.. {559692000 14400 0 +04}.. {575416800 18000 1 +04}.. {591141600 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 10800 0 +03}.. {670374000 14400 1 +03}.. {686098800 10800 0 +03}.. {701823600 14400 1 +03}.. {717548400 14400 0 +04}.. {820440000 14400 0 +04}.. {828234000 18000 1 +05}.. {846378000 14400 0 +04}.. {852062400
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):181
                                                                                                                                                                                                                                                          Entropy (8bit):4.911309754748998
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2WFKELYOiMXGm2OHB+keoHvZKmrROpDovFFsQ+8EXVeVSYe:SlSWB9eg/2wKELeDm2OHxeoHvZ3FO1og
                                                                                                                                                                                                                                                          MD5:9AC4947AC29C797055B7EBFA4F6AC710
                                                                                                                                                                                                                                                          SHA1:E7758A9A8BFA255F6B2D27F5366D9FE2A26DDF6C
                                                                                                                                                                                                                                                          SHA-256:6E72BA908F250FD45D554A12E3E7B3BD2F1C02A6C2431F806FD2A054F843AA90
                                                                                                                                                                                                                                                          SHA-512:F9D0F0CB7D3726C2AB3B5049429172D9DD4BA21353F6F98570CBA4EE969F7D97BD973CB165AECFF930AFFA8633E8052624D44EE7FB91763681ED3F78A61F4F98
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Bangkok) {.. {-9223372036854775808 24124 0 LMT}.. {-2840164924 24124 0 BMT}.. {-1570084924 25200 0 +07}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2117
                                                                                                                                                                                                                                                          Entropy (8bit):3.7025684250364725
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5VeTtXJfsFN/3sFrOksF/sF7IyksF7FRZsFLsFTsFcsFk73sFK/XCFKTipnFEnsr:5n40yVRB7VfXucdKmtTTDOV
                                                                                                                                                                                                                                                          MD5:6CC13B6910412A3A3D16CA36ADF00352
                                                                                                                                                                                                                                                          SHA1:061CF4A8FEA8C139F50F96E6B6506B50ED3DD792
                                                                                                                                                                                                                                                          SHA-256:992F93A7975F8CD4E94D96B3BA1ECFB3585E52A53F4442A15993402D3F955F66
                                                                                                                                                                                                                                                          SHA-512:4E9750B1C3C0BA4F7922BCBC76276A3E74031D78A98E21DC59F66D6EA8E1B70865BBEB50A6B77EB0423421A18428B97B47412053CE15213128CEED669F4DD6E8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Barnaul) {.. {-9223372036854775808 20100 0 LMT}.. {-1579844100 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {76470
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8024
                                                                                                                                                                                                                                                          Entropy (8bit):3.7230911686481774
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:4nBKPP8LFH0TDkywaZb1QSCK5VUjiO1PoBQpo7778CZicJZS80EGcLt4Mok1MgJl:4M38LCRZb+sAiO1PoBQpo1ikjD
                                                                                                                                                                                                                                                          MD5:1D99E2BBB01B1669403CFBAF7E03F733
                                                                                                                                                                                                                                                          SHA1:DBDD58C7FD195FC602C4541D6F416CC96094C121
                                                                                                                                                                                                                                                          SHA-256:17AF14646D562AFE17DCCFD1D2FBA95C122F3E0263906A36EB48BFF04ACF233E
                                                                                                                                                                                                                                                          SHA-512:98524E8DCD17C090058F17BDA1200D9801EB1B14EB5CEB8C31149A4A402A53BA4923A2AFF457E0A72DAA601D88095247806F945F704000F874FCBF73631DD135
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Beirut) {.. {-9223372036854775808 8520 0 LMT}.. {-2840149320 7200 0 EET}.. {-1570413600 10800 1 EEST}.. {-1552186800 7200 0 EET}.. {-1538359200 10800 1 EEST}.. {-1522551600 7200 0 EET}.. {-1507514400 10800 1 EEST}.. {-1490583600 7200 0 EET}.. {-1473645600 10800 1 EEST}.. {-1460948400 7200 0 EET}.. {-399866400 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336794400 10800 1 EEST}.. {-323578800 7200 0 EET}.. {-305172000 10800 1 EEST}.. {-291956400 7200 0 EET}.. {-273636000 10800 1 EEST}.. {-260420400 7200 0 EET}.. {78012000 10800 1 EEST}.. {86734800 7200 0 EET}.. {105055200 10800 1 EEST}.. {118270800 7200 0 EET}.. {136591200 10800 1 EEST}.. {149806800 7200 0 EET}.. {168127200 10800 1 EEST}.. {181342800 7200 0 EET}.. {199749600 10800 1 EEST}.. {212965200 7200 0 EET}.. {231285600 10800
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1669
                                                                                                                                                                                                                                                          Entropy (8bit):3.7443715330695735
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5qvdJqxiF0rvK5XvV4vUzvCjvT7voPvkPvJUbvn0vYpv99v3uvuWvKJhv3T:Ad1mzK5/VkULCbTjoHkHJUDnQYV9p3mO
                                                                                                                                                                                                                                                          MD5:1EE8FF3DF0D931A140ADBB021EB3BFEB
                                                                                                                                                                                                                                                          SHA1:F1F15EF70C4E9F456849AF89CAC97AD747D9E192
                                                                                                                                                                                                                                                          SHA-256:1D5E9A8F6A04273AF741F648EF10718B004A60D7884FE432DDF85A8F558BEA98
                                                                                                                                                                                                                                                          SHA-512:155539A5CF21A34FBFACBF1652D934BF32255F4E505E60B3B4D8B5F2F7FAE552E6CB4824D8608A9C56370F58E48702335995BBD16B7A296A86A72A615FBC8ABC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Bishkek) {.. {-9223372036854775808 17904 0 LMT}.. {-1441169904 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 18000 0 +05}.. {670366800 21600 1 +05}.. {683586000 18000 0 +05}.. {703018800 21600 1 +05}.. {717530400 18000 0 +05}.. {734468400 21600 1 +05}.. {748980000 18000 0 +05}.. {765918000 21600 1 +05}.. {78042
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):176
                                                                                                                                                                                                                                                          Entropy (8bit):4.949517569857329
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8kLP/vXHAIgN16L1RL/2WFKXeAMM7QWFKPLPyn:SlSWB9vsM3yELPHAIg+L1N/2wK0oQwKW
                                                                                                                                                                                                                                                          MD5:716D842F23974137C5E07A1A65CEFC5D
                                                                                                                                                                                                                                                          SHA1:C7248C9DBD6AE5AF33BD4B3602D17737EBE023A0
                                                                                                                                                                                                                                                          SHA-256:F3110E9DD514E3654A9DE777E22B2D2391692927954B4B7E42ED54AB665C3CF5
                                                                                                                                                                                                                                                          SHA-512:4EC012EAABE60728D9447EEDF4BA7B16CA82786AA39EE79B2F9B32F227F9816FCE42F173153261F9AF88A12209752E84EBD7170C54D126C2DBB1ED3A8D069668
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Kuching)]} {.. LoadTimeZoneFile Asia/Kuching..}..set TZData(:Asia/Brunei) $TZData(:Asia/Kuching)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):178
                                                                                                                                                                                                                                                          Entropy (8bit):4.774027471796823
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq864DyXHAIgN1QvRL/2WFKh0s+WFKvovn:SlSWB9vsM3ya4DSHAIgcvN/2wKN+wKvy
                                                                                                                                                                                                                                                          MD5:8BB098AB77CB0469B1FA0E0B64C4A9E7
                                                                                                                                                                                                                                                          SHA1:88C73626985071DD0923E1CAB343ACCD854A7297
                                                                                                                                                                                                                                                          SHA-256:1BAEF7850111D2C33B2A766A8AE804534ABA1711BF80A4087A89656DDD8469D5
                                                                                                                                                                                                                                                          SHA-512:82216A7F787AF20A4C97C7AA754CD6BE979FEF24137CF9A8B18EECA5E8FBCF12834DD8A6FC9CD2357D807F1629806745B46B11DC0472E0284E18DCCC983897DE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Kolkata)]} {.. LoadTimeZoneFile Asia/Kolkata..}..set TZData(:Asia/Calcutta) $TZData(:Asia/Kolkata)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2086
                                                                                                                                                                                                                                                          Entropy (8bit):3.6981807774781017
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5Bpr1gIgWH/lt0irzEzCSCItWiIrW+rDQk9CVhyFY7rRWjYuhUmgr2M:95PhtjLiII2ZFlgd
                                                                                                                                                                                                                                                          MD5:69E03A5CEB689E19B60168C0F7EBAE8E
                                                                                                                                                                                                                                                          SHA1:95C6396EB753753B4FE4AE1B98D76332523E72A4
                                                                                                                                                                                                                                                          SHA-256:10B6F435B05D887176A4D90CA5AC957F327F62F36F15D6F6E4F81844662429B9
                                                                                                                                                                                                                                                          SHA-512:DFA72EDC54A11F0840ADBEE7F5AD8EA472AA52A1F196292F1341CD92A68FB2EC0A5BC7DE6C8E83C975420DB4B76CECD4393370FDB2C09F86EC11A50E540F6F02
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Chita) {.. {-9223372036854775808 27232 0 LMT}.. {-1579419232 28800 0 +08}.. {-1247558400 32400 0 +10}.. {354898800 36000 1 +10}.. {370706400 32400 0 +09}.. {386434800 36000 1 +10}.. {402242400 32400 0 +09}.. {417970800 36000 1 +10}.. {433778400 32400 0 +09}.. {449593200 36000 1 +10}.. {465325200 32400 0 +09}.. {481050000 36000 1 +10}.. {496774800 32400 0 +09}.. {512499600 36000 1 +10}.. {528224400 32400 0 +09}.. {543949200 36000 1 +10}.. {559674000 32400 0 +09}.. {575398800 36000 1 +10}.. {591123600 32400 0 +09}.. {606848400 36000 1 +10}.. {622573200 32400 0 +09}.. {638298000 36000 1 +10}.. {654627600 32400 0 +09}.. {670352400 28800 0 +09}.. {670356000 32400 1 +09}.. {686080800 28800 0 +08}.. {695757600 32400 0 +10}.. {701802000 36000 1 +10}.. {717526800 32400 0 +09}.. {733251600 36000 1 +10}.. {748976400 32400 0 +09}.. {7647012
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1619
                                                                                                                                                                                                                                                          Entropy (8bit):3.775783980828041
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5th5fSW2sp4Qh2rRSQnGw7GywvWbC25XrMYWG4AIQTUhp9pkTGdXguHaena44XY5:rh5kpmWG29QFUmD
                                                                                                                                                                                                                                                          MD5:540A7304A62ABB8D7F84454ABD6E2556
                                                                                                                                                                                                                                                          SHA1:52C37529929218A668D7A4AD6FD1B5FE0A727E16
                                                                                                                                                                                                                                                          SHA-256:94B2C14EF45C695EF6B19D94722E1BCBB629A595F2866DBA80F00A66721040B5
                                                                                                                                                                                                                                                          SHA-512:3B535D109DB369E301D6B412F21EC990976B997826F22B2E16ECEEEB048D60F064C7CA1A616393DC2F1B491BAC0548DC0965B9EA149A95280FFDBCAD6726EF0F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Choibalsan) {.. {-9223372036854775808 27480 0 LMT}.. {-2032933080 25200 0 +07}.. {252435600 28800 0 +08}.. {417974400 36000 0 +09}.. {433778400 32400 0 +09}.. {449593200 36000 1 +09}.. {465314400 32400 0 +09}.. {481042800 36000 1 +09}.. {496764000 32400 0 +09}.. {512492400 36000 1 +09}.. {528213600 32400 0 +09}.. {543942000 36000 1 +09}.. {559663200 32400 0 +09}.. {575391600 36000 1 +09}.. {591112800 32400 0 +09}.. {606841200 36000 1 +09}.. {622562400 32400 0 +09}.. {638290800 36000 1 +09}.. {654616800 32400 0 +09}.. {670345200 36000 1 +09}.. {686066400 32400 0 +09}.. {701794800 36000 1 +09}.. {717516000 32400 0 +09}.. {733244400 36000 1 +09}.. {748965600 32400 0 +09}.. {764694000 36000 1 +09}.. {780415200 32400 0 +09}.. {796143600 36000 1 +09}.. {811864800 32400 0 +09}.. {828198000 36000 1 +09}.. {843919200 32400 0 +09}.. {8596
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):182
                                                                                                                                                                                                                                                          Entropy (8bit):4.865222436335267
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8qvfXHAIgNtaYFARL/2WFKh2V7/4WFKdy:SlSWB9vsM3yMPHAIgO8AN/2wKho4wKU
                                                                                                                                                                                                                                                          MD5:C5DC40C6325391F7247251ADB2C07F78
                                                                                                                                                                                                                                                          SHA1:3DDB1BF94532FB1F1271095B9C8CAA779BC545EF
                                                                                                                                                                                                                                                          SHA-256:A87382DC5F3C3141547A65E3746AF1DAF94B51468B96DA6CEF30E95754C97D37
                                                                                                                                                                                                                                                          SHA-512:062FF8D5E5392E5372B0405EDF3C7CF997AC33F95EBFFAA9CC9AB82BBE27B60C80255FCCEE9E6F5E02CBFCB163F99984BB2103217FFD1F80BDEC5C684BF2F61A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:Asia/Chongqing) $TZData(:Asia/Shanghai)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):182
                                                                                                                                                                                                                                                          Entropy (8bit):4.889115378893491
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8qvfXHAIgNtaYFARL/2WFK7LeL9J4WFKdy:SlSWB9vsM3yMPHAIgO8AN/2wK7LUT4wj
                                                                                                                                                                                                                                                          MD5:C3676771EB813B346F58A7B574D0D7B5
                                                                                                                                                                                                                                                          SHA1:A473EF621309E019F29F3DEF95C38593775B8404
                                                                                                                                                                                                                                                          SHA-256:D6D2B4A761C547F1F853AE901AC71AB49FBE825037079C4E0C89DC940AE4A822
                                                                                                                                                                                                                                                          SHA-512:21C3A5D499E6E0427FBF585CA8CC5D99D193C586483AB107C4D8E9F9DC8412021E8E019A314757DAFE1225D2635F6D48E9C54A511709863F22A02449FA201E02
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:Asia/Chungking) $TZData(:Asia/Shanghai)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):369
                                                                                                                                                                                                                                                          Entropy (8bit):4.465596050904646
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wKr+iDm2OHgoHvZv9tdvjSWV/FSQipPUrKkTD/k5QqRVVFSQOR/UIp:MB862zZmdHgCvZvJvj1Nj+Phkv/YtvjA
                                                                                                                                                                                                                                                          MD5:9541BB43E79AB0C6E8163945B5BFB1BF
                                                                                                                                                                                                                                                          SHA1:C4994420DB8313DECDE19B4B9F6C5DB0126A95A7
                                                                                                                                                                                                                                                          SHA-256:E5B5E6D607A15DA65CB00C92C35A63EAF25F547E64CB34BB419CB8CFC2714B1B
                                                                                                                                                                                                                                                          SHA-512:46F623B3F7CF8A50F97DD812521398EB9100C9CDFB967C18EF1BD112306AAEB3C9CB224424E48611CB8CC21D1DC3D820DD83032D12BC9DF19301CF07786FA664
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Colombo) {.. {-9223372036854775808 19164 0 LMT}.. {-2840159964 19172 0 MMT}.. {-2019705572 19800 0 +0530}.. {-883287000 21600 1 +06}.. {-862639200 23400 1 +0630}.. {-764051400 19800 0 +0530}.. {832962600 23400 0 +0630}.. {846266400 21600 0 +06}.. {1145039400 19800 0 +0530}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):169
                                                                                                                                                                                                                                                          Entropy (8bit):4.786111096226559
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8ntyXHAIgN6KyFvRL/2WFK1S2WFKwBn:SlSWB9vsM3yHtSHAIgMKON/2wKM2wKwB
                                                                                                                                                                                                                                                          MD5:BA575D37459540907A644438071277F8
                                                                                                                                                                                                                                                          SHA1:14CF10D6AABBAF7BAE42B3B9641D8469C206567F
                                                                                                                                                                                                                                                          SHA-256:B3AD560F66EA330E54A147017E6E6AB64452A5255D097B962D540836D7B19EE7
                                                                                                                                                                                                                                                          SHA-512:9CA386EF4D812B00C2E63558B81B273F92BBCA98AF304C9FD6FC166210FC4E2F92B769E1D6FB96B670650DC76EFFAD2FC6E39AE12C24B47EAED4E50A2AFAC2D7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dhaka)]} {.. LoadTimeZoneFile Asia/Dhaka..}..set TZData(:Asia/Dacca) $TZData(:Asia/Dhaka)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3692
                                                                                                                                                                                                                                                          Entropy (8bit):3.7832279883701254
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:59xu6+RYla5W87rtYV08a7bd+dYV004X7JkX3Q0dzPeP2ua/XAog7jP/xZsNaTvT:8YI5WpVAdVGlkBOLh8X0CkBheIFlR
                                                                                                                                                                                                                                                          MD5:1D6B2CC38669C0F7378D9A576F10C477
                                                                                                                                                                                                                                                          SHA1:09A31E6295D9FC39219DFA4FC598B46F55C41180
                                                                                                                                                                                                                                                          SHA-256:7E577F0F9DA459BA1A325BE95C1FA0DB2C6ECFC1D64CDB73F3ADB09588293BA7
                                                                                                                                                                                                                                                          SHA-512:A0BBD5CE7883C275BF9752C75BA0C9AF0181046D94D27EFC96EC8823C374BADCB69B2B11D2C4497295E5BC25D5790634C69C6E7185F406F2107A8E16044E670F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Damascus) {.. {-9223372036854775808 8712 0 LMT}.. {-1577931912 7200 0 EET}.. {-1568592000 10800 1 EEST}.. {-1554080400 7200 0 EET}.. {-1537142400 10800 1 EEST}.. {-1522630800 7200 0 EET}.. {-1505692800 10800 1 EEST}.. {-1491181200 7200 0 EET}.. {-1474243200 10800 1 EEST}.. {-1459126800 7200 0 EET}.. {-242265600 10800 1 EEST}.. {-228877200 7200 0 EET}.. {-210556800 10800 1 EEST}.. {-197427600 7200 0 EET}.. {-178934400 10800 1 EEST}.. {-165718800 7200 0 EET}.. {-147398400 10800 1 EEST}.. {-134269200 7200 0 EET}.. {-116467200 10800 1 EEST}.. {-102646800 7200 0 EET}.. {-84326400 10800 1 EEST}.. {-71110800 7200 0 EET}.. {-52704000 10800 1 EEST}.. {-39488400 7200 0 EET}.. {-21168000 10800 1 EEST}.. {-7952400 7200 0 EET}.. {10368000 10800 1 EEST}.. {23583600 7200 0 EET}.. {41904000 10800 1 EEST}.. {55119600 7200 0 EET}.. {73526400 10800 1
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):364
                                                                                                                                                                                                                                                          Entropy (8bit):4.412125512631861
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wKwiDm2OHEmVFnoHv9vX+Yl7UIFckVVFSQiL/FG/UIvy/Ur9i/Ur97:MB862Y2mdHzdCv9P+Y9vvjeQlP9/9VkK
                                                                                                                                                                                                                                                          MD5:B5496A038AC230B9D75AA22BB2BE6BDD
                                                                                                                                                                                                                                                          SHA1:ACFD9C78F803F344272E8E188C41ED969EBADA16
                                                                                                                                                                                                                                                          SHA-256:BFC4562055CC4355E79F9EFAA580A4C6A658285916159A5D390A0CDA96A97E98
                                                                                                                                                                                                                                                          SHA-512:AB05D0176DADC1ED03CC526C372B9827A5FA03459E4F4B4365C6CE4B6FBDA043514A9D3FE2DA747159C5A1BC0E07727E6578A101E42B4DB120AF9624368C5FEA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dhaka) {.. {-9223372036854775808 21700 0 LMT}.. {-2524543300 21200 0 HMT}.. {-891582800 23400 0 +0630}.. {-872058600 19800 0 +0530}.. {-862637400 23400 0 +0630}.. {-576138600 21600 0 +06}.. {1230746400 21600 0 +06}.. {1245430800 25200 1 +06}.. {1262278800 21600 0 +06}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):235
                                                                                                                                                                                                                                                          Entropy (8bit):4.597480383845617
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wKCXeSDm2OHnBGeoH1mpvyvScHTU71avScr:MB862qXbmdHnBvC1SyHHq8Hr
                                                                                                                                                                                                                                                          MD5:316DDF860FA234621698EB473E558DB7
                                                                                                                                                                                                                                                          SHA1:35BF955F764555945CF8B314B8E881DAD6CF557B
                                                                                                                                                                                                                                                          SHA-256:8BC2E0D77AC35B6D63E11B820AC45EC23A4195ED773680C600C772FDF4B953F8
                                                                                                                                                                                                                                                          SHA-512:D1A8D5F1DAAB7827BDCBC14506AF8681FD1ED94C6101CC4A3C8CC2A76EA7D3649038069158C539A2007A1B0734FBD87DE120415E07A3F08F44417100C95459F5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dili) {.. {-9223372036854775808 30140 0 LMT}.. {-1830414140 28800 0 +08}.. {-879152400 32400 0 +09}.. {199897200 28800 0 +08}.. {969120000 32400 0 +09}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):148
                                                                                                                                                                                                                                                          Entropy (8bit):4.97292023820863
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2WFKQUMXGm2OHvkdoHsQK23NVsRYovV:SlSWB9eg/2wKQUDm2OHvsoHxVNSN
                                                                                                                                                                                                                                                          MD5:861BA4A0A71E6C3F71B90074275FD57C
                                                                                                                                                                                                                                                          SHA1:BC6FC5233340BB19AE4BD0BA563875479AC0A2B9
                                                                                                                                                                                                                                                          SHA-256:3DB174F1568BC23BF467A3DC7BAF8A2A2952B70653D4DE54F4DB391EC50B6925
                                                                                                                                                                                                                                                          SHA-512:B187735E0783F299253D9F93E002AEFF131FCCA50FB3E04CF0545B334B051D5ED978108A47C6957B608F5F93ED4CC3D69751FE0F40413719EE1C0440CD49AC76
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dubai) {.. {-9223372036854775808 13272 0 LMT}.. {-1577936472 14400 0 +04}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):820
                                                                                                                                                                                                                                                          Entropy (8bit):3.969189280047274
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5we3dJvOt81FCuLqecDngO6jPvTpYy5T4TiFGDr:5BvdJqxiF0uGr
                                                                                                                                                                                                                                                          MD5:9ABD0ECB5F3E738F49CDD1F81C9FF1A4
                                                                                                                                                                                                                                                          SHA1:46B68C7BBD1BE9791B00128A5129AA3668435C93
                                                                                                                                                                                                                                                          SHA-256:550DB44595F59D0F151BE4AF70D6FECE20580AB687EF45DE2A0A75FB2515AC80
                                                                                                                                                                                                                                                          SHA-512:67E2B0EF216D509C4B6DD367519E0A733E54A7CA767D5F7960715E8056E61B7B633C7516D568544F55C9277E90412C1443B822C6EED3341C01F1BD9AA9476FA1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dushanbe) {.. {-9223372036854775808 16512 0 LMT}.. {-1441168512 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 21600 1 +06}.. {684363600 18000 0 +05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7597
                                                                                                                                                                                                                                                          Entropy (8bit):3.7170041442081203
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:G3pv/7V6Aj8aZaNlK0UpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBKb0l:G3v/AaaivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                                                                          MD5:F8E4BA3E260452AE13CF234E60149A62
                                                                                                                                                                                                                                                          SHA1:8DDB08E2FDEEF6539EE0C0038B166908BFED16CD
                                                                                                                                                                                                                                                          SHA-256:8CFE85C48FC22033411432F8B75EE4C097A5D84897698CB1AFD5AB51C47FF5A3
                                                                                                                                                                                                                                                          SHA-512:487177411FB7E9F83AB9AAD84B685322B13A85784D4F90BB9C30F57BFAA6A9298E5C4F36C97444DE1117E51F85A62DC639D08B405460D071C2B29C898553E9A3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Famagusta) {.. {-9223372036854775808 8148 0 LMT}.. {-1518920148 7200 0 EET}.. {166572000 10800 1 EEST}.. {182293200 7200 0 EET}.. {200959200 10800 1 EEST}.. {213829200 7200 0 EET}.. {228866400 10800 1 EEST}.. {243982800 7200 0 EET}.. {260316000 10800 1 EEST}.. {276123600 7200 0 EET}.. {291765600 10800 1 EEST}.. {307486800 7200 0 EET}.. {323820000 10800 1 EEST}.. {338936400 7200 0 EET}.. {354664800 10800 1 EEST}.. {370386000 7200 0 EET}.. {386114400 10800 1 EEST}.. {401835600 7200 0 EET}.. {417564000 10800 1 EEST}.. {433285200 7200 0 EET}.. {449013600 10800 1 EEST}.. {465339600 7200 0 EET}.. {481068000 10800 1 EEST}.. {496789200 7200 0 EET}.. {512517600 10800 1 EEST}.. {528238800 7200 0 EET}.. {543967200 10800 1 EEST}.. {559688400 7200 0 EET}.. {575416800 10800 1 EEST}.. {591138000 7200 0 EET}.. {606866400 10800 1 EEST}.. {622587
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10227
                                                                                                                                                                                                                                                          Entropy (8bit):3.7368714063968778
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:NyyIgGbJv3dPAD7c1FoMNvW0W6AY900g+jCI:NyypGbJv3JKU3WzY9WI
                                                                                                                                                                                                                                                          MD5:DA7A30DF3A661B1E33F2F9D572D69153
                                                                                                                                                                                                                                                          SHA1:8F0A4EFA955A079F2070C3D6AC498BF4996A4C33
                                                                                                                                                                                                                                                          SHA-256:94768CDCCEC68E1123EBDFDE55A1B6F0244C221AF8B437E969DC7EC2CD327900
                                                                                                                                                                                                                                                          SHA-512:D8C0AE1BE8E808E30D79857725CBFE3553FDD2646C8399DABBC7136385EE2E3ADBB57119B14850BAA6EB5C3BE4D52EF1EB51E14814FBB459B20B831505567514
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Gaza) {.. {-9223372036854775808 8272 0 LMT}.. {-2185409872 7200 0 EEST}.. {-933638400 10800 1 EEST}.. {-923097600 7200 0 EEST}.. {-919036800 10800 1 EEST}.. {-857347200 7200 0 EEST}.. {-844300800 10800 1 EEST}.. {-825811200 7200 0 EEST}.. {-812678400 10800 1 EEST}.. {-794188800 7200 0 EEST}.. {-779846400 10800 1 EEST}.. {-762652800 7200 0 EEST}.. {-748310400 10800 1 EEST}.. {-731116800 7200 0 EEST}.. {-682653600 7200 0 EET}.. {-399088800 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336790800 10800 1 EEST}.. {-323654400 7200 0 EET}.. {-305168400 10800 1 EEST}.. {-292032000 7200 0 EET}.. {-273632400 10800 1 EEST}.. {-260496000 7200 0 EET}.. {-242096400 10800 1 EEST}.. {-228960000 7200 0 EET}.. {-210560400 10800 1 EEST}.. {-197424000 7200 0 EET}.. {-178938000 10800 1 EEST}.. {-16580
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):179
                                                                                                                                                                                                                                                          Entropy (8bit):4.86422571961583
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8qvfXHAIgNtaYFARL/2WFKwHp4WFKdy:SlSWB9vsM3yMPHAIgO8AN/2wKi4wKU
                                                                                                                                                                                                                                                          MD5:1BCCB3578FADE993EE8B2C11EAC06CD8
                                                                                                                                                                                                                                                          SHA1:CAEAB714E014CD5040C44E4603708B97BC0B03D4
                                                                                                                                                                                                                                                          SHA-256:12811A7944B892E3D1C0B4B09057CC1899F28081B3CD47FFD248BA49BA308AF0
                                                                                                                                                                                                                                                          SHA-512:1D791DC0E8F45359366DF33C2C337688D2E0E972A90F038733B840D28585505AEF542DDBAD014C9EA8C252048A588CD017DD67A84545A81EDB7C17E3B2E65092
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:Asia/Harbin) $TZData(:Asia/Shanghai)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10202
                                                                                                                                                                                                                                                          Entropy (8bit):3.739018846523374
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:fiIgGbJv3dPADPc1FoMNvW0W6AY900g+jCI:fipGbJv3JKA3WzY9WI
                                                                                                                                                                                                                                                          MD5:48079249A3FB2F8A75BD3246A973D3DA
                                                                                                                                                                                                                                                          SHA1:6616D524EAD7A398F05FC9D099284A0C62AD1511
                                                                                                                                                                                                                                                          SHA-256:337DC81F78EE2114248A554D67D7329EAE22B127D3BB3DF10B4E8ECE311547FD
                                                                                                                                                                                                                                                          SHA-512:DA5A0EBF2BFE43D3B6D96613E8BA3718933F5808B07AF0587813DF20602678E6C9C4270B652023B5DA0B563A2C24F77C39C8A488A8456D2E0BAF8704D5D3B391
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Hebron) {.. {-9223372036854775808 8423 0 LMT}.. {-2185410023 7200 0 EEST}.. {-933638400 10800 1 EEST}.. {-923097600 7200 0 EEST}.. {-919036800 10800 1 EEST}.. {-857347200 7200 0 EEST}.. {-844300800 10800 1 EEST}.. {-825811200 7200 0 EEST}.. {-812678400 10800 1 EEST}.. {-794188800 7200 0 EEST}.. {-779846400 10800 1 EEST}.. {-762652800 7200 0 EEST}.. {-748310400 10800 1 EEST}.. {-731116800 7200 0 EEST}.. {-682653600 7200 0 EET}.. {-399088800 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336790800 10800 1 EEST}.. {-323654400 7200 0 EET}.. {-305168400 10800 1 EEST}.. {-292032000 7200 0 EET}.. {-273632400 10800 1 EEST}.. {-260496000 7200 0 EET}.. {-242096400 10800 1 EEST}.. {-228960000 7200 0 EET}.. {-210560400 10800 1 EEST}.. {-197424000 7200 0 EET}.. {-178938000 10800 1 EEST}.. {-165
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):395
                                                                                                                                                                                                                                                          Entropy (8bit):4.435709983335578
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862RLmdHneCvhYC5sF/p+zHHviViksF/dMUY3sF/RQ9EsV:5de3vhd5sFR+znv2vsFlM/3sFVsV
                                                                                                                                                                                                                                                          MD5:9415271D45F180A88E961F2015B4779D
                                                                                                                                                                                                                                                          SHA1:2016DC7F72D7A24712B5147D6759124F8D46BE00
                                                                                                                                                                                                                                                          SHA-256:4E42C1819E92F391C8B7C186CF273A6E7CD2CAD037C094BC5F065072DF687ABF
                                                                                                                                                                                                                                                          SHA-512:3ADFF85E3E985BF13940F03851FE8E96017CE8C828F08BF687E49C383B3011EC059A22D489BA625997A25DA7BD4DC883F1C900B1A7B977353A23E3C75598962C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ho_Chi_Minh) {.. {-9223372036854775808 25590 0 LMT}.. {-2004073590 25590 0 PLMT}.. {-1851577590 25200 0 +07}.. {-852105600 28800 0 +08}.. {-782643600 32400 0 +09}.. {-767869200 25200 0 +07}.. {-718095600 28800 0 +08}.. {-457772400 25200 0 +07}.. {-315648000 28800 0 +08}.. {171820800 25200 0 +07}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2226
                                                                                                                                                                                                                                                          Entropy (8bit):4.0055033036300145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5Ze9l9Pm4yoHtTYJJIX1Zcp6GS0j1SPQpP6gPE8fTZIPNYQGm75st/nQdwi9:DyaoTcwQt6EsQTng
                                                                                                                                                                                                                                                          MD5:26BCBBA28AE34FE3CF7D17EF4C6B69C8
                                                                                                                                                                                                                                                          SHA1:5324DEA8E7965C66650E7B4769EFA1297B508486
                                                                                                                                                                                                                                                          SHA-256:EE9A6997BC1AAD4A8FA95DB312774C3F37FBB895549230C30FC66C02CC170EB6
                                                                                                                                                                                                                                                          SHA-512:54594CD18838B4A8947EBB5BDE2415727CC127CF79AEC98FC0F5D5A32F68EEAF4E079853239DE9F753CE90F18EFD55AE51FC43D64E313666CEA0EF8AC93BF065
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Hong_Kong) {.. {-9223372036854775808 27402 0 LMT}.. {-2056690800 28800 0 HKT}.. {-900910800 32400 1 HKST}.. {-891579600 30600 1 HKWT}.. {-884248200 32400 0 JST}.. {-761209200 28800 0 HKT}.. {-747907200 32400 1 HKST}.. {-728541000 28800 0 HKT}.. {-717049800 32400 1 HKST}.. {-697091400 28800 0 HKT}.. {-683785800 32400 1 HKST}.. {-668061000 28800 0 HKT}.. {-654755400 32400 1 HKST}.. {-636611400 28800 0 HKT}.. {-623305800 32400 1 HKST}.. {-605161800 28800 0 HKT}.. {-591856200 32400 1 HKST}.. {-573712200 28800 0 HKT}.. {-559801800 32400 1 HKST}.. {-541657800 28800 0 HKT}.. {-528352200 32400 1 HKST}.. {-510211800 28800 0 HKT}.. {-498112200 32400 1 HKST}.. {-478762200 28800 0 HKT}.. {-466662600 32400 1 HKST}.. {-446707800 28800 0 HKT}.. {-435213000 32400 1 HKST}.. {-415258200 28800 0 HKT}.. {-403158600 32400 1 HKST}.. {-383808600 28800 0 HKT
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1583
                                                                                                                                                                                                                                                          Entropy (8bit):3.7521760184466206
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5x3LecCvgsFFFKOksF8FpsF71FQnsFNFxhsFlF6sFaFasFZFisF8GF5sFKLFAZsZ:5FqKVx8Cq9f/y2L
                                                                                                                                                                                                                                                          MD5:A77140A0D8C2D3E2993E4BA7CADFB4C6
                                                                                                                                                                                                                                                          SHA1:AE3586264A86D42F578D4B0F7A30C9BE6047EAB1
                                                                                                                                                                                                                                                          SHA-256:CA88A45E954A9854C680B399E69E4858BF5E861FABFADC19D62D97B734B25415
                                                                                                                                                                                                                                                          SHA-512:05EA9D903EEC755F799B7C2399ED933245A5AE3A594648FE37AF1CE7699AE499B4ED159F428D91259D80BC9AF5117F2DA055A506AED94E5281C38B7AFF69C6FE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Hovd) {.. {-9223372036854775808 21996 0 LMT}.. {-2032927596 21600 0 +06}.. {252439200 25200 0 +07}.. {417978000 28800 1 +07}.. {433785600 25200 0 +07}.. {449600400 28800 1 +07}.. {465321600 25200 0 +07}.. {481050000 28800 1 +07}.. {496771200 25200 0 +07}.. {512499600 28800 1 +07}.. {528220800 25200 0 +07}.. {543949200 28800 1 +07}.. {559670400 25200 0 +07}.. {575398800 28800 1 +07}.. {591120000 25200 0 +07}.. {606848400 28800 1 +07}.. {622569600 25200 0 +07}.. {638298000 28800 1 +07}.. {654624000 25200 0 +07}.. {670352400 28800 1 +07}.. {686073600 25200 0 +07}.. {701802000 28800 1 +07}.. {717523200 25200 0 +07}.. {733251600 28800 1 +07}.. {748972800 25200 0 +07}.. {764701200 28800 1 +07}.. {780422400 25200 0 +07}.. {796150800 28800 1 +07}.. {811872000 25200 0 +07}.. {828205200 28800 1 +07}.. {843926400 25200 0 +07}.. {859654800
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2089
                                                                                                                                                                                                                                                          Entropy (8bit):3.7296034934492694
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5PZy4DdOKStci4KjXoYjoSvfQJWE00dtT43kgiTskNrrBizhzRBqY3M:Py2/svfraBGfgP
                                                                                                                                                                                                                                                          MD5:C9F7AC464970567E5C38CB01ED2297AE
                                                                                                                                                                                                                                                          SHA1:453718BACCAE3FACD761AF22CA5875185478ADDD
                                                                                                                                                                                                                                                          SHA-256:61BAAAD6315FFBDAED6F266880165B06ECCAF72F660B7FB01C8B654F3952D68E
                                                                                                                                                                                                                                                          SHA-512:72044EFAE262CC12974F2DE2AAF06AC4C31BE73071ACD53DDC6B8D8BFC6FBDF937EC03DC881901F730659BDE662FBCFC76C57B2C086DAA97F160530464FBA7C6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Irkutsk) {.. {-9223372036854775808 25025 0 LMT}.. {-2840165825 25025 0 IMT}.. {-1575874625 25200 0 +07}.. {-1247554800 28800 0 +09}.. {354902400 32400 1 +09}.. {370710000 28800 0 +08}.. {386438400 32400 1 +09}.. {402246000 28800 0 +08}.. {417974400 32400 1 +09}.. {433782000 28800 0 +08}.. {449596800 32400 1 +09}.. {465328800 28800 0 +08}.. {481053600 32400 1 +09}.. {496778400 28800 0 +08}.. {512503200 32400 1 +09}.. {528228000 28800 0 +08}.. {543952800 32400 1 +09}.. {559677600 28800 0 +08}.. {575402400 32400 1 +09}.. {591127200 28800 0 +08}.. {606852000 32400 1 +09}.. {622576800 28800 0 +08}.. {638301600 32400 1 +09}.. {654631200 28800 0 +08}.. {670356000 25200 0 +08}.. {670359600 28800 1 +08}.. {686084400 25200 0 +07}.. {695761200 28800 0 +09}.. {701805600 32400 1 +09}.. {717530400 28800 0 +08}.. {733255200 32400 1 +09}.. {748
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):187
                                                                                                                                                                                                                                                          Entropy (8bit):4.9013773460609
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV0XaDovXHAIgoq3XRFvHRL/2WFK4HB/8QaqXKv:SlSWB9vsM3ymQa2HAIgoQ/HN/2wK4HJa
                                                                                                                                                                                                                                                          MD5:8A92C690BE27A69D122BFF51479B7B56
                                                                                                                                                                                                                                                          SHA1:52DB64587A347F34153A51788BDE8C349D966575
                                                                                                                                                                                                                                                          SHA-256:1F77C4BD27574E1D2066885DEF01806A02D3E444424A219A8EC5C114F89665E5
                                                                                                                                                                                                                                                          SHA-512:FEDF57C4862B6792A789F339EB1027EC8A8472B01B7D1D0814C419850B9AC03A7B454FDB04D8BECE166E9A8BCAA58B0B461007A6C824B30B1080991A1DB49CCA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Istanbul)]} {.. LoadTimeZoneFile Europe/Istanbul..}..set TZData(:Asia/Istanbul) $TZData(:Europe/Istanbul)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):370
                                                                                                                                                                                                                                                          Entropy (8bit):4.4733192761103515
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wKcrJfDm2OHATJeoHMaSYov/YSZkc5q/MVSSFFWSyvScH+dMVSSFL+:MB862EJLmdHjCEdOc5aMxaSyHHaMxF6P
                                                                                                                                                                                                                                                          MD5:C689A1AA9FFE535AEB3AD3D7EDE55172
                                                                                                                                                                                                                                                          SHA1:0520FC9A4619FB555A79C5DF2AE82422BF2C5EDA
                                                                                                                                                                                                                                                          SHA-256:2F39D9F93761B85C254F458317A7DE2B4184BE9459F2193A85C08662E801269A
                                                                                                                                                                                                                                                          SHA-512:C1034FB2FCFEF201C5362AF21B048B6637A824C5C93D75854CF3807892C772CD4376533E58BFF8D8726F531F43CB231365B8012EBD3C1BECED865D3CD2D6673D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Jakarta) {.. {-9223372036854775808 25632 0 LMT}.. {-3231299232 25632 0 BMT}.. {-1451719200 26400 0 +0720}.. {-1172906400 27000 0 +0730}.. {-876641400 32400 0 +09}.. {-766054800 27000 0 +0730}.. {-683883000 28800 0 +08}.. {-620812800 27000 0 +0730}.. {-189415800 25200 0 WIB}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):213
                                                                                                                                                                                                                                                          Entropy (8bit):4.834345288972067
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wKcaDm2OHG4YoH1kcfvScHVowkVcr2CV4zvhyov:MB862PmdHNYC6cfHHVop2NVkoov
                                                                                                                                                                                                                                                          MD5:2CB3A13FCC48F8C4457E001FC309918B
                                                                                                                                                                                                                                                          SHA1:83174176815CB93D216B5BC532C120EC8AC433CF
                                                                                                                                                                                                                                                          SHA-256:761C1E80FEBF46D6D6215CEBF211F121974156D9BCE2FB4258C1074C6ED2CE22
                                                                                                                                                                                                                                                          SHA-512:65009020AB9FEC2F8158A4851A78B71127F9B262DDD1472583942E19B7C086304F54BC8DAE5A40BD1448BCAEDA0FDBACCD19400E10FFA0357E324535F9036EF0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Jayapura) {.. {-9223372036854775808 33768 0 LMT}.. {-1172913768 32400 0 +09}.. {-799491600 34200 0 +0930}.. {-189423000 32400 0 WIT}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8135
                                                                                                                                                                                                                                                          Entropy (8bit):3.770028446231146
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:GKfnxFAEX/nPVl8diAg9oEhH20AHz7LzdWhYbBJPXuVhKaM76Rmg4DLeEcNptv5C:7ffBvPAzF0AHzPzdD1+XBRF0
                                                                                                                                                                                                                                                          MD5:884227D48C92BA6C519BFE571D4F1037
                                                                                                                                                                                                                                                          SHA1:21F8977816C2B439686A50D353B836A6D132A946
                                                                                                                                                                                                                                                          SHA-256:0BDC2C693134199C2ECD374CC01468813DB29DF47422C706A3EA2BE5ECCA177A
                                                                                                                                                                                                                                                          SHA-512:8A09F1FE11DAD203501A16FE6A2CAEC969FE3553B456B8BD1997E55B3EE430B2BB4B54F7D87C5E99931FD96E7C769CAA618C777EBD23FBD1E1A0F57409422914
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Jerusalem) {.. {-9223372036854775808 8454 0 LMT}.. {-2840149254 8440 0 JMT}.. {-1641003640 7200 0 IST}.. {-933638400 10800 1 IDT}.. {-923097600 7200 0 IST}.. {-919036800 10800 1 IDT}.. {-857347200 7200 0 IST}.. {-844300800 10800 1 IDT}.. {-825811200 7200 0 IST}.. {-812678400 10800 1 IDT}.. {-794188800 7200 0 IST}.. {-779846400 10800 1 IDT}.. {-762652800 7200 0 IST}.. {-748310400 10800 1 IDT}.. {-731116800 7200 0 IST}.. {-681955200 14400 1 IDDT}.. {-673228800 10800 1 IDT}.. {-667958400 7200 0 IST}.. {-652320000 10800 1 IDT}.. {-636422400 7200 0 IST}.. {-622080000 10800 1 IDT}.. {-608947200 7200 0 IST}.. {-591840000 10800 1 IDT}.. {-572486400 7200 0 IST}.. {-558576000 10800 1 IDT}.. {-542851200 7200 0 IST}.. {-527731200 10800 1 IDT}.. {-514425600 7200 0 IST}.. {-490838400 10800 1 IDT}.. {-482976000 7200 0 IST}.. {-459388800 10800 1 I
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):180
                                                                                                                                                                                                                                                          Entropy (8bit):4.8546989169864085
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2WFKTtNMXGm2OHodFxsYoHvgVHURRNVsRYovFFFkdj/cXHF:SlSWB9eg/2wKTPDm2OHoH+YoHvgVHURA
                                                                                                                                                                                                                                                          MD5:9BD9B21661C235C0794078EC98978D3B
                                                                                                                                                                                                                                                          SHA1:3D854780F49D0E5F5A190DC9367C7406127C5E4D
                                                                                                                                                                                                                                                          SHA-256:A59C95C038F2E945D685D96FA9B859CE82A643A1B7F56EB36B2C809DE91CD4BA
                                                                                                                                                                                                                                                          SHA-512:A76E99CF03DA8897F0A210A98DB79E4CD60070F2BE363D0D0960D9882919F9B49978FA55BB2500F1648ADD4080730CAD85BAFF61D885A9EAD394AC04C850F6BA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kabul) {.. {-9223372036854775808 16608 0 LMT}.. {-2524538208 14400 0 +04}.. {-788932800 16200 0 +0430}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2060
                                                                                                                                                                                                                                                          Entropy (8bit):3.788131608921229
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5+SeWI/2kkWk7YFpR2kHmxCcUdBbcHDLV2vpXt25A0UeRr9ydzkMfF6USRWk9UuV:5i/2ZsFLrcZwvJt2F+doTr9Q3G80
                                                                                                                                                                                                                                                          MD5:390F39934F095F89358B73D056D90264
                                                                                                                                                                                                                                                          SHA1:6B57CE5346B50ED88BFBB6BC57F834FB3F564905
                                                                                                                                                                                                                                                          SHA-256:6E0278E389072437BC07A5032CD58E9E5B1B2BDB20918632C422EFA97BC43ABF
                                                                                                                                                                                                                                                          SHA-512:6C54D94E95D73030F2FFCF8D130494CBD79FB1CEB9B59ADE0743C10F02557C3DD59CC6274B262A7E29C2D4C35DDA4B6A9A0398C661F5BD40F3B92181192B9577
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kamchatka) {.. {-9223372036854775808 38076 0 LMT}.. {-1487759676 39600 0 +11}.. {-1247569200 43200 0 +13}.. {354888000 46800 1 +13}.. {370695600 43200 0 +12}.. {386424000 46800 1 +13}.. {402231600 43200 0 +12}.. {417960000 46800 1 +13}.. {433767600 43200 0 +12}.. {449582400 46800 1 +13}.. {465314400 43200 0 +12}.. {481039200 46800 1 +13}.. {496764000 43200 0 +12}.. {512488800 46800 1 +13}.. {528213600 43200 0 +12}.. {543938400 46800 1 +13}.. {559663200 43200 0 +12}.. {575388000 46800 1 +13}.. {591112800 43200 0 +12}.. {606837600 46800 1 +13}.. {622562400 43200 0 +12}.. {638287200 46800 1 +13}.. {654616800 43200 0 +12}.. {670341600 39600 0 +12}.. {670345200 43200 1 +12}.. {686070000 39600 0 +11}.. {695746800 43200 0 +13}.. {701791200 46800 1 +13}.. {717516000 43200 0 +12}.. {733240800 46800 1 +13}.. {748965600 43200 0 +12}.. {764
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):457
                                                                                                                                                                                                                                                          Entropy (8bit):4.396286144160272
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862dmdH35Cy6DvjeQXvjKEn6vNEhFc0bkTfb2iWToN1:5de3IjjeQ/jKE6vNNa8
                                                                                                                                                                                                                                                          MD5:DF604BCD42A3C1E6BABD0E4FF5764CA3
                                                                                                                                                                                                                                                          SHA1:984111F3A75EE7D8760AA2B839010545AF8EE359
                                                                                                                                                                                                                                                          SHA-256:4E7F7ACAE8B4018A835328744F680C8054771805BB0BB07678A09737963C090D
                                                                                                                                                                                                                                                          SHA-512:690AC3FC7CA3C66AA70F17E38C6B43FFACAB3F86040C3BA94FBFF80AC8C1AECF8192E503282109DABF3228F8DC73C732F1041C80455B8B26BDB25C4C32FA286A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Karachi) {.. {-9223372036854775808 16092 0 LMT}.. {-1988166492 19800 0 +0530}.. {-862637400 23400 1 +0630}.. {-764145000 19800 0 +0530}.. {-576135000 18000 0 +05}.. {38775600 18000 0 PKT}.. {1018119600 21600 1 PKST}.. {1033840800 18000 0 PKT}.. {1212260400 21600 1 PKST}.. {1225476000 18000 0 PKT}.. {1239735600 21600 1 PKST}.. {1257012000 18000 0 PKT}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):174
                                                                                                                                                                                                                                                          Entropy (8bit):4.967143524972358
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8s4YkyXHAIgNrYOARL/2WFKu3e2WFKjov:SlSWB9vsM3yMGSHAIgvAN/2wKulwKjy
                                                                                                                                                                                                                                                          MD5:259662F35AA09A891C2DDF8FCFECD6F0
                                                                                                                                                                                                                                                          SHA1:DBB3A363A34C33F0B6B0D677E43C2985E2BAF976
                                                                                                                                                                                                                                                          SHA-256:7B2251F0A41CBADF45D69F24604834167B14D8D33B510E635719AB404CABBCE2
                                                                                                                                                                                                                                                          SHA-512:CD7E514555D58985C774535556B66542EFC5FB7CD5891F42FE21B591612CB7EBD4B41E96593E26E9283BA1B01EF3BE0FDFAE871F5EF6ADF2286AF1E479DCB44B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Urumqi)]} {.. LoadTimeZoneFile Asia/Urumqi..}..set TZData(:Asia/Kashgar) $TZData(:Asia/Urumqi)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.896398105471451
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2WFKXIi7hvXMXGm2OHF+VT5oHsQKwMTXvv6Q6zRk8P4VvW/:SlSWB9eg/2wKYghfDm2OH0T5oHxNMzv8
                                                                                                                                                                                                                                                          MD5:7AC6429D2A08372C71C61B4521246FEC
                                                                                                                                                                                                                                                          SHA1:6E50F5AD1018398491453D751F8B717B618EF46E
                                                                                                                                                                                                                                                          SHA-256:F0A0816E62036637F75081CBF17A1E6B8FBC2D86AEC3CD2E234BBBDD6EC9F109
                                                                                                                                                                                                                                                          SHA-512:A5389A318896ABCAFE419262F6B8CA86C917788F1E2AFBC8CB1C074A52870E7A92C9F6F7D79DDE4AB0D267D870D3CCD69B3FC5FD57520352EFE36C583B493FB9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kathmandu) {.. {-9223372036854775808 20476 0 LMT}.. {-1577943676 19800 0 +0530}.. {504901800 20700 0 +0545}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.8363583658476745
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8yIi7V5XHAIgN1AIilvWARL/2WFKSiZ1/2WFKXIi7y:SlSWB9vsM3y7gVJHAIg5QOAN/2wKSg15
                                                                                                                                                                                                                                                          MD5:4CCC96293A33113D9ADC4130DCD19CBA
                                                                                                                                                                                                                                                          SHA1:7BAB4B8DD6BB415A2FC86D9AB36BE2A893C03153
                                                                                                                                                                                                                                                          SHA-256:9ACC9586B6F8B53BFE8B242283A434A9A9633D60559EBFDEE263B4C8915D50CA
                                                                                                                                                                                                                                                          SHA-512:644E1777E01C15A728E30526F131462FCE50476A8FEDA9B99F41D95013BB8833A79437E75AA2025E2FD2E253B9AD40709DEF77E1F0C73DAAE7A9CF886A175A03
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Kathmandu)]} {.. LoadTimeZoneFile Asia/Kathmandu..}..set TZData(:Asia/Katmandu) $TZData(:Asia/Kathmandu)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2119
                                                                                                                                                                                                                                                          Entropy (8bit):3.707911838150672
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5No6r1gIgWH/lt0irzEzCSCItWiIrW+rDQk9CVhyFYkRDhUBAc6l:r5PhtjLiII2JBC6c6l
                                                                                                                                                                                                                                                          MD5:D7B394A9662D60D01781005FE73CC9E8
                                                                                                                                                                                                                                                          SHA1:50B5EBD02596DC45D1F69358C5B69DD3058905FC
                                                                                                                                                                                                                                                          SHA-256:33203D7FB7F3D1F848640ECE0642A2305E1863B4D47413075E2E7E40BD7418E7
                                                                                                                                                                                                                                                          SHA-512:055EBA420F2F6049E803796ACCA263264B9E585E5312A86B8DF7B409C5F1CB1810F3AEDACD66CCF4605E55198947D263C240486C2A4D453D23C89802F0C66BBA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Khandyga) {.. {-9223372036854775808 32533 0 LMT}.. {-1579424533 28800 0 +08}.. {-1247558400 32400 0 +10}.. {354898800 36000 1 +10}.. {370706400 32400 0 +09}.. {386434800 36000 1 +10}.. {402242400 32400 0 +09}.. {417970800 36000 1 +10}.. {433778400 32400 0 +09}.. {449593200 36000 1 +10}.. {465325200 32400 0 +09}.. {481050000 36000 1 +10}.. {496774800 32400 0 +09}.. {512499600 36000 1 +10}.. {528224400 32400 0 +09}.. {543949200 36000 1 +10}.. {559674000 32400 0 +09}.. {575398800 36000 1 +10}.. {591123600 32400 0 +09}.. {606848400 36000 1 +10}.. {622573200 32400 0 +09}.. {638298000 36000 1 +10}.. {654627600 32400 0 +09}.. {670352400 28800 0 +09}.. {670356000 32400 1 +09}.. {686080800 28800 0 +08}.. {695757600 32400 0 +10}.. {701802000 36000 1 +10}.. {717526800 32400 0 +09}.. {733251600 36000 1 +10}.. {748976400 32400 0 +09}.. {7647
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):336
                                                                                                                                                                                                                                                          Entropy (8bit):4.614218930153471
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wKvhfDm2OHEX3gYoHrXdUvvYbQLpUFdvjSVVFJLNsR/QFckVVFJLLW:MB8623tmdHNYCDWXYbQtUTvjAJBs50vs
                                                                                                                                                                                                                                                          MD5:248F1B5A26455000C936CE8BC02C1A0B
                                                                                                                                                                                                                                                          SHA1:0C3F8CD4E038B113E5238AC52652809B6CA27999
                                                                                                                                                                                                                                                          SHA-256:6D464564ED2EFC9DADA1586D4FC99FE333726D2BE15A00E30C2391F588896463
                                                                                                                                                                                                                                                          SHA-512:AF36B0B3D410305ED504726C87265ACCAF5577A9B5DD7E7DAF135420E356C651287873197431B65B5317B4BA2009274288E4F101AC1274045A8D99E2414AB132
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kolkata) {.. {-9223372036854775808 21208 0 LMT}.. {-3645237208 21200 0 HMT}.. {-3155694800 19270 0 MMT}.. {-2019705670 19800 0 IST}.. {-891581400 23400 1 +0630}.. {-872058600 19800 0 IST}.. {-862637400 23400 1 +0630}.. {-764145000 19800 0 IST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2062
                                                                                                                                                                                                                                                          Entropy (8bit):3.7086418466382605
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5Ote2CoXJfsFN/3sFrOksF/sF7IyksF7FRZsFLsFTsFcsFk73sFK/XCFKTipnFEw:5B40yVRB7VfXucydm46I/CTxwh
                                                                                                                                                                                                                                                          MD5:A59F7FFD0C3EBAD47EC5F2B89EBBD9FA
                                                                                                                                                                                                                                                          SHA1:ACB94E28E0CF7C6606086267CEA1F63A3E755F56
                                                                                                                                                                                                                                                          SHA-256:53B8D5E7FB1BD67FECE66A933D9BDBB773F14A8C04D316A2A1B00EC6DBC151DD
                                                                                                                                                                                                                                                          SHA-512:7B3886B9D0A793CCEEDB2B190523922CFEBE5C82A5201C9EFA30CA4C7F63FB75C998CC7E1BD48D5D489F16E36FC0C22BD954CB7D321B3C09B36B60629C4C9F7E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Krasnoyarsk) {.. {-9223372036854775808 22286 0 LMT}.. {-1577513486 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {7
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):188
                                                                                                                                                                                                                                                          Entropy (8bit):4.956557779400841
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq801c3vXHAIgNtK1tyHRL/2WFK1NFWFKf1z:SlSWB9vsM3yUgHAIgWv6N/2wK1NFwKf9
                                                                                                                                                                                                                                                          MD5:E70767DA85A7E1FA9395FF0B16CFE5CE
                                                                                                                                                                                                                                                          SHA1:3F78034F166CFC80B54E56AF289C7700A7E4AA5C
                                                                                                                                                                                                                                                          SHA-256:056D352DDCFEC155375430FFF3C8743ED5C9B51B866A099E97E12CC381071F50
                                                                                                                                                                                                                                                          SHA-512:FEDC854FB043AA79F132827F98F8983E480727FAA039CF2FB5B82611E724312A4F3F006EE58707F12B0AA90F5872E17F76E2A040CFB3A90D017C5CF92E52DA0A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Singapore)]} {.. LoadTimeZoneFile Asia/Singapore..}..set TZData(:Asia/Kuala_Lumpur) $TZData(:Asia/Singapore)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):669
                                                                                                                                                                                                                                                          Entropy (8bit):4.074079100812583
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wKPLBDm2OHXoH3UTdMVSSFVM5qGeCiKaFzsBRcerUNwGvULhMXeiCs:MB862HL1mdHXC3UBMxJJo9rphTXUzHHF
                                                                                                                                                                                                                                                          MD5:489E706324960E86B6E174D913C72E02
                                                                                                                                                                                                                                                          SHA1:C7D77482C0D41F3426FC269B3B6C0575EF0E8C7E
                                                                                                                                                                                                                                                          SHA-256:6E35E560675B0B5322474900D4EC8326C504788C1F82E533B09785DEEFF092DF
                                                                                                                                                                                                                                                          SHA-512:5CEFD44656C041E59A16481E042EA914E7C003BDE6ADF5F49B57052E91F4F732A91A244BD8BC09EF5DC2640D3210DEE53882717C5C4CBD85CCE44A93B028E9C3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kuching) {.. {-9223372036854775808 26480 0 LMT}.. {-1383463280 27000 0 +0730}.. {-1167636600 28800 0 +08}.. {-1082448000 30000 1 +08}.. {-1074586800 28800 0 +08}.. {-1050825600 30000 1 +08}.. {-1042964400 28800 0 +08}.. {-1019289600 30000 1 +08}.. {-1011428400 28800 0 +08}.. {-987753600 30000 1 +08}.. {-979892400 28800 0 +08}.. {-956217600 30000 1 +08}.. {-948356400 28800 0 +08}.. {-924595200 30000 1 +08}.. {-916734000 28800 0 +08}.. {-893059200 30000 1 +08}.. {-885198000 28800 0 +08}.. {-879667200 32400 0 +09}.. {-767005200 28800 0 +08}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):173
                                                                                                                                                                                                                                                          Entropy (8bit):4.877362838821003
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8t14XHAIgNsM13oOARL/2WFKdQWFK81Fn:SlSWB9vsM3yN14HAIgaM1YOAN/2wKdQ6
                                                                                                                                                                                                                                                          MD5:EA1DB4B80CC74CBA024B9BF3734B31F2
                                                                                                                                                                                                                                                          SHA1:D8131C093BCA3B378BEC606CFEB56A40CB4E246F
                                                                                                                                                                                                                                                          SHA-256:8E0C60A9AA64FB8602EDC35311F7436B04853970A21C1F6C871494A09AAD5787
                                                                                                                                                                                                                                                          SHA-512:3B57C9CCC16AA4FE71D275D5EC6A7BC1838841023EE4408158362A7E13E7F1B345F7D95006BC8D2FC270158864E286A1A9364C792F679D5803BD82148399C199
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Riyadh)]} {.. LoadTimeZoneFile Asia/Riyadh..}..set TZData(:Asia/Kuwait) $TZData(:Asia/Riyadh)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):169
                                                                                                                                                                                                                                                          Entropy (8bit):4.781739054385376
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8PWXHAIgNz+NOARL/2WFKf+WFKkvn:SlSWB9vsM3yOHAIg1AN/2wKGwKmn
                                                                                                                                                                                                                                                          MD5:55DAE27AEAA74FE822338C20B6CDFF68
                                                                                                                                                                                                                                                          SHA1:F00EB827DC29EB2063B3A0EDBC39856637C55F33
                                                                                                                                                                                                                                                          SHA-256:4308D741C83B263C7C9FB8EC692A7B7B502135E407B265B12EA7EF92523455C0
                                                                                                                                                                                                                                                          SHA-512:398EE6015C58BDBBEAB49B74833B938FD84DE1AC6D3B8D095CE772ECA980D9E93F4EBFFFFCEAE7F91E287C8CE4F94B1A078D8E1460C352B7C2018F99915838FF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Macau)]} {.. LoadTimeZoneFile Asia/Macau..}..set TZData(:Asia/Macao) $TZData(:Asia/Macau)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2217
                                                                                                                                                                                                                                                          Entropy (8bit):3.9638741177777868
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5ReCX8Iv3nhPHCvzncCHg9PHjZzH+0HDHN1aHhHNaezHBjHeHsH65H18HDH983lY:5d8u3hfCTcaOrh6qn151Wf3Bogp+nlC
                                                                                                                                                                                                                                                          MD5:B184E7403CB7168607D2C9E158F86A3B
                                                                                                                                                                                                                                                          SHA1:48B003B8F822BE979FBCB08CBDBFFC617BCF99DB
                                                                                                                                                                                                                                                          SHA-256:FBCB92CECB1CB0BC284ADC30D70C5F57B3AFC992136A0D898ABC64490BB700FB
                                                                                                                                                                                                                                                          SHA-512:D8C5C67CAEB7C670B7BD1DACC1203C4DEE4DDB16A780F502C4440997CFCFF869E86842EF87C2CD0E0B942941C02A6BC3BDAB7CEAD78B026B68F4A031173400C8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Macau) {.. {-9223372036854775808 27250 0 LMT}.. {-2056692850 28800 0 CST}.. {-884509200 32400 0 +09}.. {-873280800 36000 1 +09}.. {-855918000 32400 0 +09}.. {-841744800 36000 1 +09}.. {-828529200 32400 0 +10}.. {-765363600 28800 0 CT}.. {-747046800 32400 1 CDT}.. {-733827600 28800 0 CST}.. {-716461200 32400 1 CDT}.. {-697021200 28800 0 CST}.. {-683715600 32400 1 CDT}.. {-667990800 28800 0 CST}.. {-654771600 32400 1 CDT}.. {-636627600 28800 0 CST}.. {-623322000 32400 1 CDT}.. {-605178000 28800 0 CST}.. {-591872400 32400 1 CDT}.. {-573642000 28800 0 CST}.. {-559818000 32400 1 CDT}.. {-541674000 28800 0 CST}.. {-528368400 32400 1 CDT}.. {-510224400 28800 0 CST}.. {-498128400 32400 1 CDT}.. {-478774800 28800 0 CST}.. {-466678800 32400 1 CDT}.. {-446720400 28800 0 CST}.. {-435229200 32400 1 CDT}.. {-415258200 28800 0 CST}.. {-403158600
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2088
                                                                                                                                                                                                                                                          Entropy (8bit):3.7643610103361134
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5he9dbbv+OC+jsuwltZQONEa2Ggf3augO8UoxLyHdX/CX6bW4Bv/7NKx/y:5wv+0j6lua2Gg/3gO8UoOZU2Wc/pKo
                                                                                                                                                                                                                                                          MD5:F62A89F441C9C17EB99F64223C815651
                                                                                                                                                                                                                                                          SHA1:408C38A79E056FF9B03D0DA85114DC015CB66938
                                                                                                                                                                                                                                                          SHA-256:0C6EEEB7975A95C2B0678D137E6A735238D244A37FA11078050051511DE499FE
                                                                                                                                                                                                                                                          SHA-512:55DC72546BDC26450D5318E9D2819E32A91C27D06A7AF5432BD50F8722C69984BBAA8599055A824D2935D919F0C0AA357687DD9B47F49F213EEE21AF7458FE17
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Magadan) {.. {-9223372036854775808 36192 0 LMT}.. {-1441188192 36000 0 +10}.. {-1247565600 39600 0 +12}.. {354891600 43200 1 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}.. {76469
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):243
                                                                                                                                                                                                                                                          Entropy (8bit):4.737440985553183
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wK5XDm2OHUVoHxYQTLQTvj1kc3gEpHkH8vScHr0:MB862hTmdHsCLTI6cQe7HHA
                                                                                                                                                                                                                                                          MD5:9116C0B70AB33EC49F933EAE0238FD4B
                                                                                                                                                                                                                                                          SHA1:BA390E8FBEAF5EA6E861AFC5A51CD4DF0B422461
                                                                                                                                                                                                                                                          SHA-256:30D8AB00E32ECE51442C0310E650D89D6989E0809600EE334CB10C506D84BF9D
                                                                                                                                                                                                                                                          SHA-512:499E60E8CBDA72226BCB4E241020E62B6F88E7D3E4329D260A6536EF87C02D7D61FD1BECC47D4FF308B4EB5D3E7FFBE2EC1C96FE2DEDC09DD1D973421C5FFE1E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Makassar) {.. {-9223372036854775808 28656 0 LMT}.. {-1577951856 28656 0 MMT}.. {-1172908656 28800 0 +08}.. {-880272000 32400 0 +09}.. {-766054800 28800 0 WITA}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):421
                                                                                                                                                                                                                                                          Entropy (8bit):4.48495488773916
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862GjmdHnCTZBCvEo6AwoucQzy4orjAbomAtoNv:5GjeCVwvB6AduXzylHAMmAa9
                                                                                                                                                                                                                                                          MD5:0FBF0ED252638DF31826C33EB3FFBFE2
                                                                                                                                                                                                                                                          SHA1:3496E4A5251A9BDF3AA4368297140780B6DBF66D
                                                                                                                                                                                                                                                          SHA-256:070D61A0E39643A700ABA89A8A4BE5733BA456958966098405E11ECDFA854D76
                                                                                                                                                                                                                                                          SHA-512:2A40E14964B357809E596DF88D8C4141ED78664BACA0A7724A7CA837EF427DC2B07C48D9DBE5787FAB0015673F5BDE002223D489334C5B91B74EEC5507A14B78
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Manila) {.. {-9223372036854775808 -57360 0 LMT}.. {-3944621040 29040 0 LMT}.. {-2229321840 28800 0 PST}.. {-1046678400 32400 1 PDT}.. {-1038733200 28800 0 PST}.. {-873273600 32400 0 JST}.. {-794221200 28800 0 PST}.. {-496224000 32400 1 PDT}.. {-489315600 28800 0 PST}.. {259344000 32400 1 PDT}.. {275151600 28800 0 PST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):170
                                                                                                                                                                                                                                                          Entropy (8bit):4.805992552335358
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8DeXHAIgN6S7ARL/2WFKvE+H+WFKQ3n:SlSWB9vsM3yj+HAIgMS7AN/2wKLewKQ3
                                                                                                                                                                                                                                                          MD5:8AEB5C3E81069F884A370714E8013F1F
                                                                                                                                                                                                                                                          SHA1:4E3DD4A84627E75E84726C0CBA72CA6801280C2B
                                                                                                                                                                                                                                                          SHA-256:011B7DE1C9F7EC241B224BC864D8AE66ACB433FBC8AD939E4DBEB12BE6390243
                                                                                                                                                                                                                                                          SHA-512:50B1DE2615AE9B4781505DC709F9D07F6221D4E6D7B61D7BDA682377EAD9807F47FF0E933B79823D0DFD9F3647A82CFC28FB41FBB2226ED1D08B76F86FEB45DC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dubai)]} {.. LoadTimeZoneFile Asia/Dubai..}..set TZData(:Asia/Muscat) $TZData(:Asia/Dubai)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7625
                                                                                                                                                                                                                                                          Entropy (8bit):3.7113086720696398
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:R3pv/7V6Aj8aZaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBKb0l:R3v/AauivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                                                                          MD5:2ADD0DFC1F133E4D044727234251A3DC
                                                                                                                                                                                                                                                          SHA1:0D1502986258349E384017BA6CB8FA0AC424638C
                                                                                                                                                                                                                                                          SHA-256:3C3E4844C70D361893EF022D6C3C8E38B243E91D40C5A726C924355476816F25
                                                                                                                                                                                                                                                          SHA-512:70CDD53E7E44EDABF653A4F92EECBF5BB20A31DA95D65209D1CADE7DD9FC68946B8EC8829C28AE00BE5F42AAB545B9282CBBCFC5834437D6A94A179BF4FE0141
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Nicosia) {.. {-9223372036854775808 8008 0 LMT}.. {-1518920008 7200 0 EET}.. {166572000 10800 1 EEST}.. {182293200 7200 0 EET}.. {200959200 10800 1 EEST}.. {213829200 7200 0 EET}.. {228866400 10800 1 EEST}.. {243982800 7200 0 EET}.. {260316000 10800 1 EEST}.. {276123600 7200 0 EET}.. {291765600 10800 1 EEST}.. {307486800 7200 0 EET}.. {323820000 10800 1 EEST}.. {338936400 7200 0 EET}.. {354664800 10800 1 EEST}.. {370386000 7200 0 EET}.. {386114400 10800 1 EEST}.. {401835600 7200 0 EET}.. {417564000 10800 1 EEST}.. {433285200 7200 0 EET}.. {449013600 10800 1 EEST}.. {465339600 7200 0 EET}.. {481068000 10800 1 EEST}.. {496789200 7200 0 EET}.. {512517600 10800 1 EEST}.. {528238800 7200 0 EET}.. {543967200 10800 1 EEST}.. {559688400 7200 0 EET}.. {575416800 10800 1 EEST}.. {591138000 7200 0 EET}.. {606866400 10800 1 EEST}.. {62258760
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2063
                                                                                                                                                                                                                                                          Entropy (8bit):3.718004112421892
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:526enddzXJfsFN/3sFrOksF/sF7IyksF7FRZsFLsFTsFcsFk73sFK/XCFKTipnFf:5l40yVRB7VfXucydm46I/CTxwf
                                                                                                                                                                                                                                                          MD5:513B6A2AF76DAED9002C037BEC99862F
                                                                                                                                                                                                                                                          SHA1:82D1C47BDF46B8B901C35BACACE8595C093BF5F2
                                                                                                                                                                                                                                                          SHA-256:96A445D47D834C28480D1E2036ECA4962B35AFA494C219065D4879F71C1830DB
                                                                                                                                                                                                                                                          SHA-512:2FE5AF4FA9D6AAB4FBD8E354789B82D39FA1B52394D3A0ABFBC6A30A531E0B7429A3D9AC7835A2843A6E9859E0255565F151FDFC87004ACB4EBD1AAD40BDA8A4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Novokuznetsk) {.. {-9223372036854775808 20928 0 LMT}.. {-1441259328 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2121
                                                                                                                                                                                                                                                          Entropy (8bit):3.714792994893581
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:52sve20ruXJfsFN/3sFrOksF/sF7IyksF7FRZsFLsFTsFcsFk73sFK/XCFKTipnF:5Hc40yVRB7VfXu0TKmtTTDOWQ
                                                                                                                                                                                                                                                          MD5:AC8C8D768503C8334A9FBAEF4C3A9CAB
                                                                                                                                                                                                                                                          SHA1:CA10BB99E2D7AB329229759BD4801068A3AEB6D5
                                                                                                                                                                                                                                                          SHA-256:EF799077291F6B3B19E0AEC88F224BB592FAAD09D30740F2376D3D20F2169639
                                                                                                                                                                                                                                                          SHA-512:34049B1AC4254F999C3E5AD8CB31ABF88AC2D972E20E19927F33CC59935354F92125A0342A413E64227E8AE29DDFC2FFE5F67AE538C89D8EBAD7FCA889321DFA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Novosibirsk) {.. {-9223372036854775808 19900 0 LMT}.. {-1579476700 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {738090000 25200 0 +07}.. {7
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2055
                                                                                                                                                                                                                                                          Entropy (8bit):3.6912374223526396
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5abexPvO1FMnFP1FCnFHnFKqenFdDnFQgOnFxjPnFITnFonFJynFAT4TBThSv0FP:5asvjdqxph01NSvPETKmtTTDO0
                                                                                                                                                                                                                                                          MD5:3E06B20B0B62AA09FA03082FAEE4FD62
                                                                                                                                                                                                                                                          SHA1:8886EC80528ECA13D3364138BFFE92F881768169
                                                                                                                                                                                                                                                          SHA-256:2605CD1E26E4AB48BCB4399BB5B17BAD115A47F87BA3DD54B55BB50C3FE82606
                                                                                                                                                                                                                                                          SHA-512:04C1B6A898D12C8EA1B0B2F6665C870434061C63CC8F7A067BFC708E9828BA2E60104B82E2025E42D51DA2F485890C4D34EC0341EF466A7942649BE64F5EEE17
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Omsk) {.. {-9223372036854775808 17610 0 LMT}.. {-1582088010 18000 0 +05}.. {-1247547600 21600 0 +07}.. {354909600 25200 1 +07}.. {370717200 21600 0 +06}.. {386445600 25200 1 +07}.. {402253200 21600 0 +06}.. {417981600 25200 1 +07}.. {433789200 21600 0 +06}.. {449604000 25200 1 +07}.. {465336000 21600 0 +06}.. {481060800 25200 1 +07}.. {496785600 21600 0 +06}.. {512510400 25200 1 +07}.. {528235200 21600 0 +06}.. {543960000 25200 1 +07}.. {559684800 21600 0 +06}.. {575409600 25200 1 +07}.. {591134400 21600 0 +06}.. {606859200 25200 1 +07}.. {622584000 21600 0 +06}.. {638308800 25200 1 +07}.. {654638400 21600 0 +06}.. {670363200 18000 0 +06}.. {670366800 21600 1 +06}.. {686091600 18000 0 +05}.. {695768400 21600 0 +07}.. {701812800 25200 1 +07}.. {717537600 21600 0 +06}.. {733262400 25200 1 +07}.. {748987200 21600 0 +06}.. {76471200
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1664
                                                                                                                                                                                                                                                          Entropy (8bit):3.708603813141953
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:53PvalvNhQQvmRKqv0fvzQIovWdvEGvDaDv7w9hYwr:JHaBNKs6b03zB0WJEuDa77w9hYA
                                                                                                                                                                                                                                                          MD5:A3BD0C15642AE4F001F98F8E060E8374
                                                                                                                                                                                                                                                          SHA1:366F3C7FD4000AC23B79AB0FF4429371ED323B81
                                                                                                                                                                                                                                                          SHA-256:933BBCD7AE0BF59A5B4A6E0EF74C237FEEDC42E6A3AEB2158131AA70FBA6FE47
                                                                                                                                                                                                                                                          SHA-512:16D8692D3EA96D3594E6220A6989BBFBB926A66EEBEB240C4DC68BE75C69C5206659D9D341D92AE6128928FD38A5F45B445621CBBBA4E4BA8C34C3AC52BF3C08
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Oral) {.. {-9223372036854775808 12324 0 LMT}.. {-1441164324 10800 0 +03}.. {-1247540400 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {701816400 14400 0 +04}.. {701820000 18000 1 +04}.. {717544800 14400 0 +04}.. {733269600 18000 1 +04}.. {74899440
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):180
                                                                                                                                                                                                                                                          Entropy (8bit):4.958543249401788
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8VLYO5YFfXHAIgN8ELYOJARL/2WFKeHKLNM0WFKELt:SlSWB9vsM3y1LePHAIgKELtAN/2wKTNg
                                                                                                                                                                                                                                                          MD5:EBF01E229CC41EB8B27650A3D668EDC1
                                                                                                                                                                                                                                                          SHA1:33E1B252C1B45EAE326FCF8CC7C80C78A46F7E8D
                                                                                                                                                                                                                                                          SHA-256:DCEE88876D00396918F43DECA421B6C9B02F84B5866A2CE16E641B814B390A9F
                                                                                                                                                                                                                                                          SHA-512:80840600F37A256B8FD9933760FBAE7C13DE1E24EFD970E47BE8DEC731DFABF6D6FB76999BEEC775FF8C8B8719E94788ED7EEB04376A34C827ACB443F720F7E3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Bangkok)]} {.. LoadTimeZoneFile Asia/Bangkok..}..set TZData(:Asia/Phnom_Penh) $TZData(:Asia/Bangkok)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):369
                                                                                                                                                                                                                                                          Entropy (8bit):4.492596995768464
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wKT5PDm2OHUeoH99xV/1kc5k/MVSSFFCLkvScH+dMVSSFL1CnF4mMz:MB862L5bmdHFCRV/6c5kMxGLkHHaMxFn
                                                                                                                                                                                                                                                          MD5:9ADB1A9E41A143A06116E24EA0A53D90
                                                                                                                                                                                                                                                          SHA1:6E50B549E1A705C0090BD5EDE26F7DED78CDF71A
                                                                                                                                                                                                                                                          SHA-256:AC8370AEDF5FE3FE1E80710CE117DEE23815BE377D418E4B4F3259A1930E8DBF
                                                                                                                                                                                                                                                          SHA-512:92790B20B960AC518AB2E18F902C6E0BA887F268909F5571CAC1068F5E719CCF6943AE6902DA1B683E170658B5E7BE06C6A187C1C0A652DD052D5BD0B2A7B84D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Pontianak) {.. {-9223372036854775808 26240 0 LMT}.. {-1946186240 26240 0 PMT}.. {-1172906240 27000 0 +0730}.. {-881220600 32400 0 +09}.. {-766054800 27000 0 +0730}.. {-683883000 28800 0 +08}.. {-620812800 27000 0 +0730}.. {-189415800 28800 0 WITA}.. {567964800 25200 0 WIB}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):273
                                                                                                                                                                                                                                                          Entropy (8bit):4.709411633376997
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wK8cE4SDm2OHnNoH9Aw8vmVuT0vjLtcjviov:MB8620cExmdHnNCGv2Ezv
                                                                                                                                                                                                                                                          MD5:727BBC1A1662B500F616F544A484F213
                                                                                                                                                                                                                                                          SHA1:93C1D902D9D4AA4197C7D16C61FB784AC01D0DE5
                                                                                                                                                                                                                                                          SHA-256:29BA17F756F5C0BBA30FEBF44E620504D04921C832BD1CB56E1B60EF288B57DF
                                                                                                                                                                                                                                                          SHA-512:C3C91E2F180109FF33E6491722F679A1B8DCE8CD31DE006D7FF2CBE270C008E927507C953641D28EE77D139BBEA54DEA1B7DBD6C30B208DDAB1B58756C32AC02
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Pyongyang) {.. {-9223372036854775808 30180 0 LMT}.. {-1948782180 30600 0 KST}.. {-1830414600 32400 0 JST}.. {-768646800 32400 0 KST}.. {1439564400 30600 0 KST}.. {1525446000 32400 0 KST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):176
                                                                                                                                                                                                                                                          Entropy (8bit):4.851251407399968
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2WFKK3ovXMXGm2OHPFV4YoHsQKb3VvVsRYovFFF3FRVGsWr:SlSWB9eg/2wKK3yXDm2OHoYoHxcvSNFS
                                                                                                                                                                                                                                                          MD5:CBA9635133F88AD3B27E23B95430C27C
                                                                                                                                                                                                                                                          SHA1:5E41232EC03BBC71B522F58CB2D05E6BFFFF1A75
                                                                                                                                                                                                                                                          SHA-256:18CCA69F933795CE3F7DB31506EFC063E6CE1DFDCAB32AA387C398456D7F7E1F
                                                                                                                                                                                                                                                          SHA-512:D7C43F1F9ADA54C914ADB3CB2C9063EB7044089CFC7755ACFD08828CDEBA3C116AE2BE916ABE5D561E63699B921BC52636DD0BBC2C4304F813616D320D7DDAAF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Qatar) {.. {-9223372036854775808 12368 0 LMT}.. {-1577935568 14400 0 +04}.. {76190400 10800 0 +03}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1698
                                                                                                                                                                                                                                                          Entropy (8bit):3.7252424912274966
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5DwvalvNhQQvmRKqv0fvzQIovWdvEGvDaDvs5vZlovKWyvNSvTqvIQvyovklvqQ4:BMaBNKs6b03zB0WJEuDa7sFZiKWaN6Tk
                                                                                                                                                                                                                                                          MD5:52E2636EA6360DA255DBB7921A03F664
                                                                                                                                                                                                                                                          SHA1:92438112D9F85B02805CDBBE45E47CF86CAB6610
                                                                                                                                                                                                                                                          SHA-256:9981882BBF0DEC7C2ED44BA0EB9BAA64FB13F635BD8BD19D1520ED09460CC856
                                                                                                                                                                                                                                                          SHA-512:2984B1370B0755B235DFE46978DD426DAF458D1FBFAF0792176DFD3F45121D0E353D3EF4D381EE8E76C135528A7EE4CCAD109B0CF21812A1E06D7A681697EE3B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Qostanay) {.. {-9223372036854775808 15268 0 LMT}.. {-1441167268 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {7489
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1670
                                                                                                                                                                                                                                                          Entropy (8bit):3.734572151642808
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5NvalvNhQQvmRKqv0fvzQIovWdvEGvDaDvs5vZlovKWgvNSvTqvIQvyovklvqQX0:TaBNKs6b03zB0WJEuDa7sFZiKWcN6Tir
                                                                                                                                                                                                                                                          MD5:026EC6E479EC006C4398288362254680
                                                                                                                                                                                                                                                          SHA1:24AD03DD21DA394B3423D27211955BFD694F8E73
                                                                                                                                                                                                                                                          SHA-256:CD6B067AA3EF6935B4E89CA36E6A03FCB97F1E0EE61A7B5D46C06BF4DE140774
                                                                                                                                                                                                                                                          SHA-512:023AC55E118F13A31CE996C7BA155C90D47DEB6C223EEB3C0EE7B702871FF0CCA13CDF61D65FDDABE41B888CD7A74274AA5730059CC5688F8ED4DDBF8FE4ECA4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Qyzylorda) {.. {-9223372036854775808 15712 0 LMT}.. {-1441167712 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {701812800 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990800 18000 0 +05}.. {764
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):174
                                                                                                                                                                                                                                                          Entropy (8bit):4.812955128020714
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8nv3vXHAIgNnDA6RL/2WFK02KQMFfh4WFKsyn:SlSWB9vsM3yHvPHAIg15N/2wK0GEJ4wy
                                                                                                                                                                                                                                                          MD5:BD3F294F1EDDD21467E980C9F5A0E7DE
                                                                                                                                                                                                                                                          SHA1:11A3FC3E4489C18BDF9BFFB4C44615559D9DD99D
                                                                                                                                                                                                                                                          SHA-256:E4D2C38D8E7377A528291A88129CDAC40CA4D40A5F1CD8ADB98228527556906E
                                                                                                                                                                                                                                                          SHA-512:FA5FD600627793EABB83C1066BE246A47BCCE1FC57830596B9C0CDE8901B949AF178ABDE876C3B73CC3751312E8A4C03C390888B0B5A9669F511344143F83073
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Yangon)]} {.. LoadTimeZoneFile Asia/Yangon..}..set TZData(:Asia/Rangoon) $TZData(:Asia/Yangon)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):148
                                                                                                                                                                                                                                                          Entropy (8bit):4.973311159904374
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2WFK814PMXGm2OHFukeoHqUi9VssWYcv:SlSWB9eg/2wK81GDm2OHF7eoHvi9V1Wr
                                                                                                                                                                                                                                                          MD5:AD3236CFF141732831732357AB181EE3
                                                                                                                                                                                                                                                          SHA1:EAF51A63898A2048EA5FBE9BA4C001EEE37FFDB2
                                                                                                                                                                                                                                                          SHA-256:411E31D09FFA48E44169C42661AE2F7FC142460BCAA216837D8C4740983CA7BD
                                                                                                                                                                                                                                                          SHA-512:6CA2D89C02568580786BE98A863453ADCF4D21CAC52E5B44C4F7A05E76D29AEB3E28E353D6FB758BB553DBC8F35389462B388F61E94C68F5DB50A3E8C429336D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Riyadh) {.. {-9223372036854775808 11212 0 LMT}.. {-719636812 10800 0 +03}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):188
                                                                                                                                                                                                                                                          Entropy (8bit):4.946090704619887
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8I65eV5XHAIgN2h6560ARL/2WFKwJ6h4WFK365ey:SlSWB9vsM3yJAVJHAIgA4k0AN/2wKl4i
                                                                                                                                                                                                                                                          MD5:0766480A295525EE5D65F1ED32094858
                                                                                                                                                                                                                                                          SHA1:7A2D68E1009DDD809A4A700931456C617DCD343A
                                                                                                                                                                                                                                                          SHA-256:C695981A0DF691C3F4509999FBC52858ADC75024CCCBDEFBE1094FED17E809E4
                                                                                                                                                                                                                                                          SHA-512:A21536FB61A64E953E8D6414FF0AEF1BC7E68A33C5DCF7090517A91FC449B96A93A4FBDF2C00682540D1193FDB29603349F5BDB455FD90045FDBCA61247A9860
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Ho_Chi_Minh)]} {.. LoadTimeZoneFile Asia/Ho_Chi_Minh..}..set TZData(:Asia/Saigon) $TZData(:Asia/Ho_Chi_Minh)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2117
                                                                                                                                                                                                                                                          Entropy (8bit):3.7276904131666577
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5q+3Vv+0j6lua2Gg/3gO8UoflcXRDhUBAc+:YxIa2GOT8tiXBC6c+
                                                                                                                                                                                                                                                          MD5:295D51B8FBBE890C97637687B8F32322
                                                                                                                                                                                                                                                          SHA1:7BB72B0EC783898DDF625D275E3BBB964D1693FB
                                                                                                                                                                                                                                                          SHA-256:D7D0EA5CEF908442AB0D777A4B097BED18540CD5280FF63F33DD989E27E72908
                                                                                                                                                                                                                                                          SHA-512:9B3E3BA01EAE38A00B0EE8A8FB17191CB4ED2EE9E46AE06403BA8C1193804764C86599840DC03E0C6A631456E1BE2BC560BDF6CF0450068EF78A6E494041326C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Sakhalin) {.. {-9223372036854775808 34248 0 LMT}.. {-2031039048 32400 0 +09}.. {-768560400 39600 0 +12}.. {354891600 43200 1 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}.. {76469
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):879
                                                                                                                                                                                                                                                          Entropy (8bit):3.9460497720710506
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5t8eZd7QvalvNhQQvmRKqvzQfv7PQIovWxrvEGvDWdDvs5v/RlovKT10Sv6r:5MvalvNhQQvmRKqv0fvzQIovWdvEGvDO
                                                                                                                                                                                                                                                          MD5:10A758996B0DF756E520541BEA9B7D75
                                                                                                                                                                                                                                                          SHA1:137E5FD4E00CFA4B3939EF11868862B7F93D87CD
                                                                                                                                                                                                                                                          SHA-256:35E4B905723891281D9A6A0A1FD3760A3A48136E1419C686BE31ACE83BF7AA9D
                                                                                                                                                                                                                                                          SHA-512:7E32661731EAB2ED8C387533ACCB4853F5B6225BAC11E93247E7B06D7AA856E6A665F63718BFE395CFD00F80A4C16789D7097FFA8DAD88B1D707BF9C155C1D4C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Samarkand) {.. {-9223372036854775808 16073 0 LMT}.. {-1441168073 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 21600 1 +05}.. {686091600 18000 0 +05}.. {694206000 18000 0 +05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):985
                                                                                                                                                                                                                                                          Entropy (8bit):4.121802167517286
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5AemgvHzF+zg2c+z3NGmJhIUfqII8yHg/zoD:5F/nfWUBISHg/G
                                                                                                                                                                                                                                                          MD5:A1DE6975DEA70D7241B5B3C43E1EA3AA
                                                                                                                                                                                                                                                          SHA1:35EE563A2BCA77C761F7E878997763EA8D258040
                                                                                                                                                                                                                                                          SHA-256:C4F82C94650572FE4D03BC1FE54CED8F4BF55DFBEE855D52DE3EA6378240AF93
                                                                                                                                                                                                                                                          SHA-512:1639B0609115DBEA6A381986A732A5CA1523952AEF84843B4D714D5B2FF40B16C4166D8D60D31D4FC2C2BA34DED1F6DB39474336195603562265BDBF71687696
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Seoul) {.. {-9223372036854775808 30472 0 LMT}.. {-1948782472 30600 0 KST}.. {-1830414600 32400 0 JST}.. {-767350800 32400 0 KST}.. {-681210000 36000 1 KDT}.. {-672228000 32400 0 KST}.. {-654771600 36000 1 KDT}.. {-640864800 32400 0 KST}.. {-623408400 36000 1 KDT}.. {-609415200 32400 0 KST}.. {-588848400 36000 1 KDT}.. {-577965600 32400 0 KST}.. {-498128400 30600 0 KST}.. {-462702600 34200 1 KDT}.. {-451733400 30600 0 KST}.. {-429784200 34200 1 KDT}.. {-418296600 30600 0 KST}.. {-399544200 34200 1 KDT}.. {-387451800 30600 0 KST}.. {-368094600 34200 1 KDT}.. {-356002200 30600 0 KST}.. {-336645000 34200 1 KDT}.. {-324552600 30600 0 KST}.. {-305195400 34200 1 KDT}.. {-293103000 30600 0 KST}.. {-264933000 32400 0 KST}.. {547578000 36000 1 KDT}.. {560883600 32400 0 KST}.. {579027600 36000 1 KDT}.. {592333200 32400 0 KST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):981
                                                                                                                                                                                                                                                          Entropy (8bit):4.16042656890735
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5Te3vvZJzHjwH6kHp7FH32AzHjZBHNHlQHuHxmHUjH6zHj2HBHeC:5ovZZO7lLpT24
                                                                                                                                                                                                                                                          MD5:A266AA43A84FD5E4890BC77AA4E240D0
                                                                                                                                                                                                                                                          SHA1:CD88C5D451CD7D3F50C9B36FDD47C84D20377441
                                                                                                                                                                                                                                                          SHA-256:3AABB42D9EFE95D906B7F34640E7815919A1A20979EBB6EC1527FCAA3B09B22A
                                                                                                                                                                                                                                                          SHA-512:13AE48F58C9AF24002F0FE4F28BF96B10EE0ED293E0DE9D29BCEBAAE102B2EA818F42CA4069544A254C95444A48604EC57E6AB2BEBDA4B5E72C82B49E61AD0A0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Shanghai) {.. {-9223372036854775808 29143 0 LMT}.. {-2177481943 28800 0 CST}.. {-1600675200 32400 1 CDT}.. {-1585904400 28800 0 CST}.. {-933667200 32400 1 CDT}.. {-922093200 28800 0 CST}.. {-908870400 32400 1 CDT}.. {-888829200 28800 0 CST}.. {-881049600 32400 1 CDT}.. {-767869200 28800 0 CST}.. {-745833600 32400 1 CDT}.. {-733827600 28800 0 CST}.. {-716889600 32400 1 CDT}.. {-699613200 28800 0 CST}.. {-683884800 32400 1 CDT}.. {-670669200 28800 0 CST}.. {-652348800 32400 1 CDT}.. {-650016000 28800 0 CST}.. {515527200 32400 1 CDT}.. {527014800 28800 0 CST}.. {545162400 32400 1 CDT}.. {558464400 28800 0 CST}.. {577216800 32400 1 CDT}.. {589914000 28800 0 CST}.. {608666400 32400 1 CDT}.. {621968400 28800 0 CST}.. {640116000 32400 1 CDT}.. {653418000 28800 0 CST}.. {671565600 32400 1 CDT}.. {684867600 28800 0 CST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):372
                                                                                                                                                                                                                                                          Entropy (8bit):4.436676898144829
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wKfbSDm2OHxdoHvm5vWOb/MVSYyF/3MesF5XJSx0dMVSSFF8kvScHy:MB862nbGmdHDCvsvDTMsF/CFDMx/HHbO
                                                                                                                                                                                                                                                          MD5:008EED394614C7082478686F19D26707
                                                                                                                                                                                                                                                          SHA1:70313A704D225D1008CCD7A8A5D86931E12534CA
                                                                                                                                                                                                                                                          SHA-256:FDBD970E6835279A01E2D343D03994E32AC94A10EBDA88AD6942CBEAABB19136
                                                                                                                                                                                                                                                          SHA-512:786363D146630B76506D72071805D9C1C8CA825C11513EA6A6EF5D3373F39C42CE46DD675A3F15376D870EFAE2EDD1A4919AA226B756E80AC98430CC1C72D8ED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Singapore) {.. {-9223372036854775808 24925 0 LMT}.. {-2177477725 24925 0 SMT}.. {-2038200925 25200 0 +07}.. {-1167634800 26400 1 +0720}.. {-1073028000 26400 0 +0720}.. {-894180000 27000 0 +0730}.. {-879665400 32400 0 +09}.. {-767005200 27000 0 +0730}.. {378662400 28800 0 +08}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2064
                                                                                                                                                                                                                                                          Entropy (8bit):3.7913177223006698
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5HJeidmbv+OC+jsuwltZQONEa2Ggf3augO8UoxLyHdX/CX6bW4Bv/7NKxwy:5HSv+0j6lua2Gg/3gO8UoOZU2Wc/pKf
                                                                                                                                                                                                                                                          MD5:B4FA38E884A85F6BD47C8BB02BB0500C
                                                                                                                                                                                                                                                          SHA1:1DD135B79CC0D81C048D7B2C6BE0CF71171DD19E
                                                                                                                                                                                                                                                          SHA-256:705D6D8360C2DCD51E909E39E1910FE876145220D151031612DA36B247207395
                                                                                                                                                                                                                                                          SHA-512:2D32AAAF1BCC865B5F2810BFE0FB82BE98140BB5F2ECA1DA7FD148A3074DA127B81242F17B8BA9C9E259B61CBB123FD1513CCE6A85C8D7679ADFC0D689B552BB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Srednekolymsk) {.. {-9223372036854775808 36892 0 LMT}.. {-1441188892 36000 0 +10}.. {-1247565600 39600 0 +12}.. {354891600 43200 1 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1344
                                                                                                                                                                                                                                                          Entropy (8bit):4.062084847879695
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5X2eIvZPzGzHjZBHNHlQHKn3HnHNd9HiHkHBHaHLHMtyH9Qm+zHFOzHZ32HZvHiR:5Xi1ypBvt1mwO3Kq46T
                                                                                                                                                                                                                                                          MD5:AECA800C8F2A679D0B19E5BB90AFD858
                                                                                                                                                                                                                                                          SHA1:2C7DCEB709F9A4312C511971FE1E6A9DC1FBD0E8
                                                                                                                                                                                                                                                          SHA-256:389C9D3EE2970665D0D8C5CB61B8B790C5FBDDC0DF0BF2B9753046F5953A477F
                                                                                                                                                                                                                                                          SHA-512:C2D6BB4FEB5848D0704647D26F94C0BD8CD7E834AA2187EC9C877E80157E9CC225BBA3BECEE0148894C8639105D292AB50EE95830992BF357C632ACF001E020F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Taipei) {.. {-9223372036854775808 29160 0 LMT}.. {-2335248360 28800 0 CST}.. {-1017820800 32400 0 JST}.. {-766224000 28800 0 CST}.. {-745833600 32400 1 CDT}.. {-733827600 28800 0 CST}.. {-716889600 32400 1 CDT}.. {-699613200 28800 0 CST}.. {-683884800 32400 1 CDT}.. {-670669200 28800 0 CST}.. {-652348800 32400 1 CDT}.. {-639133200 28800 0 CST}.. {-620812800 32400 1 CDT}.. {-607597200 28800 0 CST}.. {-589276800 32400 1 CDT}.. {-576061200 28800 0 CST}.. {-562924800 32400 1 CDT}.. {-541760400 28800 0 CST}.. {-528710400 32400 1 CDT}.. {-510224400 28800 0 CST}.. {-497174400 32400 1 CDT}.. {-478688400 28800 0 CST}.. {-465638400 32400 1 CDT}.. {-449830800 28800 0 CST}.. {-434016000 32400 1 CDT}.. {-418208400 28800 0 CST}.. {-402480000 32400 1 CDT}.. {-386672400 28800 0 CST}.. {-370944000 32400 1 CDT}.. {-355136400 28800 0 CST}.. {-3394080
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):878
                                                                                                                                                                                                                                                          Entropy (8bit):3.9280321712564845
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5geQqdNRvOt81FCuLqecDngO6jPvTpYy5T4TXvKT10Sv6r:5+EvdJqxiF0rvK50Sv6r
                                                                                                                                                                                                                                                          MD5:DB59DB8E401E12917B7367D5604D3DE6
                                                                                                                                                                                                                                                          SHA1:7CC7C5C1DB551BD381B833C81746201D36BC59A9
                                                                                                                                                                                                                                                          SHA-256:4445F3F892C7267A6867009CC1A3F0B0548D0240408375A9D15360B28993C2A9
                                                                                                                                                                                                                                                          SHA-512:2C7AE63C408A9F06F973AAC16845E1DBE92D15A421BBBE420914F21155AD5E57CD058D7E4427E43185E023D2FF475EBF9D74003ECEF004FF4E5F9D5681ADFB80
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tashkent) {.. {-9223372036854775808 16631 0 LMT}.. {-1441168631 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 18000 0 +05}.. {670366800 21600 1 +05}.. {686091600 18000 0 +05}.. {694206000 18000 0 +05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1729
                                                                                                                                                                                                                                                          Entropy (8bit):3.6815162494646034
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5yBeqvIdZlykbocXcwJUE5iu8JmFebARoc9lVNk7/9bq8dq16b3C9UPqUsx9Ul4N:5MmsUf8mFpNWFnytO6VnYK
                                                                                                                                                                                                                                                          MD5:C376C9ED66F6CC011E063D3E8E0DCED1
                                                                                                                                                                                                                                                          SHA1:13C6345F8CB0EC79FE7C78B156C5737BCB66E49E
                                                                                                                                                                                                                                                          SHA-256:B637BB0E49144C717E99E93540CB2C4D3695D63B91FE42547F2F0AA006498693
                                                                                                                                                                                                                                                          SHA-512:FD60192CBEDC91C5D6B3B5E6F19DEDCAE14DCF48DCAE6D4865A8F0BBDC01CBF8DAAE92C4C46C353AF5B3EEE36CCC87B23F193DDF221132F5404C42507B708364
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tbilisi) {.. {-9223372036854775808 10751 0 LMT}.. {-2840151551 10751 0 TBMT}.. {-1441162751 10800 0 +03}.. {-405140400 14400 0 +04}.. {354916800 18000 1 +04}.. {370724400 14400 0 +04}.. {386452800 18000 1 +04}.. {402260400 14400 0 +04}.. {417988800 18000 1 +04}.. {433796400 14400 0 +04}.. {449611200 18000 1 +04}.. {465343200 14400 0 +04}.. {481068000 18000 1 +04}.. {496792800 14400 0 +04}.. {512517600 18000 1 +04}.. {528242400 14400 0 +04}.. {543967200 18000 1 +04}.. {559692000 14400 0 +04}.. {575416800 18000 1 +04}.. {591141600 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 10800 0 +03}.. {670374000 14400 1 +03}.. {686098800 10800 0 +03}.. {694213200 10800 0 +03}.. {701816400 14400 1 +03}.. {717537600 10800 0 +03}.. {733266000 14400 1 +03}.. {748
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2354
                                                                                                                                                                                                                                                          Entropy (8bit):3.666553647637418
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5Z2eendFalxbr1p4USUcESUUxSuEqzSUUongA3jJW3eY37U8uuZrc3cNWH1/ANzx:54G9SOSWzx1qcK83kv3OR0xV1ox
                                                                                                                                                                                                                                                          MD5:A7A174A14E51E0ACD7092D2A5AA50F99
                                                                                                                                                                                                                                                          SHA1:69ADDDDB68084B90819AD49A5230D5B0E1A9CD85
                                                                                                                                                                                                                                                          SHA-256:25870503A8A679DA13B98117BD473EAA0C79B094B85D3AD50629FF0946D5EACE
                                                                                                                                                                                                                                                          SHA-512:1ECFB558B13C94BDC848E7BBBB0CA1BB854BB12E112EBF306045EC14F00CE3E3C2DA51EBA8AF2D63C95D71B945647C3D9E9881158FE128DEBE940A742C4BFEB1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tehran) {.. {-9223372036854775808 12344 0 LMT}.. {-1704165944 12344 0 TMT}.. {-1090466744 12600 0 +0330}.. {227820600 16200 1 +0330}.. {246227400 14400 0 +04}.. {259617600 18000 1 +04}.. {271108800 14400 0 +04}.. {283982400 12600 0 +0330}.. {296598600 16200 1 +0330}.. {306531000 12600 0 +0330}.. {322432200 16200 1 +0330}.. {338499000 12600 0 +0330}.. {673216200 16200 1 +0330}.. {685481400 12600 0 +0330}.. {701209800 16200 1 +0330}.. {717103800 12600 0 +0330}.. {732745800 16200 1 +0330}.. {748639800 12600 0 +0330}.. {764281800 16200 1 +0330}.. {780175800 12600 0 +0330}.. {795817800 16200 1 +0330}.. {811711800 12600 0 +0330}.. {827353800 16200 1 +0330}.. {843247800 12600 0 +0330}.. {858976200 16200 1 +0330}.. {874870200 12600 0 +0330}.. {890512200 16200 1 +0330}.. {906406200 12600 0 +0330}.. {922048200 16200 1 +0330}.. {937942200 12600
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.876713308636272
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq85zFFfXHAIgN0AzFFVHRL/2WFK+TT52WFKYzFgn:SlSWB9vsM3yZbPHAIgCAXRN/2wKsswKR
                                                                                                                                                                                                                                                          MD5:40B15013485EE2138A3DCB915F9121E7
                                                                                                                                                                                                                                                          SHA1:3ADBE38686C7CA1FDE3DDD12BE908F39BFD1E228
                                                                                                                                                                                                                                                          SHA-256:07537A30E6236D9E334DAFD5C4D352D25FDEF95D6DC7496F5D93EFAB74D9EBB1
                                                                                                                                                                                                                                                          SHA-512:DA3B7B44B3BEF07CA8AA5253BF684A838181D8A15D7CCF0447A6B5F5BAE28D155CF65BCFB6286EB36C0B9F4FDD1FE862A3297ADB6FC33532B9F766334283D725
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Jerusalem)]} {.. LoadTimeZoneFile Asia/Jerusalem..}..set TZData(:Asia/Tel_Aviv) $TZData(:Asia/Jerusalem)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):176
                                                                                                                                                                                                                                                          Entropy (8bit):4.906503135441824
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8kNZ4WXHAIgNqFNKARL/2WFK9Z752WFKvNZovn:SlSWB9vsM3ykZ42HAIgc3KAN/2wKf126
                                                                                                                                                                                                                                                          MD5:081862B6FB33389BEC9B0E6B500AA342
                                                                                                                                                                                                                                                          SHA1:AF9467BB87C4C28921DF62A87B81223052F9FF4A
                                                                                                                                                                                                                                                          SHA-256:37459C17B59639DF62B3F3943751902CE6AAF1F11B7630069DB45052EBEFB5B9
                                                                                                                                                                                                                                                          SHA-512:CAF6F1C928528C4471229A2EF2944623545626532986628E6CE38884535286A0B38BA88C1A295E8B11322475D6BFAC61BF89786A76330C1A0C729339A3532BAF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Thimphu)]} {.. LoadTimeZoneFile Asia/Thimphu..}..set TZData(:Asia/Thimbu) $TZData(:Asia/Thimphu)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):180
                                                                                                                                                                                                                                                          Entropy (8bit):4.887493603495978
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2WFKvNZJMXGm2OHEQUTFnoHqVaJKuc/v6Q61V9gmZVFSTVV:SlSWB9eg/2wKVZJDm2OHEfnoHDKuc/SC
                                                                                                                                                                                                                                                          MD5:F239452984CCA9F23E97A880652C39E6
                                                                                                                                                                                                                                                          SHA1:52D25282D03B79960F152D21E7492EE26DAEBBAA
                                                                                                                                                                                                                                                          SHA-256:B797C74E3840298C3CD8149FC8AA4BCE839EFE79E7C3310986FF23C965607929
                                                                                                                                                                                                                                                          SHA-512:1044BEDAE04FCA7BD62937AFCE70F6C447583A90DD1596C3029A64A8251E3F73C106F4D940548DD38E895D67FEFDCD196B257E11437DEB399085EE80C345AA50
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Thimphu) {.. {-9223372036854775808 21516 0 LMT}.. {-706341516 19800 0 +0530}.. {560025000 21600 0 +06}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):388
                                                                                                                                                                                                                                                          Entropy (8bit):4.470556147950505
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862ymdHOx5CvAoK3zoiIxtoFDIe+zT0agbov:5yeOCvARzzCOVa/gby
                                                                                                                                                                                                                                                          MD5:3CCC15B63A882DB1B7459A51CD1C8165
                                                                                                                                                                                                                                                          SHA1:77A3EFE6E4EE524B9EC6F51593DD7521FD7B8DAD
                                                                                                                                                                                                                                                          SHA-256:3DA522FA88541A375D53F30A0B62DC4A305FA0315FEE534B7998C9E0A239450A
                                                                                                                                                                                                                                                          SHA-512:15238E96DABAB5D2B9FFD25B3F50417ED32205FA69239D6F6B28DA97A378D669FD409164964D0DD2A5B1D795C8F60E8D4EB15924046348C3D6010646A536E07C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tokyo) {.. {-9223372036854775808 33539 0 LMT}.. {-2587712400 32400 0 JST}.. {-683802000 36000 1 JDT}.. {-672310800 32400 0 JST}.. {-654771600 36000 1 JDT}.. {-640861200 32400 0 JST}.. {-620298000 36000 1 JDT}.. {-609411600 32400 0 JST}.. {-588848400 36000 1 JDT}.. {-577962000 32400 0 JST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2116
                                                                                                                                                                                                                                                          Entropy (8bit):3.695316005718174
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5CeLz/XJfsFN/3sFrOksF/sF7IyksF7FRZsFLsFTsFcsFk73sFK/XCFKTipnFEno:5H040yVRB7VfXucydm4IqtTTDOS
                                                                                                                                                                                                                                                          MD5:E95DE93CBCE72C5E02D7ECFE94C96308
                                                                                                                                                                                                                                                          SHA1:59A49EBFE544D97545BADFEFE716BB5659C64C20
                                                                                                                                                                                                                                                          SHA-256:6B64A01D0F0B5EC7A1410C3BD6883BA7CC133E9F073D40E8BFECE037E3A3FA24
                                                                                                                                                                                                                                                          SHA-512:9E33DC9C1C6D60F3226263C484AF46A14AAB31F838516A0D69BA08F8F416EF10D09697E8D7ABAC1CE1F5BCE8AB0C2635D99FBE70C89ECC268DED0DCE89E67466
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tomsk) {.. {-9223372036854775808 20391 0 LMT}.. {-1578807591 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {7647084
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):186
                                                                                                                                                                                                                                                          Entropy (8bit):4.897140749162557
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8pYFfXHAIgNzGRRL/2WFKPQOrFJ4WFKov:SlSWB9vsM3yWFPHAIg0RN/2wKPQOrFJD
                                                                                                                                                                                                                                                          MD5:F6AE33D706C36FDD8A21F44AD59F5607
                                                                                                                                                                                                                                                          SHA1:94D6EC7A437249AEBE2FA4AF8AFB029A620368C0
                                                                                                                                                                                                                                                          SHA-256:732751845ACEDBFFD3C6170F4B94CB20B25BFDCFCC5EEA19F4BE439F5C5B573A
                                                                                                                                                                                                                                                          SHA-512:2314AB2B154887842211C9A570BC1323D9B4375FF60C96296835DB001E8A277CA62D40B8562BC34EDDF281D96D5325640B79F7907558C6E0319C7D2A76BE239C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Makassar)]} {.. LoadTimeZoneFile Asia/Makassar..}..set TZData(:Asia/Ujung_Pandang) $TZData(:Asia/Makassar)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1590
                                                                                                                                                                                                                                                          Entropy (8bit):3.7728141273024374
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5IerIvusF7cCGK6zoCjZte3kzMjsBw0oZzlL98oysHqGzJvqE+ksabzdX+YjL:5VujmUCei46oljFC67
                                                                                                                                                                                                                                                          MD5:A4647294401D2B54ABAA8E509BF05A6F
                                                                                                                                                                                                                                                          SHA1:BF804CC38996D7715E3BA9BAD715D7ADBED781B9
                                                                                                                                                                                                                                                          SHA-256:A56A26981163A717CF388A423CFE7A2BAD1BE8652BE2E338670CBC0C0A70E5E9
                                                                                                                                                                                                                                                          SHA-512:B43157FABDE016FA6636CAB7B06CC1DEA53526B42FB46BB41DC4B7E48188D191C325BEF0D170B125E885F321C4316746A8D478D798828E2DC4A51C71DA4A610C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ulaanbaatar) {.. {-9223372036854775808 25652 0 LMT}.. {-2032931252 25200 0 +07}.. {252435600 28800 0 +08}.. {417974400 32400 1 +08}.. {433782000 28800 0 +08}.. {449596800 32400 1 +08}.. {465318000 28800 0 +08}.. {481046400 32400 1 +08}.. {496767600 28800 0 +08}.. {512496000 32400 1 +08}.. {528217200 28800 0 +08}.. {543945600 32400 1 +08}.. {559666800 28800 0 +08}.. {575395200 32400 1 +08}.. {591116400 28800 0 +08}.. {606844800 32400 1 +08}.. {622566000 28800 0 +08}.. {638294400 32400 1 +08}.. {654620400 28800 0 +08}.. {670348800 32400 1 +08}.. {686070000 28800 0 +08}.. {701798400 32400 1 +08}.. {717519600 28800 0 +08}.. {733248000 32400 1 +08}.. {748969200 28800 0 +08}.. {764697600 32400 1 +08}.. {780418800 28800 0 +08}.. {796147200 32400 1 +08}.. {811868400 28800 0 +08}.. {828201600 32400 1 +08}.. {843922800 28800 0 +08}.. {859
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):192
                                                                                                                                                                                                                                                          Entropy (8bit):4.728285544456033
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8TcXkXHAIgNrfcXORL/2WFKhrMEBQWFKucXB:SlSWB9vsM3yXHAIgTN/2wKhrMEewKX
                                                                                                                                                                                                                                                          MD5:D2EAEA6182FB332CAA707B523F6C8A9D
                                                                                                                                                                                                                                                          SHA1:3BFC654E2B3BCF902AF41AEEC46772C84FFF3890
                                                                                                                                                                                                                                                          SHA-256:D17FDAF17B3DAC3A1310E2332F61585598185E64CED799ABD68249EB5B698591
                                                                                                                                                                                                                                                          SHA-512:E16BEE28BFE3AFFFE6F0025C09D0D65001F38D5045AAB1B554E4D3A66A88273F985B7BAA11F8D26E76E5ABC9F559E3E4B794CC939AAD5FF012A5A47924D08CB3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Ulaanbaatar)]} {.. LoadTimeZoneFile Asia/Ulaanbaatar..}..set TZData(:Asia/Ulan_Bator) $TZData(:Asia/Ulaanbaatar)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):149
                                                                                                                                                                                                                                                          Entropy (8bit):5.006390440264841
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2WFKjhfMXGm2OHEVPoHsWA0GVFSTVVn:SlSWB9eg/2wKjJDm2OHEVPoH3A0CUX
                                                                                                                                                                                                                                                          MD5:D6245CAAEC9BA2579F4CEFFF196A9369
                                                                                                                                                                                                                                                          SHA1:4D182953F2CEEFF3583265F977B14F40C1A2FB43
                                                                                                                                                                                                                                                          SHA-256:C445B8030DEDDDED0AFF5CC692CC323B63BE8C14BBD42DC3FDE90AD4F9D14785
                                                                                                                                                                                                                                                          SHA-512:A32C477B6FAA79247907D1C4E2DF400B05AF4B529277C4CE12B33097872311E3F579115DC8CBA93DAC936928FD574414F3473A9CB7C8E85AB57CCA57489B60F8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Urumqi) {.. {-9223372036854775808 21020 0 LMT}.. {-1325483420 21600 0 +06}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2058
                                                                                                                                                                                                                                                          Entropy (8bit):3.773734429231407
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5petrlfgLv+OC+jsuwltZQONEa2Ggf3augO8UoxLyHdX/CX6bW4Bv/7NKxKG:5Ysv+0j6lua2Gg/3gO8UoOZU2Wc/pKF
                                                                                                                                                                                                                                                          MD5:5ADD78E4AFCBA913D078A8790861A2DE
                                                                                                                                                                                                                                                          SHA1:BB63A762D5D76C0FD3CB9AB2BCDE95718E1C99EB
                                                                                                                                                                                                                                                          SHA-256:9D639C0FC69B3BEEBC96969092F9590EB48E7946E901B225BF245E165973B9A8
                                                                                                                                                                                                                                                          SHA-512:7C2418FD1F96F101B83E2ABDF2551405C6E429DBBF30A2FA7CD2477E2CE1CEEBB790C51B28AEFF043BA7A7A914CEF3C812668058D69225B9FE9475C56508453D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ust-Nera) {.. {-9223372036854775808 34374 0 LMT}.. {-1579426374 28800 0 +08}.. {354898800 43200 0 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}.. {764694000 43200 1 +12}.. {780418
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):179
                                                                                                                                                                                                                                                          Entropy (8bit):4.858039387006872
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8VLYO5YFfXHAIgN8ELYOJARL/2WFKgTjEHp4WFKELt:SlSWB9vsM3y1LePHAIgKELtAN/2wKgsX
                                                                                                                                                                                                                                                          MD5:D23A09C84A5368FBB47174BC0A460D14
                                                                                                                                                                                                                                                          SHA1:045A72FEA79C75E5F0029BD110E33A022C57DFAB
                                                                                                                                                                                                                                                          SHA-256:18F5E4FE8247F676278AC5F1912AC401DC48DF5B756D22E76FF1CFA702F88DA7
                                                                                                                                                                                                                                                          SHA-512:404EABC2FC162E18C678CED063249C7FF4C28653880EA1903CE846FD191CD1C5B61E0610736F250B79BBAC768B1AFD6B9A8824D56D74591A95D7301B47D48387
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Bangkok)]} {.. LoadTimeZoneFile Asia/Bangkok..}..set TZData(:Asia/Vientiane) $TZData(:Asia/Bangkok)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2062
                                                                                                                                                                                                                                                          Entropy (8bit):3.7094518963173035
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:56beOUYQ7FyDy3le3i96VwAmnuBNuTw6vl9O8nfipRkwhUZDAcD:56cYQBIy343dVNUIukElcXRDhUBAcD
                                                                                                                                                                                                                                                          MD5:5C0C094B088D0212182E7B944197D4FE
                                                                                                                                                                                                                                                          SHA1:CF43A511FE9CD295207DF350704462E09D4D5278
                                                                                                                                                                                                                                                          SHA-256:2558C96E25359C72F168DAC6FB3C16C54F8FD7D0724EEB1671156D4A1F42AC6C
                                                                                                                                                                                                                                                          SHA-512:5D659EBDC8C2B06C964B083ECC78B4370A4658590D83F020CD23910C44E2D8DAFE69F61E8EB569E1905E89F38CD03ABE6B92F6CE36CF0B1EE0732A7645AFA65D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Vladivostok) {.. {-9223372036854775808 31651 0 LMT}.. {-1487321251 32400 0 +09}.. {-1247562000 36000 0 +11}.. {354895200 39600 1 +11}.. {370702800 36000 0 +10}.. {386431200 39600 1 +11}.. {402238800 36000 0 +10}.. {417967200 39600 1 +11}.. {433774800 36000 0 +10}.. {449589600 39600 1 +11}.. {465321600 36000 0 +10}.. {481046400 39600 1 +11}.. {496771200 36000 0 +10}.. {512496000 39600 1 +11}.. {528220800 36000 0 +10}.. {543945600 39600 1 +11}.. {559670400 36000 0 +10}.. {575395200 39600 1 +11}.. {591120000 36000 0 +10}.. {606844800 39600 1 +11}.. {622569600 36000 0 +10}.. {638294400 39600 1 +11}.. {654624000 36000 0 +10}.. {670348800 32400 0 +10}.. {670352400 36000 1 +10}.. {686077200 32400 0 +09}.. {695754000 36000 0 +11}.. {701798400 39600 1 +11}.. {717523200 36000 0 +10}.. {733248000 39600 1 +11}.. {748972800 36000 0 +10}.. {7
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2058
                                                                                                                                                                                                                                                          Entropy (8bit):3.7081033128260934
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5h+r1gIgWH/lt0irzEzCSCItWiIrW+rDQk9CVhyFY7rRWjYuhUmgr2j:K5PhtjLiII2ZFlgm
                                                                                                                                                                                                                                                          MD5:E43E5F0EA7C4575525BAB130984DCDCC
                                                                                                                                                                                                                                                          SHA1:2D715749469FEA51A8E25D1F4F8DC4FF9178817D
                                                                                                                                                                                                                                                          SHA-256:3BEF13638C46F16435D326C675907E61BB68C8173153CED3359E983BE0E413E5
                                                                                                                                                                                                                                                          SHA-512:27954FEC865031BC363CFDE94E97B3B19836A6F777646EA4AAB12ECCAEE6D60A0C690711EA192B917AC717F94A01D1EF64BAE97DF968069CC12415971B070498
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yakutsk) {.. {-9223372036854775808 31138 0 LMT}.. {-1579423138 28800 0 +08}.. {-1247558400 32400 0 +10}.. {354898800 36000 1 +10}.. {370706400 32400 0 +09}.. {386434800 36000 1 +10}.. {402242400 32400 0 +09}.. {417970800 36000 1 +10}.. {433778400 32400 0 +09}.. {449593200 36000 1 +10}.. {465325200 32400 0 +09}.. {481050000 36000 1 +10}.. {496774800 32400 0 +09}.. {512499600 36000 1 +10}.. {528224400 32400 0 +09}.. {543949200 36000 1 +10}.. {559674000 32400 0 +09}.. {575398800 36000 1 +10}.. {591123600 32400 0 +09}.. {606848400 36000 1 +10}.. {622573200 32400 0 +09}.. {638298000 36000 1 +10}.. {654627600 32400 0 +09}.. {670352400 28800 0 +09}.. {670356000 32400 1 +09}.. {686080800 28800 0 +08}.. {695757600 32400 0 +10}.. {701802000 36000 1 +10}.. {717526800 32400 0 +09}.. {733251600 36000 1 +10}.. {748976400 32400 0 +09}.. {76470
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):244
                                                                                                                                                                                                                                                          Entropy (8bit):4.692243303623333
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2wKs5XDm2OHGVQoHvZN6FCDx+UIFDVkvScHbY/s5UIAy:MB862KTmdHGuCvZNNkkHH3Sy
                                                                                                                                                                                                                                                          MD5:D45766D30074719C9A88ACE8BB53204B
                                                                                                                                                                                                                                                          SHA1:69B333DFCCCCEB66DD0F7DC28B272BB10769B6B0
                                                                                                                                                                                                                                                          SHA-256:2526557810747E78E713AE09BC305621A80FAEECF8D441632E7825738D4C79CB
                                                                                                                                                                                                                                                          SHA-512:5255DEED72D7D13862A4D6BED7E0458C099D2EF5A1B41536CAA7C0E65A61DE8B8D1AD62AD44559F970B6613ADFB3862778D1CC99B9A05CB5BBCA7F0202B5A5B2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yangon) {.. {-9223372036854775808 23087 0 LMT}.. {-2840163887 23087 0 RMT}.. {-1577946287 23400 0 +0630}.. {-873268200 32400 0 +09}.. {-778410000 23400 0 +0630}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2095
                                                                                                                                                                                                                                                          Entropy (8bit):3.704641905144701
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:5ievNhYvm1qv7vXIovPvSvlDvtvuovKKvKcNvHvAvivBvqvvEyv8vlvEv+v4v+v+:/Nupj40H6l75FKCKcZP8qdyEaoBAWkW+
                                                                                                                                                                                                                                                          MD5:D4DABA407BB8A10E4961D1DE5D9781D1
                                                                                                                                                                                                                                                          SHA1:6933DE65336331BD90E2BEC6AEA0609B16DAEDC9
                                                                                                                                                                                                                                                          SHA-256:2C78699EFC60758B8F8D0D1DEEDFDED5E65C65EBF3082B23E60BDEA8BF8FBCFE
                                                                                                                                                                                                                                                          SHA-512:459E2187FAA66414F5CE934C335F563DFD2FA5316B86A54D1A29123A0460AFD65B7CE46629BD6A070A14CB6873A28A2F2803DE5FF4F29EA610712EB07FAD303F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yekaterinburg) {.. {-9223372036854775808 14553 0 LMT}.. {-1688270553 13505 0 PMT}.. {-1592610305 14400 0 +04}.. {-1247544000 18000 0 +06}.. {354913200 21600 1 +06}.. {370720800 18000 0 +05}.. {386449200 21600 1 +06}.. {402256800 18000 0 +05}.. {417985200 21600 1 +06}.. {433792800 18000 0 +05}.. {449607600 21600 1 +06}.. {465339600 18000 0 +05}.. {481064400 21600 1 +06}.. {496789200 18000 0 +05}.. {512514000 21600 1 +06}.. {528238800 18000 0 +05}.. {543963600 21600 1 +06}.. {559688400 18000 0 +05}.. {575413200 21600 1 +06}.. {591138000 18000 0 +05}.. {606862800 21600 1 +06}.. {622587600 18000 0 +05}.. {638312400 21600 1 +06}.. {654642000 18000 0 +05}.. {670366800 14400 0 +05}.. {670370400 18000 1 +05}.. {686095200 14400 0 +04}.. {695772000 18000 0 +06}.. {701816400 21600 1 +06}.. {717541200 18000 0 +05}.. {733266000 21600 1 +06}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2029
                                                                                                                                                                                                                                                          Entropy (8bit):3.6487650030366106
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:5O4GeuadYlykbocXcwJUE5iu8JmFebARoc9lVNk7/9bq8dq16b3C9UPBUUUl2ue/:5xKdsUf8mFpNWFnyLCPYmPJSi3sh4
                                                                                                                                                                                                                                                          MD5:2CFA7C55D0731D24679CA5D5DC716381
                                                                                                                                                                                                                                                          SHA1:2BB66783D75C71E76409365757980FBC15F53231
                                                                                                                                                                                                                                                          SHA-256:20871FA6AA959DDFB73D846271B4A568627B564CFC08A11BDD84B98C2F2019A3
                                                                                                                                                                                                                                                          SHA-512:CAB10A48859B2C0B2CC7C56E0AA530AE7E506A4986BADC5ED974D124BD46DB328B50C423F83FCFD52D31962A249EEFC10351798B86D51EDA500F412C8D42E6BC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yerevan) {.. {-9223372036854775808 10680 0 LMT}.. {-1441162680 10800 0 +03}.. {-405140400 14400 0 +04}.. {354916800 18000 1 +04}.. {370724400 14400 0 +04}.. {386452800 18000 1 +04}.. {402260400 14400 0 +04}.. {417988800 18000 1 +04}.. {433796400 14400 0 +04}.. {449611200 18000 1 +04}.. {465343200 14400 0 +04}.. {481068000 18000 1 +04}.. {496792800 14400 0 +04}.. {512517600 18000 1 +04}.. {528242400 14400 0 +04}.. {543967200 18000 1 +04}.. {559692000 14400 0 +04}.. {575416800 18000 1 +04}.. {591141600 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 10800 0 +03}.. {670374000 14400 1 +03}.. {686098800 10800 0 +03}.. {701823600 14400 1 +03}.. {717548400 10800 0 +03}.. {733273200 14400 1 +03}.. {748998000 10800 0 +03}.. {764722800 14400 1 +03}.. {780447
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9879
                                                                                                                                                                                                                                                          Entropy (8bit):3.557602151081988
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:K35nZPOUYySoluItljncxelTMwtrayE6x5sETNek/CyNzybxYKmX6SXL/XbEcygI:K940pb6cL/b3Ldr9Q7TMq+ML
                                                                                                                                                                                                                                                          MD5:E7F2A3EE0362E9ED3ECBAD24168AD098
                                                                                                                                                                                                                                                          SHA1:98832274F6D9B641B809123D1272A1C04EEAA177
                                                                                                                                                                                                                                                          SHA-256:6B3609BE4E93D21A2AB492594EDD387931E2C787E8471C9F2D3A677F34002D8F
                                                                                                                                                                                                                                                          SHA-512:C48A76F8251AE455C759CB98802E40B3BEF716FD8E7441B6DE0242942C913367E3572B7C871082E97CA9BE67EC7DC37F8D01C438965217AC0EC36AD508DCE0D4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Azores) {.. {-9223372036854775808 -6160 0 LMT}.. {-2713904240 -6872 0 HMT}.. {-1830376800 -7200 0 -02}.. {-1689548400 -3600 1 -01}.. {-1677794400 -7200 0 -02}.. {-1667430000 -3600 1 -01}.. {-1647730800 -7200 0 -02}.. {-1635807600 -3600 1 -01}.. {-1616194800 -7200 0 -02}.. {-1604358000 -3600 1 -01}.. {-1584658800 -7200 0 -02}.. {-1572735600 -3600 1 -01}.. {-1553036400 -7200 0 -02}.. {-1541199600 -3600 1 -01}.. {-1521500400 -7200 0 -02}.. {-1442444400 -3600 1 -01}.. {-1426806000 -7200 0 -02}.. {-1379286000 -3600 1 -01}.. {-1364770800 -7200 0 -02}.. {-1348441200 -3600 1 -01}.. {-1333321200 -7200 0 -02}.. {-1316386800 -3600 1 -01}.. {-1301266800 -7200 0 -02}.. {-1284332400 -3600 1 -01}.. {-1269817200 -7200 0 -02}.. {-1221433200 -3600 1 -01}.. {-1206918000 -7200 0 -02}.. {-1191193200 -3600 1 -01}.. {-1175468400 -7200 0 -02}.. {-1127689
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8784
                                                                                                                                                                                                                                                          Entropy (8bit):3.833553120942514
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:ZRBHksL3zq6bCvyjvspNWMPm4bPJWXtRbALtuFW4ng2CEBJuQaeEy9P19OBYEi/+:ft0CC
                                                                                                                                                                                                                                                          MD5:B04E22B9B42722013941169B5D04DEA2
                                                                                                                                                                                                                                                          SHA1:32B96A7D9504D5022A6C4E2D310E95B5F062947F
                                                                                                                                                                                                                                                          SHA-256:099C3BEFBA3B4C00AE19BC53D475A52B32FAC9B36EC823C8EAEFC7D00F78F388
                                                                                                                                                                                                                                                          SHA-512:8B93BCA1E923B7A43F2EB0889216E8FF991D13CB8D25BD300310ED7CD8537DBD858E8F422C9B52AE2F52F7C1CB450EF0B7C5C1B3AE547C9C1E18E2A851569DD5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Bermuda) {.. {-9223372036854775808 -15558 0 LMT}.. {-2524506042 -15558 0 BMT}.. {-1664307642 -11958 1 BMT}.. {-1648932042 -15558 0 BMT}.. {-1632080442 -11958 1 BMT}.. {-1618692042 -15558 0 BST}.. {-1262281242 -14400 0 AT}.. {-882727200 -10800 1 ADT}.. {-858538800 -14400 0 AST}.. {-845229600 -10800 1 ADT}.. {-825879600 -14400 0 AST}.. {-814384800 -10800 1 ADT}.. {-793825200 -14400 0 AST}.. {-782935200 -10800 1 ADT}.. {-762375600 -14400 0 AST}.. {-713988000 -10800 1 ADT}.. {-703710000 -14400 0 AST}.. {-681933600 -10800 1 ADT}.. {-672865200 -14400 0 AST}.. {-650484000 -10800 1 ADT}.. {-641415600 -14400 0 AST}.. {-618429600 -10800 1 ADT}.. {-609966000 -14400 0 AST}.. {-586980000 -10800 1 ADT}.. {-578516400 -14400 0 AST}.. {-555530400 -10800 1 ADT}.. {-546462000 -14400 0 AST}.. {-429127200 -10800 1 ADT}.. {-415825200 -14400 0 AST}.. {1
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6856
                                                                                                                                                                                                                                                          Entropy (8bit):3.8064107143060752
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:KXVuHfXCiZoFtFPIaFF1w0urfva946ZGsE3f2Sf+aCNmSv+kznl4klEp8OT:KXVQbkIaFF1w0us4qE3+sSGjT
                                                                                                                                                                                                                                                          MD5:8ABD279386C50705C074EEE18BF5AE59
                                                                                                                                                                                                                                                          SHA1:C392231DBE744F5942DA4BFAC8AD0ABEBAEA0BF3
                                                                                                                                                                                                                                                          SHA-256:2026944DCDEBC52F64405E35119F4CF97EA9AA1E769498730880B03F29A2B885
                                                                                                                                                                                                                                                          SHA-512:3095759D01AC7EEA25E427CA38E8A0395BEFA7250E7A0C1327BF9D61F07F4570CDF7313FBE6695973EB0DD66D201C6C63591CC0DA8A1E0029926DC7056F4C95B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Canary) {.. {-9223372036854775808 -3696 0 LMT}.. {-1509663504 -3600 0 -01}.. {-733874400 0 0 WET}.. {323827200 3600 1 WEST}.. {338950800 0 0 WET}.. {354675600 3600 1 WEST}.. {370400400 0 0 WET}.. {386125200 3600 1 WEST}.. {401850000 0 0 WET}.. {417574800 3600 1 WEST}.. {433299600 0 0 WET}.. {449024400 3600 1 WEST}.. {465354000 0 0 WET}.. {481078800 3600 1 WEST}.. {496803600 0 0 WET}.. {512528400 3600 1 WEST}.. {528253200 0 0 WET}.. {543978000 3600 1 WEST}.. {559702800 0 0 WET}.. {575427600 3600 1 WEST}.. {591152400 0 0 WET}.. {606877200 3600 1 WEST}.. {622602000 0 0 WET}.. {638326800 3600 1 WEST}.. {654656400 0 0 WET}.. {670381200 3600 1 WEST}.. {686106000 0 0 WET}.. {701830800 3600 1 WEST}.. {717555600 0 0 WET}.. {733280400 3600 1 WEST}.. {749005200 0 0 WET}.. {764730000 3600 1 WEST}.. {780454800 0 0 WET}.. {796179600
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):246
                                                                                                                                                                                                                                                          Entropy (8bit):4.637993677747699
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/2RQ7RfDm2OHDoH1JlvQV/FFrR3FcykVvQV/FFf+nmwV:MB86267RLmdHDC1w/FH3FcyL/FomwV
                                                                                                                                                                                                                                                          MD5:1581C6470850E0C9DB204975488B1AF8
                                                                                                                                                                                                                                                          SHA1:6933ED13F18AD785CEDF0837F86EFAC671297A85
                                                                                                                                                                                                                                                          SHA-256:2EA59ACDB5BBDD3C6ABCEEA456838A5CA57371A3D2BB93604B37F998ED8B9D4D
                                                                                                                                                                                                                                                          SHA-512:9FFFA013D82CEFF6F447521C19270ECDD71152F23670164423E6013FEC46253C62D2CB79B42630BD786BD113F27369E746CA981DD17E789F7571F473B47247C1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Cape_Verde) {.. {-9223372036854775808 -5644 0 LMT}.. {-1830376800 -7200 0 -02}.. {-862610400 -3600 1 -01}.. {-764118000 -7200 0 -02}.. {186120000 -3600 0 -01}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):186
                                                                                                                                                                                                                                                          Entropy (8bit):4.709193799640151
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqLG4E23vXHAIgvMG4EeRRL/2RQqG4EZrB/4RQqG4E1n:SlSWB9vsM3yCPHAIgvoRN/2RQ1rB/4Ri
                                                                                                                                                                                                                                                          MD5:601EB889A87F9CAD6F1DF4D1AB009FAE
                                                                                                                                                                                                                                                          SHA1:EB43C253A48755442A67A2408D7E3295549F831C
                                                                                                                                                                                                                                                          SHA-256:64FB8CAD17CD36666C7027AAD01344FEF659B13699EEF1942365842F8ED2170E
                                                                                                                                                                                                                                                          SHA-512:9CFC4A446ED6A3BEF6C26AE57324F10A970EE2ADD6933130447FAD6A3DB538841F2490DD461AF5776FACD9BD2CDC4A83247DFA6B34802AE844DDC6D4C37B28EA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Atlantic/Faroe)]} {.. LoadTimeZoneFile Atlantic/Faroe..}..set TZData(:Atlantic/Faeroe) $TZData(:Atlantic/Faroe)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6796
                                                                                                                                                                                                                                                          Entropy (8bit):3.804838552487436
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:96ufXCiZoFtFPIaFF1w0urfva946ZGsE3f2Sf+aCNmSv+kznl4klEp8OT:/bkIaFF1w0us4qE3+sSGjT
                                                                                                                                                                                                                                                          MD5:F97CC7EB9C52D00177BFF4715832FCD5
                                                                                                                                                                                                                                                          SHA1:CD9DCBB5E6ADD6EA91C8F142957EC229FC7F6DA3
                                                                                                                                                                                                                                                          SHA-256:795F438E7F01342D5F25ECCDD09FCE65C03C5D2D561B9B5191301D57EC16B850
                                                                                                                                                                                                                                                          SHA-512:9586289FEB6C597160011A47432F0AC40000483FA2E579BD89046EFD33E98DDAD652B792FD80CEDEB4CD87B6439A7B473F25F1B7375BC75353CBAF9F77E1084E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Faroe) {.. {-9223372036854775808 -1624 0 LMT}.. {-1955748776 0 0 WET}.. {347155200 0 0 WET}.. {354675600 3600 1 WEST}.. {370400400 0 0 WET}.. {386125200 3600 1 WEST}.. {401850000 0 0 WET}.. {417574800 3600 1 WEST}.. {433299600 0 0 WET}.. {449024400 3600 1 WEST}.. {465354000 0 0 WET}.. {481078800 3600 1 WEST}.. {496803600 0 0 WET}.. {512528400 3600 1 WEST}.. {528253200 0 0 WET}.. {543978000 3600 1 WEST}.. {559702800 0 0 WET}.. {575427600 3600 1 WEST}.. {591152400 0 0 WET}.. {606877200 3600 1 WEST}.. {622602000 0 0 WET}.. {638326800 3600 1 WEST}.. {654656400 0 0 WET}.. {670381200 3600 1 WEST}.. {686106000 0 0 WET}.. {701830800 3600 1 WEST}.. {717555600 0 0 WET}.. {733280400 3600 1 WEST}.. {749005200 0 0 WET}.. {764730000 3600 1 WEST}.. {780454800 0 0 WET}.. {796179600 3600 1 WEST}.. {811904400 0 0 WET}.. {828234000 3600
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):186
                                                                                                                                                                                                                                                          Entropy (8bit):4.957633978425468
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/y+YF3vXHAIgoq8yFRRL/2RQqG0EHEcAg/h8QahV:SlSWB9vsM3ymhVoPHAIgoh6N/2RQaK85
                                                                                                                                                                                                                                                          MD5:95C2D55CCE5809089CDB041EA3D464F8
                                                                                                                                                                                                                                                          SHA1:B395F5F26CE979BDF2B9E2CB51C06929AED11A6C
                                                                                                                                                                                                                                                          SHA-256:11BF0746F95BA01807D3B34C8FAE3FF4AE9DB5E4E6BC0CB8B36906CC3F44EDE5
                                                                                                                                                                                                                                                          SHA-512:AB2BE22E95A7C36E18EBA1BB63B3930A523ED793E43A3F597A8F63AE2F0E44436C39144BC136E7E5716D7FCBFAE7F1FAF36BCFFCF9C8D51151FF25BB14D6F8B5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Atlantic/Jan_Mayen) $TZData(:Europe/Berlin)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9709
                                                                                                                                                                                                                                                          Entropy (8bit):3.80455694200614
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:hZUiLbMsf/ss0qKd+aKyUXtOZHY1SCOcesoQivoKbFVCdm1rXWNXyCXTOuUbkIaq:hZZDQX1rWJysukysLE3+sSGjT
                                                                                                                                                                                                                                                          MD5:AC6647F9B53B5958214EC3F3B78A4D85
                                                                                                                                                                                                                                                          SHA1:7355622AF99296F069F73899D5C70941C207F676
                                                                                                                                                                                                                                                          SHA-256:B2A0D0DDC26806A05B2BE806CA3F938DB12A3FA40110B8B21FD3F04EFED3A531
                                                                                                                                                                                                                                                          SHA-512:07569CA4D5DC6D57D91D6FDC370671A7546B73BA653D094E1B501D33570F7700727AD7FF2A083BC79E9EDE807C47E7A5604BEF5803F290B2F277C51DEF10FA6B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Madeira) {.. {-9223372036854775808 -4056 0 LMT}.. {-2713906344 -4056 0 FMT}.. {-1830380400 -3600 0 -01}.. {-1689552000 0 1 +00}.. {-1677798000 -3600 0 -01}.. {-1667433600 0 1 +00}.. {-1647734400 -3600 0 -01}.. {-1635811200 0 1 +00}.. {-1616198400 -3600 0 -01}.. {-1604361600 0 1 +00}.. {-1584662400 -3600 0 -01}.. {-1572739200 0 1 +00}.. {-1553040000 -3600 0 -01}.. {-1541203200 0 1 +00}.. {-1521504000 -3600 0 -01}.. {-1442448000 0 1 +00}.. {-1426809600 -3600 0 -01}.. {-1379289600 0 1 +00}.. {-1364774400 -3600 0 -01}.. {-1348444800 0 1 +00}.. {-1333324800 -3600 0 -01}.. {-1316390400 0 1 +00}.. {-1301270400 -3600 0 -01}.. {-1284336000 0 1 +00}.. {-1269820800 -3600 0 -01}.. {-1221436800 0 1 +00}.. {-1206921600 -3600 0 -01}.. {-1191196800 0 1 +00}.. {-1175472000 -3600 0 -01}.. {-1127692800 0 1 +00}.. {-1111968000 -3600 0 -01}.. {-
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.910514445868106
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2RQqGsA/8rVDcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2RQjQD4
                                                                                                                                                                                                                                                          MD5:ECB480DA99D29C0ACE67426D45534754
                                                                                                                                                                                                                                                          SHA1:784CF126B030C3D883EE541877E6181F795C9697
                                                                                                                                                                                                                                                          SHA-256:BDA015714260001BAE2848991DD21E802580BE2915797E5DABC376135D1C5246
                                                                                                                                                                                                                                                          SHA-512:54C1B20E45C7C73354DCD4E0F4444720771820ED10B282F745DC391BEADEAEDC629BEF97B1908FB62CDAEC915D32AF1F54FC6AA9DC83E317E7CE19FC2586EF28
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Atlantic/Reykjavik) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):160
                                                                                                                                                                                                                                                          Entropy (8bit):5.011466665416709
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/2RQqGtlN62/EiMXGm2OHXT14YoHvhFvdQVIyV:SlSWB9eg/2RQrlo2MiDm2OHXqYoHvTFS
                                                                                                                                                                                                                                                          MD5:3B310BB8C90CA716DC1AC5A697ACA9CD
                                                                                                                                                                                                                                                          SHA1:CD583F49478DCDAD91EF78539502C6FC62945C1E
                                                                                                                                                                                                                                                          SHA-256:51BFABCB3388107753A3C1A8CF31118E6627132BAA09B9878D9E7CEDBEBB4886
                                                                                                                                                                                                                                                          SHA-512:F593B7A1FAF0EA6B42D5EE86C20C9A8F5CD7ACD9B30EF7755E45ECAFEA8752C32E4CF4BEDF531F494E59D9F0C49CCC6FCA077292E20794AA265DFC0A56DFE579
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/South_Georgia) {.. {-9223372036854775808 -8768 0 LMT}.. {-2524512832 -7200 0 -02}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.880390141563645
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2RQqGt4r+DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2RQr4rV
                                                                                                                                                                                                                                                          MD5:2C73A963F515376A46762CE153AAF5C5
                                                                                                                                                                                                                                                          SHA1:996C3C93DFAD89EA80AC5DFA1DFBD7CECD9ED28D
                                                                                                                                                                                                                                                          SHA-256:1C9CA8966FC8BD0BE70F4A187E17E56FB99139BC88C392E82BA2E23E23111C54
                                                                                                                                                                                                                                                          SHA-512:35A9ADC047DB058D71C21FC4ECB57CD14B0D9BA4416506763D1800D72CE6C9E81636F332AAD3533616F05C86F90A60416BD4065C5F832A51AA3DC186218BDCAE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Atlantic/St_Helena) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2256
                                                                                                                                                                                                                                                          Entropy (8bit):3.662522763865322
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:506KSBSdSs2SbSwGSyPU3lSsS5SGScSo/SkSuShSceS3SBSc7XSiSgSwSd/SJkS6:JKU+Ew0FU1TuhrR//tOIoOjXZfDWSkPR
                                                                                                                                                                                                                                                          MD5:77C7ECE4FCBE150069B611C75E8DAA0E
                                                                                                                                                                                                                                                          SHA1:22F4E5F15BCA92D8456B70BB36230F2605CA5E1C
                                                                                                                                                                                                                                                          SHA-256:F0E99EF01F140CD5AAFE16803A657922207E6F7F6AF10B0AE795790916C302C4
                                                                                                                                                                                                                                                          SHA-512:6FB57E8499A587292AFAFA9BD003721572393D5268CAF956230DA76983A112B27D6731BE561A22CCEF84935F43AC988B667C2DC404C157EA8D0E7830FC1A2AB8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Stanley) {.. {-9223372036854775808 -13884 0 LMT}.. {-2524507716 -13884 0 SMT}.. {-1824235716 -14400 0 -04}.. {-1018209600 -10800 1 -04}.. {-1003093200 -14400 0 -04}.. {-986760000 -10800 1 -04}.. {-971643600 -14400 0 -04}.. {-954705600 -10800 1 -04}.. {-939589200 -14400 0 -04}.. {-923256000 -10800 1 -04}.. {-908139600 -14400 0 -04}.. {-891806400 -10800 1 -04}.. {-876690000 -14400 0 -04}.. {-860356800 -10800 1 -04}.. {420606000 -7200 0 -03}.. {433303200 -7200 1 -03}.. {452052000 -10800 0 -03}.. {464151600 -7200 1 -03}.. {483501600 -10800 0 -03}.. {495597600 -14400 0 -04}.. {495604800 -10800 1 -04}.. {514350000 -14400 0 -04}.. {527054400 -10800 1 -04}.. {545799600 -14400 0 -04}.. {558504000 -10800 1 -04}.. {577249200 -14400 0 -04}.. {589953600 -10800 1 -04}.. {608698800 -14400 0 -04}.. {621403200 -10800 1 -04}.. {640753200 -14400 0 -
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.862270414049974
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq/xJjLkXHAIgoXjLyFvHRL/2QWCCjpMFBx/h4QWCCj1:SlSWB9vsM3yI9kHAIgmON/2DCeMFB/4d
                                                                                                                                                                                                                                                          MD5:2EF41863430897F45E0CBB51E6A44069
                                                                                                                                                                                                                                                          SHA1:8E9561060E9509FAF235E5E033FC9C2918E438DB
                                                                                                                                                                                                                                                          SHA-256:DF7CBDDCBB2F5926A07D19A35739E5B8DCD9733C037F7D1FF95753C28D574674
                                                                                                                                                                                                                                                          SHA-512:9D3A37D64DCCCA28093C30FAB595690D021FACEC15F351A77CA33A779D645D305A2FA031869F0DE3B0404C498C2C321D3D02E4DC592D3C632F6700F5DCB54900
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Sydney)]} {.. LoadTimeZoneFile Australia/Sydney..}..set TZData(:Australia/ACT) $TZData(:Australia/Sydney)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8372
                                                                                                                                                                                                                                                          Entropy (8bit):3.894755849491153
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:j8SY62BXovlCyRL8pJXa4NyPaNw0leasxMQ/UvuQPxBFNsLQ2nDs020DdDncIsea:j8X3Xzgl3PaN8asiQ/Uv9UnvtCaRs
                                                                                                                                                                                                                                                          MD5:94E1A0C4326D09AF103107E64625CC6C
                                                                                                                                                                                                                                                          SHA1:C026565F020EB158309549D98313632BAA79205F
                                                                                                                                                                                                                                                          SHA-256:5C43D3152982BCFD5B9F51D0E909CF3A558BED1C270FEFFE030531D38D6F91B7
                                                                                                                                                                                                                                                          SHA-512:CA08A8BC0EB740D59650FE0A9E56D9E169348AD0994F2BFFD6CCFBF9CC42E82F892FB719E80C4E2084B5702E9725C651359EE3066BD71BB19397EA83B6A68430
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Adelaide) {.. {-9223372036854775808 33260 0 LMT}.. {-2364110060 32400 0 ACST}.. {-2230189200 34200 0 ACST}.. {-1672558200 37800 1 ACDT}.. {-1665387000 34200 0 ACST}.. {-883639800 37800 1 ACDT}.. {-876123000 34200 0 ACST}.. {-860398200 37800 1 ACDT}.. {-844673400 34200 0 ACST}.. {-828343800 37800 1 ACDT}.. {-813223800 34200 0 ACST}.. {31501800 34200 0 ACST}.. {57688200 37800 1 ACDT}.. {67969800 34200 0 ACST}.. {89137800 37800 1 ACDT}.. {100024200 34200 0 ACST}.. {120587400 37800 1 ACDT}.. {131473800 34200 0 ACST}.. {152037000 37800 1 ACDT}.. {162923400 34200 0 ACST}.. {183486600 37800 1 ACDT}.. {194977800 34200 0 ACST}.. {215541000 37800 1 ACDT}.. {226427400 34200 0 ACST}.. {246990600 37800 1 ACDT}.. {257877000 34200 0 ACST}.. {278440200 37800 1 ACDT}.. {289326600 34200 0 ACST}.. {309889800 37800 1 ACDT}.. {320776200 34200 0 ACST}
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):674
                                                                                                                                                                                                                                                          Entropy (8bit):4.32071371733564
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862ELmdHLOYCvSi0xT0ryRIvUr0obZv:5ELe6dvSi6L
                                                                                                                                                                                                                                                          MD5:900B39F1D4AB93A445F37B6C0A8DE3D9
                                                                                                                                                                                                                                                          SHA1:DE82800779DCB8094C395B5024BD01FFA3C3BB8C
                                                                                                                                                                                                                                                          SHA-256:0D3C39EDAB34A8DB31A658A1549772F7D69EB57565E40AA87B707953A2D854A4
                                                                                                                                                                                                                                                          SHA-512:8D115D1D14FE6FF21A4AE77E3AAC075E6A877214E568956B9A4FD2E75A46E458CAA5AE26B483F128B4C62960D73BD7543BC32F22B760059423B3D9ABCBA24B6A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Brisbane) {.. {-9223372036854775808 36728 0 LMT}.. {-2366791928 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {625593600 39600 1 AEDT}.. {636480000 36000 0 AEST}.. {657043200 39600 1 AEDT}.. {667929600 36000 0 AEST}.. {688492800 39600 1 AEDT}.. {699379200 36000 0 AEST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8437
                                                                                                                                                                                                                                                          Entropy (8bit):3.902306256303896
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:QZSSY62BXovldRL8q75aANyPaNw0leasxMQ/UvuQPxBFNsLQ2nDs020DdDncIsea:QZSX3X2QfPaN8asiQ/Uv9UnvtCaRs
                                                                                                                                                                                                                                                          MD5:1553DAAB804A6C9BB15D711554980D3B
                                                                                                                                                                                                                                                          SHA1:5E3161B1FBB4C246DCB5E11ABD94095121CE38ED
                                                                                                                                                                                                                                                          SHA-256:734F295BD0B558BDF6178DE62151B8913699D08AB2B1D101C55B8DEBC410074C
                                                                                                                                                                                                                                                          SHA-512:06B21886070E39E390ECBD18841B7FDBFCA2C7C8573495D2BAA2B92EB113CD1C73C18D73C49DE3C49572CBCBCBED2FAD3248BC651BEB825A1E089B1DEDEFCBFA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Broken_Hill) {.. {-9223372036854775808 33948 0 LMT}.. {-2364110748 36000 0 AEST}.. {-2314951200 32400 0 ACST}.. {-2230189200 34200 0 ACST}.. {-1672558200 37800 1 ACDT}.. {-1665387000 34200 0 ACST}.. {-883639800 37800 1 ACDT}.. {-876123000 34200 0 ACST}.. {-860398200 37800 1 ACDT}.. {-844673400 34200 0 ACST}.. {-828343800 37800 1 ACDT}.. {-813223800 34200 0 ACST}.. {31501800 34200 0 ACST}.. {57688200 37800 1 ACDT}.. {67969800 34200 0 ACST}.. {89137800 37800 1 ACDT}.. {100024200 34200 0 ACST}.. {120587400 37800 1 ACDT}.. {131473800 34200 0 ACST}.. {152037000 37800 1 ACDT}.. {162923400 34200 0 ACST}.. {183486600 37800 1 ACDT}.. {194977800 34200 0 ACST}.. {215541000 37800 1 ACDT}.. {226427400 34200 0 ACST}.. {246990600 37800 1 ACDT}.. {257877000 34200 0 ACST}.. {278440200 37800 1 ACDT}.. {289326600 34200 0 ACST}.. {309889800 37800 1
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):195
                                                                                                                                                                                                                                                          Entropy (8bit):4.851279484907769
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq/xJjLkXHAIgoXjLyFvHRL/2QWCCjnSV1+QWCCjLBn:SlSWB9vsM3yI9kHAIgmON/2DCcq+DCyB
                                                                                                                                                                                                                                                          MD5:8944D3DF8FBECC03A8FB18C3B2DA3B53
                                                                                                                                                                                                                                                          SHA1:6B17B38D6560592CA49840C47DB9BDA7E79F9F76
                                                                                                                                                                                                                                                          SHA-256:5FE3CED97293FE0573D5ECE0CEF59CE5DDB4C57BC568AE7199E77B01D3ADE17C
                                                                                                                                                                                                                                                          SHA-512:907D8BB7EA840E0B3AC683884F2F709A2C06D67CE9258BE46400A0DA63581A9B1403A44FA43E1059BE8F5C7E06F9FA05C176309AD6295317BF14F0E9FA5741E4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Sydney)]} {.. LoadTimeZoneFile Australia/Sydney..}..set TZData(:Australia/Canberra) $TZData(:Australia/Sydney)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):193
                                                                                                                                                                                                                                                          Entropy (8bit):4.79231670095588
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yI4DVJHAIgxnvVWAN/2DCkx+4DCVDy:MByMjUQVv8At2s4Ky
                                                                                                                                                                                                                                                          MD5:0C1DFC0877CE8EB08007B7C2B7AF2D87
                                                                                                                                                                                                                                                          SHA1:02F835BE2DA4FCA79DC2A6959BB4EB6ACC8DF708
                                                                                                                                                                                                                                                          SHA-256:1DD4EC4ED4F854E2EF6162B2F28C89208710F8EC5AABB95FFA9425D3FBBCAB13
                                                                                                                                                                                                                                                          SHA-512:358347045915B7D10940DB15E49528D0C636BEC1BE70129847D0B9D034F9E96E847394D88358E87D98A9E581605A3C2AB917B85FDE1296F290B4194BB7E3FA46
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Hobart)]} {.. LoadTimeZoneFile Australia/Hobart..}..set TZData(:Australia/Currie) $TZData(:Australia/Hobart)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):437
                                                                                                                                                                                                                                                          Entropy (8bit):4.508468081487136
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862pmdHPCvZUjMWpXgda/gd026Xgdvgd+v:5peKvZqMSX+4+56X+v+Q
                                                                                                                                                                                                                                                          MD5:A81864B2C0BD7BF81F4FA21F17800059
                                                                                                                                                                                                                                                          SHA1:518AC9E040A17083ED3962F4FBB47D1D83764FF7
                                                                                                                                                                                                                                                          SHA-256:AC004FD4B3C536406991EC13EBB3E64E0EC0C7B264BC18C0700C8FA545868155
                                                                                                                                                                                                                                                          SHA-512:3C24F4C2CC3072B3E820FCC1C68A747DCCBB9481FE743C1555783CC932DCBA44FE4851A732D24EABF62E845474D4E1278F120A04DB7549A18C7C49C31FB8D425
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Darwin) {.. {-9223372036854775808 31400 0 LMT}.. {-2364108200 32400 0 ACST}.. {-2230189200 34200 0 ACST}.. {-1672558200 37800 1 ACDT}.. {-1665387000 34200 0 ACST}.. {-883639800 37800 1 ACDT}.. {-876123000 34200 0 ACST}.. {-860398200 37800 1 ACDT}.. {-844673400 34200 0 ACST}.. {-828343800 37800 1 ACDT}.. {-813223800 34200 0 ACST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):759
                                                                                                                                                                                                                                                          Entropy (8bit):4.110997549215461
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862EmdHvOYCvV2mV22wF2nUV2CF2+V2pCwF21UF2biV2cHVKF25V2VF2cV2tFq:5Eemdvg2wQCKZ4j5c0LVmtH1iknohwQT
                                                                                                                                                                                                                                                          MD5:1BC8DBD2E24606EFA49F933034FC0EEF
                                                                                                                                                                                                                                                          SHA1:A511695A1B87A689C6BFF65257C11D3962FDDA3D
                                                                                                                                                                                                                                                          SHA-256:79D0C770A304360DB33F3D1EF7B3935F1E4E8125893E0DCE683AC35A51302CFB
                                                                                                                                                                                                                                                          SHA-512:A839D390D70F22FC833322029B732F3AE68FF48793B07005041BD12322DD6E5D5E5FF31787AA004A507A57F8FC245133891F266C4EF19D49F085E6B412E5B04C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Eucla) {.. {-9223372036854775808 30928 0 LMT}.. {-2337928528 31500 0 +0945}.. {-1672555500 35100 1 +0945}.. {-1665384300 31500 0 +0945}.. {-883637100 35100 1 +0945}.. {-876120300 31500 0 +0945}.. {-860395500 35100 1 +0945}.. {-844670700 31500 0 +0945}.. {-836473500 35100 0 +0945}.. {152039700 35100 1 +0945}.. {162926100 31500 0 +0945}.. {436295700 35100 1 +0945}.. {447182100 31500 0 +0945}.. {690311700 35100 1 +0945}.. {699383700 31500 0 +0945}.. {1165079700 35100 1 +0945}.. {1174756500 31500 0 +0945}.. {1193505300 35100 1 +0945}.. {1206810900 31500 0 +0945}.. {1224954900 35100 1 +0945}.. {1238260500 31500 0 +0945}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8734
                                                                                                                                                                                                                                                          Entropy (8bit):3.8515786470328823
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:aOqigkx6WsYyS39nQiAmcO38EJ8i/V9cYgCqMEjKeIZ3wQb25Ly04:aOq05hnQiAmcOM6e0pj
                                                                                                                                                                                                                                                          MD5:5E04BF8E1DEBFCC4130FDD1BBD67B2DF
                                                                                                                                                                                                                                                          SHA1:796AADCE7BB2FAF5E6FC916C941A4E3DCAFACC9E
                                                                                                                                                                                                                                                          SHA-256:D813F6A97BEFC22CA4F24C59EB755D269B9C68A449CC7CF0D2C61F911860EBE7
                                                                                                                                                                                                                                                          SHA-512:3A69CF1D1F57D6BD39E5F4DAF76BBB06A749D42BEB29452A0A5BDAA68F5DACC0DF176EDDA7A083F5B5B84FC651926C09D46CAAD2F6C4F1595AB9CCA1A958D653
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Hobart) {.. {-9223372036854775808 35356 0 LMT}.. {-2345795356 36000 0 AEST}.. {-1680508800 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-1646640000 39600 1 AEDT}.. {-1635753600 36000 0 AEST}.. {-1615190400 39600 1 AEDT}.. {-1604304000 36000 0 AEST}.. {-1583920800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {-94730400 36000 0 AEST}.. {-71136000 39600 1 AEDT}.. {-55411200 36000 0 AEST}.. {-37267200 39600 1 AEDT}.. {-25776000 36000 0 AEST}.. {-5817600 39600 1 AEDT}.. {5673600 36000 0 AEST}.. {25632000 39600 1 AEDT}.. {37728000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {89136000 39600 1 AEDT}.. {100022400 36000 0 AEST}.. {120585600 39600 1 AEDT}.. {131472000 36000 0 AES
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):199
                                                                                                                                                                                                                                                          Entropy (8bit):4.912882643701746
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yIoGEoPHAIgjGg6N/2DCkx/2DCPGUv:MByMjeXV6t2a8v
                                                                                                                                                                                                                                                          MD5:425DC7B1E31F4AA41DAD74E3C9AE3562
                                                                                                                                                                                                                                                          SHA1:D92A3269F7BF5EC00F082C64CEF6E20C43017180
                                                                                                                                                                                                                                                          SHA-256:4D84E4040FBC529C9E0366BB74D0CFADEEEEDA0DFCC6C2C9204DED6C6455CAC3
                                                                                                                                                                                                                                                          SHA-512:F3031F16C0D00D9F8A38CD378F599EB3E63F4FF85F120DB38E3013E93F08E6F512D969F164BBC88CD625910FB3E086F3352E5B8FFC1373C3CC98F363FB3FD3F7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Lord_Howe)]} {.. LoadTimeZoneFile Australia/Lord_Howe..}..set TZData(:Australia/LHI) $TZData(:Australia/Lord_Howe)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):824
                                                                                                                                                                                                                                                          Entropy (8bit):4.249672335529665
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862gtmdHVCvCi0xT0ryRIvUr0obbty/ywtUj3yv:5gteMvCi6Xlt8
                                                                                                                                                                                                                                                          MD5:504A422280E0459A2126E7CB02F527E6
                                                                                                                                                                                                                                                          SHA1:EF61B98EFB1E44EE59020E99A69EA67D6B8ACFC2
                                                                                                                                                                                                                                                          SHA-256:01B278309353849CC2FDF62A30E2FF483833D5713CF5E329252738BE6F2C0A84
                                                                                                                                                                                                                                                          SHA-512:BFDAAD56D817CD3AAB17DFD0A33EFDD422645BC542ABE269C0F8520E33796DF4F19EAB2E40BFC6C4AF93EF654239B8F2E285639B4662040D865B9C340A23CFAD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Lindeman) {.. {-9223372036854775808 35756 0 LMT}.. {-2366790956 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {625593600 39600 1 AEDT}.. {636480000 36000 0 AEST}.. {657043200 39600 1 AEDT}.. {667929600 36000 0 AEST}.. {688492800 39600 1 AEDT}.. {699379200 36000 0 AEST}.. {709912800 36000 0 AEST}.. {719942400 39600 1 AEDT}.. {731433600 36000 0 AEST}.. {751996800 39600 1 AEDT}.. {762883200 36000 0 AEST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7764
                                                                                                                                                                                                                                                          Entropy (8bit):3.5615258807990537
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:pmz39IyKxb/JbcD9gKniAF23QbNS1fEGXALNbbT2JFJ/FaKaTQ9ZJhRVK:p+cpVKniAF2AbkFKL
                                                                                                                                                                                                                                                          MD5:10F983F4683CDE13A1228AC0B04D8513
                                                                                                                                                                                                                                                          SHA1:45378BA5949BE53D698108F50FECFF50C9E3D296
                                                                                                                                                                                                                                                          SHA-256:76D1F1ED67B8F8D6903789C2FDDF79590A83677972D416F5F3C9687614EC6238
                                                                                                                                                                                                                                                          SHA-512:D60D802EF215A33750E4F859657BA12A67084B1E9FCF1B4A7CEEE7B9D816BC2C6670775D93C88EC8380CDD7790AD574133D6F90F0828F848313C26583B2F196A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Lord_Howe) {.. {-9223372036854775808 38180 0 LMT}.. {-2364114980 36000 0 AEST}.. {352216800 37800 0 +1030}.. {372785400 41400 1 +1030}.. {384273000 37800 0 +1030}.. {404839800 41400 1 +1030}.. {415722600 37800 0 +1030}.. {436289400 41400 1 +1030}.. {447172200 37800 0 +1030}.. {467739000 41400 1 +1030}.. {478621800 37800 0 +1030}.. {488984400 37800 0 +1030}.. {499188600 39600 1 +1030}.. {511282800 37800 0 +1030}.. {530033400 39600 1 +1030}.. {542732400 37800 0 +1030}.. {562087800 39600 1 +1030}.. {574786800 37800 0 +1030}.. {594142200 39600 1 +1030}.. {606236400 37800 0 +1030}.. {625591800 39600 1 +1030}.. {636476400 37800 0 +1030}.. {657041400 39600 1 +1030}.. {667926000 37800 0 +1030}.. {688491000 39600 1 +1030}.. {699375600 37800 0 +1030}.. {719940600 39600 1 +1030}.. {731430000 37800 0 +1030}.. {751995000 39600 1 +1030}.. {762
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8341
                                                                                                                                                                                                                                                          Entropy (8bit):3.8532171550973526
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:Yyigkp2EUyn8/dnQiAmcO38EJ8i/V9cYgCqMEjKeIZ3wQb25Ly04:Yy3VnQiAmcOM6e0pj
                                                                                                                                                                                                                                                          MD5:40D06B80A4A0DB415270EFD9698B97BF
                                                                                                                                                                                                                                                          SHA1:1999F0E8C7EBAA11BD21D64D9E07FA911F13C64C
                                                                                                                                                                                                                                                          SHA-256:F21B9EA51C0D41BAD0420FE0601E5A4B491FB895856F4BDDF6541D704469D92F
                                                                                                                                                                                                                                                          SHA-512:E47D597CC85D177CF2804C44C216EB4C5B74472457F15F697704311A847BF8A051DCAFD26FA61DD689555F35640151E26F25D5DC5319EFEFEA62AD86657A4A95
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Melbourne) {.. {-9223372036854775808 34792 0 LMT}.. {-2364111592 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {89136000 39600 1 AEDT}.. {100022400 36000 0 AEST}.. {120585600 39600 1 AEDT}.. {131472000 36000 0 AEST}.. {152035200 39600 1 AEDT}.. {162921600 36000 0 AEST}.. {183484800 39600 1 AEDT}.. {194976000 36000 0 AEST}.. {215539200 39600 1 AEDT}.. {226425600 36000 0 AEST}.. {246988800 39600 1 AEDT}.. {257875200 36000 0 AEST}.. {278438400 39600 1 AEDT}.. {289324800 36000 0 AEST}.. {309888000 39600 1 AEDT}.. {320774400 36000 0 AEST}.. {341337600 39600 1 AEDT}.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.893713405897538
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq/xJjLkXHAIgoXjLyFvHRL/2QWCCjREeQWCCjLBn:SlSWB9vsM3yI9kHAIgmON/2DC5eDCyB
                                                                                                                                                                                                                                                          MD5:80B7CDD1EA5A5308CE84C038180005F2
                                                                                                                                                                                                                                                          SHA1:B7CA15B58ADA8CA3EB74B7971073022D57D8EE70
                                                                                                                                                                                                                                                          SHA-256:73D7C9E207E61ACF8DF7242BDCD84488189033E22A84873A953B65DE02FA1B0B
                                                                                                                                                                                                                                                          SHA-512:F627F5FF335600AC9158D6A0D3694AB7E70180177449C17B5605BBF7B1B7F8FB447A9C207F4E1BCB627074DB47B8A66F5D78E03C6DB8FA17F8BDD6AABB331665
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Sydney)]} {.. LoadTimeZoneFile Australia/Sydney..}..set TZData(:Australia/NSW) $TZData(:Australia/Sydney)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):192
                                                                                                                                                                                                                                                          Entropy (8bit):4.830368875485429
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq/xJjbvvXHAIgoXjbBvRL/2QWCCjsrQWCCjbi:SlSWB9vsM3yIFHAIg2N/2DCZrDCl
                                                                                                                                                                                                                                                          MD5:14CB7EA1C028F457345EBEB8ADDC9237
                                                                                                                                                                                                                                                          SHA1:208BF676F56533BA271D1B98363A766DF17CF6F2
                                                                                                                                                                                                                                                          SHA-256:A983C9CAD7E542CAED43B083E68CD2B782959A4B54015F374C29250D3ACF9B8D
                                                                                                                                                                                                                                                          SHA-512:099F65E5FA705FD7257CF7B8E103905EE313C6D082844F69CCD3F318E3E7F4098B29F952FA0AA28655E1FE290A0FB2E809911088315889DE7CAAF0E04698C2FC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Darwin)]} {.. LoadTimeZoneFile Australia/Darwin..}..set TZData(:Australia/North) $TZData(:Australia/Darwin)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):739
                                                                                                                                                                                                                                                          Entropy (8bit):4.31793586514766
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB8623mdHCBdCvmlXz6zezzOz4iaLYvzkzi4zm5fVcBhg8mfev:53eCB0v4+e3Oz4iaLYbkzi4zxhfqw
                                                                                                                                                                                                                                                          MD5:01B1A88867472AD60B8F5C0E1648E3ED
                                                                                                                                                                                                                                                          SHA1:9975EA750458E8061DD8A83585675CB7E4910CA6
                                                                                                                                                                                                                                                          SHA-256:FC1B54CA261074E47A8A486FEAC12DD04D46166D1D2B44163BD8791BEC32D275
                                                                                                                                                                                                                                                          SHA-512:20BDFBCD1A5038C81552EBD955F3921DE3447A1F30E64935937768B2B98735AE53049601DCDD2D519646C78E6D03289EB465CFF4F2DADEA7D89A329504C6C475
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Perth) {.. {-9223372036854775808 27804 0 LMT}.. {-2337925404 28800 0 AWST}.. {-1672552800 32400 1 AWDT}.. {-1665381600 28800 0 AWST}.. {-883634400 32400 1 AWDT}.. {-876117600 28800 0 AWST}.. {-860392800 32400 1 AWDT}.. {-844668000 28800 0 AWST}.. {-836470800 32400 0 AWST}.. {152042400 32400 1 AWDT}.. {162928800 28800 0 AWST}.. {436298400 32400 1 AWDT}.. {447184800 28800 0 AWST}.. {690314400 32400 1 AWDT}.. {699386400 28800 0 AWST}.. {1165082400 32400 1 AWDT}.. {1174759200 28800 0 AWST}.. {1193508000 32400 1 AWDT}.. {1206813600 28800 0 AWST}.. {1224957600 32400 1 AWDT}.. {1238263200 28800 0 AWST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):203
                                                                                                                                                                                                                                                          Entropy (8bit):4.803539644461131
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yIaWhSHAIgPWAvN/2DCoRWJvFBx+DC7WN:MByMjL9t2rOvFel
                                                                                                                                                                                                                                                          MD5:401B6B2E30EF17BE20212645287EB94B
                                                                                                                                                                                                                                                          SHA1:67D15A45C61122CE680B829FE0FA3A1C501A8C8F
                                                                                                                                                                                                                                                          SHA-256:DDA669B9BFB3E08FC23CE67030148B9E4740824ADD8DE02580D6AFD31CE05BAB
                                                                                                                                                                                                                                                          SHA-512:F4348F8F4FF261C47854725AEE4E14E7E334B3C31496E5C46B0E0041551CB6861380E684E8888AFE9DA7E8E97236AC322B9CE2738EF245E9D46C9681665F83A1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Brisbane)]} {.. LoadTimeZoneFile Australia/Brisbane..}..set TZData(:Australia/Queensland) $TZData(:Australia/Brisbane)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):198
                                                                                                                                                                                                                                                          Entropy (8bit):4.752918480727309
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yIDRpGSHAIgSRrN/2DCa7QDCuRpyn:MByMjdpQYrt23QHpy
                                                                                                                                                                                                                                                          MD5:D226A0718185854DFE549E00856AA8D5
                                                                                                                                                                                                                                                          SHA1:94EE96FAE259D90C2FDF169DD95BD82B3171FFAE
                                                                                                                                                                                                                                                          SHA-256:D9DCFDC377901EC0C0FEB9CEA743C2C1425273F69A1BAA7BF3B74FEC5885B267
                                                                                                                                                                                                                                                          SHA-512:7EE29A7235CAAEF4889246B7A2241CA9A0D5D2B2E1D56B20141247C93B8736F17280F0D46004AC4588E137D1E76F661C779C906BBFC2B5F8FA73C19F7657F952
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Adelaide)]} {.. LoadTimeZoneFile Australia/Adelaide..}..set TZData(:Australia/South) $TZData(:Australia/Adelaide)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8338
                                                                                                                                                                                                                                                          Entropy (8bit):3.847525715050911
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:AZJigk42/yn8/dnQiAmcO38EJ8i/V9cYgCqMEjKeIZ3wQb25Ly04:AZJuVnQiAmcOM6e0pj
                                                                                                                                                                                                                                                          MD5:C0F1776E011C4C86B7709A592E7CA1EB
                                                                                                                                                                                                                                                          SHA1:1CA528D529BF4995E145D6E0D87A8752A3577E7F
                                                                                                                                                                                                                                                          SHA-256:FC453486325ADE1D31F14087B76D4936F3A6D551ABD1DB6FCAC129BDB043951C
                                                                                                                                                                                                                                                          SHA-512:F872182962C2615A35F012ECAB30C88F07C6BEF0261207AD52706DB22D8CDD0DA65723CD801FDA7C548C5EB0ECFC39DD66CC17503BAA3BBB77BFA35D20650E4F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Sydney) {.. {-9223372036854775808 36292 0 LMT}.. {-2364113092 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {89136000 39600 1 AEDT}.. {100022400 36000 0 AEST}.. {120585600 39600 1 AEDT}.. {131472000 36000 0 AEST}.. {152035200 39600 1 AEDT}.. {162921600 36000 0 AEST}.. {183484800 39600 1 AEDT}.. {194976000 36000 0 AEST}.. {215539200 39600 1 AEDT}.. {226425600 36000 0 AEST}.. {246988800 39600 1 AEDT}.. {257875200 36000 0 AEST}.. {278438400 39600 1 AEDT}.. {289324800 36000 0 AEST}.. {309888000 39600 1 AEDT}.. {320774400 36000 0 AEST}.. {341337600 39600 1 AEDT}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):195
                                                                                                                                                                                                                                                          Entropy (8bit):4.777331394201868
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yI4DVJHAIgxnvVWAN/2DC3neDCVDy:MByMjUQVv8At2+eKy
                                                                                                                                                                                                                                                          MD5:9C58D9EFBB03472BBDA76CE2FFAD4BB4
                                                                                                                                                                                                                                                          SHA1:30959E3681B64AE26F7FA3957887896C26AF7F19
                                                                                                                                                                                                                                                          SHA-256:C94FA7A7640CD00963EE8FF1A3D9DCDA2075408739D998EDBF7CFC998DB764FD
                                                                                                                                                                                                                                                          SHA-512:2D6B778217726691F2CB4A4995A8B1AB08DDB7FE4570A3FD04EF54F718F455EF3CBD4EEF1A1BCC99A2088C82A6E89DB455BAF1327CECD6BF608837E50F14A6C1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Hobart)]} {.. LoadTimeZoneFile Australia/Hobart..}..set TZData(:Australia/Tasmania) $TZData(:Australia/Hobart)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):204
                                                                                                                                                                                                                                                          Entropy (8bit):4.818875198673406
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yIvFfkSHAIgoFNNvN/2DCzyQDCMF4:MByMj9fKaNNvt2xQz4
                                                                                                                                                                                                                                                          MD5:0B144A2E47C81354BC510BC741DE5150
                                                                                                                                                                                                                                                          SHA1:A7396F1741F02C6C208FD1286362E4E0720198B8
                                                                                                                                                                                                                                                          SHA-256:DBEF9C5BDD290FEC5FA740D697143332D3CA1FC373CF1DF736F1883AC9BA3298
                                                                                                                                                                                                                                                          SHA-512:562B029591F9ADB8C324BA56E849B2B524E91B26D3DB441510194882A8E1E63E6948D041874A00A0A76F29925A1CEAC53DD2AE5D7F23123B6FE919346CBFD8CC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Melbourne)]} {.. LoadTimeZoneFile Australia/Melbourne..}..set TZData(:Australia/Victoria) $TZData(:Australia/Melbourne)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):188
                                                                                                                                                                                                                                                          Entropy (8bit):4.831654343064909
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq/xJjXFeyXHAIgoXjrWARL/2QWCCjH0QWCCjQ:SlSWB9vsM3yInHAIgOWAN/2DC00DCt
                                                                                                                                                                                                                                                          MD5:5F5916CB038876BE27AA5E2AD74EE085
                                                                                                                                                                                                                                                          SHA1:18AC21B638188B542455BA3DA91F958DF1724E68
                                                                                                                                                                                                                                                          SHA-256:75ABB7F20C4A0B618138AA190AF33CEAF2A6D2C707DA6C1314E4BFF2F9904F58
                                                                                                                                                                                                                                                          SHA-512:ADFD83E292AC1BB5E19255A9B2DA0E3BB9323A5F9B92D458DE34C291D7F9B6CFBBF62AA3351FB320E54F34305DD485ADC72134D21AFA6A27B2B8B7D93DCA2113
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Perth)]} {.. LoadTimeZoneFile Australia/Perth..}..set TZData(:Australia/West) $TZData(:Australia/Perth)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):212
                                                                                                                                                                                                                                                          Entropy (8bit):4.918079927018121
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yIcKlHAIgJK3N/2DCkuM0DC9KM:MByMjcKeJK3t2kVSKM
                                                                                                                                                                                                                                                          MD5:BEDEA56FCE4B2F0A3F3E9319856A5560
                                                                                                                                                                                                                                                          SHA1:9FD0FE998A003C6B4CCCD00A977153347DE07F55
                                                                                                                                                                                                                                                          SHA-256:55A9264D0414644A1BE342106AE86086A6659596DC9322A74FC4D1DDB41F7C60
                                                                                                                                                                                                                                                          SHA-512:7C438B72262B99EDEEB31AC95E0135BB722A3B0B049278B6DE67DB5FB501837FB9C03785233B538E83F4B56104F6EA3B3DA0F7C2275E0F78F232161840AA4C63
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Broken_Hill)]} {.. LoadTimeZoneFile Australia/Broken_Hill..}..set TZData(:Australia/Yancowinna) $TZData(:Australia/Broken_Hill)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):194
                                                                                                                                                                                                                                                          Entropy (8bit):4.888429541699473
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7thteSHAIgpth9RN/xWh490th4:MByMYdIp7tQ490I
                                                                                                                                                                                                                                                          MD5:A8A7A10DA4321819ED71F891480770F8
                                                                                                                                                                                                                                                          SHA1:930674EF7711542D7F471A59C1870D4576E027FD
                                                                                                                                                                                                                                                          SHA-256:2F594239A434052D36053A2B3EAB134EADBAD06EB6737E67CF72166DAB157537
                                                                                                                                                                                                                                                          SHA-512:C6AD1869A713DDE0E4DE53F7894E5CE0B7AEFDDD7C5C3D83BB5B92FB7D8E20B373A6694045053E1AE8EA98A7B7D0C052EF2C21310E47DC650A7A399A5F73D586
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Rio_Branco)]} {.. LoadTimeZoneFile America/Rio_Branco..}..set TZData(:Brazil/Acre) $TZData(:America/Rio_Branco)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.875339623736144
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0wKy4oeyXHAIg20wKARL/1bIAJl0IAcGEwKyovn:SlSWB9vsM3y7/rDSHAIgp/AN/xIAE90j
                                                                                                                                                                                                                                                          MD5:E0D0EFBEC37E27532B49FF6DD9893DA0
                                                                                                                                                                                                                                                          SHA1:9C00993A885AF448E48201A46E17629A7A602FC6
                                                                                                                                                                                                                                                          SHA-256:A676562A90FF8587A775F6F0E3BE05D870456A56D25B5330816BF9043C8D475B
                                                                                                                                                                                                                                                          SHA-512:AB0E6907F9C0002CA5C050A0069AF013B14BADA08CA4553C96B302C078DF7629D5D7EDE4A19A53DEC6E7B9E6D9857F14EC7A1DB9BC11F2EEC9FFBAC70E129EEE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Noronha)]} {.. LoadTimeZoneFile America/Noronha..}..set TZData(:Brazil/DeNoronha) $TZData(:America/Noronha)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):191
                                                                                                                                                                                                                                                          Entropy (8bit):4.948480276987682
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0tQJXveyXHAIg20tQJE6RL/1bJHIAcGEtQJXy:SlSWB9vsM3y7tIGSHAIgpt36N/xR90tF
                                                                                                                                                                                                                                                          MD5:FCCB5F44903E1B988A058E5BBF5E163B
                                                                                                                                                                                                                                                          SHA1:E1CC03DD4A804C7305D8B0C12D8451D08AE262EA
                                                                                                                                                                                                                                                          SHA-256:961FB3AB99A63B1E9704B737EAB2D588B5A39D253A213E175CC678BEDFFD498D
                                                                                                                                                                                                                                                          SHA-512:F31C80E4AD6EBE6CB8A3382E0052DC47601D073E8F81375D50241105675AA3AB45433FFD0534524D9992ABE1086C6671D85FF7C72B0D6766EB9984426F608B77
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Sao_Paulo)]} {.. LoadTimeZoneFile America/Sao_Paulo..}..set TZData(:Brazil/East) $TZData(:America/Sao_Paulo)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):182
                                                                                                                                                                                                                                                          Entropy (8bit):4.902113962502196
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0znQZF3vXHAIg20znQv5RL/1bbAWVIAcGEznQe:SlSWB9vsM3y7zn+PHAIgpznSN/xn90zN
                                                                                                                                                                                                                                                          MD5:9F4B43F4F27D0B7EAC0C5401A1A794B4
                                                                                                                                                                                                                                                          SHA1:2A8543B994E93E54BD50EAA78463905E6A8EBE74
                                                                                                                                                                                                                                                          SHA-256:0500C9A248C8CE9030EA30D0AF9DD95DC465480BAF60646C0B7C511FA23C6D1F
                                                                                                                                                                                                                                                          SHA-512:0ADAF708ACFBD80F4704951EEBC24AD144FD5856997A429279E804F3A7F7F9A8FED41DCEE85BFB1ECDBF1E05137E87E7430186474BCF5DE42067FFC74746F048
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Manaus)]} {.. LoadTimeZoneFile America/Manaus..}..set TZData(:Brazil/West) $TZData(:America/Manaus)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7736
                                                                                                                                                                                                                                                          Entropy (8bit):3.7984816540097843
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:09+xKDBb0S274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhlt7:9Ss41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:6DB983AD72FB2A88FC557BE5E873336F
                                                                                                                                                                                                                                                          SHA1:C64E988010087ED559A990B3D95078949C9B4D72
                                                                                                                                                                                                                                                          SHA-256:E2AEA7CFD428A43D9DB938BCC476623ADC1250BD8057013A7FFF5F89D7FF8EFC
                                                                                                                                                                                                                                                          SHA-512:C0A646F80FB2FD42D9146A4FD36CF5A7F62016684F8D5AF80453EC190F4AEA65EDADC5BCF071AE746ABFB43B29C27B2743F2152B6986D41BFDE1617CA774A7C5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:CET) {.. {-9223372036854775808 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766623600 3600 0 CET}.. {228877200 7200 1 CEST}.. {243997200 3600 0 CET}.. {260326800 7200 1 CEST}.. {276051600 3600 0 CET}.. {291776400 7200 1 CEST}.. {307501200 3600 0 CET}.. {323830800 7200 1 CEST}.. {338950800 3600 0 CET}.. {354675600 7200 1 CEST}.. {370400400 3600 0 CET}.. {386125200 7200 1 CEST}.. {401850000 3600 0 CET}.. {417574800 7200 1 CEST}.. {433299600 3600 0 CET}.. {449024400 7200 1 CEST}.. {465354000 3600 0 CET}.. {481078800 7200
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8505
                                                                                                                                                                                                                                                          Entropy (8bit):3.8095769056779916
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:e3HgahLi8hbZlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:eQaUqtfA604qSBgI7DBch
                                                                                                                                                                                                                                                          MD5:A6F88C55E8613A27DE3E6C25B0672910
                                                                                                                                                                                                                                                          SHA1:3B593CC17BF153A6209FC5AACE7B88DA9603BD44
                                                                                                                                                                                                                                                          SHA-256:73A9841F233AA657AFB6CED8A86A37D55FE5582DD996B9B28975D218BCCC078F
                                                                                                                                                                                                                                                          SHA-512:526A922B1594A2800B03F363F7BFEC29203D4A4F2B49C5F2618469F59176CE4F8AFBA0616B226AC39D308DB05DE7147714D9B6CDBB2EA7373A041A4D47F50E2E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:CST6CDT) {.. {-9223372036854775808 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-84384000 -18000 1 CDT}.. {-68662800 -21600 0 CST}.. {-52934400 -18000 1 CDT}.. {-37213200 -21600 0 CST}.. {-21484800 -18000 1 CDT}.. {-5763600 -21600 0 CST}.. {9964800 -18000 1 CDT}.. {25686000 -21600 0 CST}.. {41414400 -18000 1 CDT}.. {57740400 -21600 0 CST}.. {73468800 -18000 1 CDT}.. {89190000 -21600 0 CST}.. {104918400 -18000 1 CDT}.. {120639600 -21600 0 CST}.. {126691200 -18000 1 CDT}.. {152089200 -21600 0 CST}.. {162374400 -18000 1 CDT}.. {183538800 -21600 0 CST}.. {199267200 -18000 1 CDT}.. {215593200 -21600 0 CST}.. {230716800 -18000 1 CDT}.. {247042800 -21600 0 CST}.. {262771200
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.804821796604604
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx02NEO/vXHAIg202NEqA6RL/0nalGe2IAcGE2NEOyn:SlSWB9vsM3y7UEOXHAIgpUEqA6N/0af9
                                                                                                                                                                                                                                                          MD5:33A04963E70EBF29339204348E0DF874
                                                                                                                                                                                                                                                          SHA1:456C0DB88ECE4D180EEE5AE5AEF5FBEB6E977D00
                                                                                                                                                                                                                                                          SHA-256:6DC6354D761CBE7820C9186568CAB87AD48CA925507F6A740357195B60E16D87
                                                                                                                                                                                                                                                          SHA-512:DF8F46827760BD7EC922C6837E0B6649B4FBD220B79E6F1B67FE3DD8CB3D2D035ECDAF4CF6CE5BDE6DC79C6F7B6EE2B9787AF08A97845CD0D647720A2E78D7EF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Halifax)]} {.. LoadTimeZoneFile America/Halifax..}..set TZData(:Canada/Atlantic) $TZData(:America/Halifax)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):191
                                                                                                                                                                                                                                                          Entropy (8bit):4.863241040396457
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0po/vXHAIg20puFvHRL/0nPQox/h4IAcGEpoyn:SlSWB9vsM3y7pYHAIgppuRN/0d490pl
                                                                                                                                                                                                                                                          MD5:97E50CE9FBA3F1A6DFCF333F9E6D592C
                                                                                                                                                                                                                                                          SHA1:EE472C411079E788DBF32FAC9C5B7EE121960DC2
                                                                                                                                                                                                                                                          SHA-256:DB32E83949D62478D229E9FB57BB1624D21B3A9CCEE4CD55335F8262C01D820A
                                                                                                                                                                                                                                                          SHA-512:D547E3DC03848A677BE67F7CF4124E067F76EE09BB724A5B10F028BEA72C1526B17678A035B2C53F69498E9ECAACD3C5445D42B7FE58DF706DD2C5F2ADA05A73
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Winnipeg)]} {.. LoadTimeZoneFile America/Winnipeg..}..set TZData(:Canada/Central) $TZData(:America/Winnipeg)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):188
                                                                                                                                                                                                                                                          Entropy (8bit):4.758562813220951
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qMKLRXnXHAIg20qMKLRE6RL/0nbHboxp4IAcGEqM:SlSWB9vsM3y7RQtHAIgpRQPN/0Dboxpp
                                                                                                                                                                                                                                                          MD5:4365BEFA3D50EEE20843EF97A095E512
                                                                                                                                                                                                                                                          SHA1:7756049B4CD6459742686925E9516E64A9727306
                                                                                                                                                                                                                                                          SHA-256:22844994AE893F3236A091B050E932E84A5218EC0D01F72595E17CCC471FA564
                                                                                                                                                                                                                                                          SHA-512:CB265E79DF926026BEBF7158590369ABE5353C759540F509ABBA2A7ADBE59A705BC2AB936F400614BE610EDB761DE9A2B1E179A0A8B0A87E595392362C2516AA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Toronto)]} {.. LoadTimeZoneFile America/Toronto..}..set TZData(:Canada/Eastern) $TZData(:America/Toronto)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):192
                                                                                                                                                                                                                                                          Entropy (8bit):4.8181126338833655
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx07nKL50vXHAIg207nKLyRRL/0nNYLo/4IAcGE7nK1:SlSWB9vsM3y77G2HAIgp7bN/0W8/4908
                                                                                                                                                                                                                                                          MD5:FA0D0024AD72CCE4EC7229FA897FB1B7
                                                                                                                                                                                                                                                          SHA1:4373A07F2674FE974189CC801987652AA97F0204
                                                                                                                                                                                                                                                          SHA-256:D7A203E60FF19DCDEAAD14121720DE51DA73392D25B40FFA301C1935CDF89517
                                                                                                                                                                                                                                                          SHA-512:82EF7F429604A69734B04D298B4C9C9AC3BE57B9DD8C4CECF59C7AB3470BDFBA0505886C4E6AA3864F5EC7FBB4C69C54CF153A6417376828234833013C29A0C1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Edmonton)]} {.. LoadTimeZoneFile America/Edmonton..}..set TZData(:Canada/Mountain) $TZData(:America/Edmonton)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):196
                                                                                                                                                                                                                                                          Entropy (8bit):4.998628928230972
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7tgYJHAIgptVN/0xdBx+90twv:MByMYnKpTt590g
                                                                                                                                                                                                                                                          MD5:A2DCCB8BFC65DD4E7C3BB7F10DCEFF11
                                                                                                                                                                                                                                                          SHA1:6FD2F4FAE06C5D4D3F189A167A98AA76497569DD
                                                                                                                                                                                                                                                          SHA-256:87F42F45FD7D059CA47650D445420DE8320F3A7C1CBC7671FBFA8A8881274433
                                                                                                                                                                                                                                                          SHA-512:F42E32C5BD785BA914E5054784BF67DDF951460A708290D1899621CEEDC63475B584FC052A86A3B6D45BF3C651D42427FB6F9CE2A2A33764DFFF731053BECC16
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/St_Johns)]} {.. LoadTimeZoneFile America/St_Johns..}..set TZData(:Canada/Newfoundland) $TZData(:America/St_Johns)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):194
                                                                                                                                                                                                                                                          Entropy (8bit):4.887587766811186
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7ZLgXPHAIgpZLgFN/0N290ZLgK:MByMY13p1stx901/
                                                                                                                                                                                                                                                          MD5:68900CE38FE0E40578323BBD3D75184E
                                                                                                                                                                                                                                                          SHA1:9D5EAB5CBCD495DD46974207FBE354A81DD2070F
                                                                                                                                                                                                                                                          SHA-256:5C4FD46054B190A6D4B92585B4DAE4E3A8233EE2996D14472835DDD264911DC6
                                                                                                                                                                                                                                                          SHA-512:3EF53F0FCD8D88A1B977886BDFAA03D7B84EF021AC6BEDF7C571BFBF2242BFC3F3EB6A6B6A9C2F6852AF412A96DFBC30F3BB25A6619CBCD8736F3DF5B64DE1BF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Vancouver)]} {.. LoadTimeZoneFile America/Vancouver..}..set TZData(:Canada/Pacific) $TZData(:America/Vancouver)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.887593462838566
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0sAzE5Y5XHAIg20sAzEo5RL/0nogS64IAcGEsAzEB:SlSWB9vsM3y7hzi2HAIgphznN/0Hd499
                                                                                                                                                                                                                                                          MD5:A4237BDCAF68B0EFECA97178F3DEE724
                                                                                                                                                                                                                                                          SHA1:A9CBC02B5545A63A0C9B38C8FA7FA2DE6D483188
                                                                                                                                                                                                                                                          SHA-256:46BA00AE3A07A4DC83D6CB517D87C9CBBA491B3421FE9AD6C74CAC5695EB73F7
                                                                                                                                                                                                                                                          SHA-512:832BF256BE8CB2DD205DDE50017448D5830B46FF4DCA77BDB852067EE0C9DF9977014F2A3E3DD6944336158D8EA377CFBBE519EE5B56FB26EB64325B45476B9D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Regina)]} {.. LoadTimeZoneFile America/Regina..}..set TZData(:Canada/Saskatchewan) $TZData(:America/Regina)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):195
                                                                                                                                                                                                                                                          Entropy (8bit):4.889486451014262
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7peR2fkSHAIgppeR2rN/0CF/490peR24:MByMYkGk7pkOtBQ90kB
                                                                                                                                                                                                                                                          MD5:490D99BD5465CBF5A8FE28F33180B8A6
                                                                                                                                                                                                                                                          SHA1:4783295C31A804BE98145270ED28956A0783E655
                                                                                                                                                                                                                                                          SHA-256:A1B1AF37DC89C6BA663E4E967A18409AE4E0FA9EF1B908D0461368DA31001C09
                                                                                                                                                                                                                                                          SHA-512:9F6B4F204A21B69E1DFCB766C0671D3736414C73269DCEDCDB4FC3DBA869BBA1511DF6B5061F8964F0AF9C3816133D04E5DFB8A6AD07CA06E7712787A8FECC5A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Whitehorse)]} {.. LoadTimeZoneFile America/Whitehorse..}..set TZData(:Canada/Yukon) $TZData(:America/Whitehorse)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):194
                                                                                                                                                                                                                                                          Entropy (8bit):4.812019117774239
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7tfEJkHAIgptfEJo5N/0rHM490tfEJB:MByMYE9pEOt4X90EB
                                                                                                                                                                                                                                                          MD5:6EF54792279C249B16877100682F1806
                                                                                                                                                                                                                                                          SHA1:A62629EA055207D917740E3AEF4F0B005EA49CC4
                                                                                                                                                                                                                                                          SHA-256:5B40167DD0C0B5C293861070C4AC249F78DDF8BAD798DD0165E3AE894C9B9570
                                                                                                                                                                                                                                                          SHA-512:3CF93003C3EA2B4386660F0C87074F9AE2BAC4EE72D88451DCB1EA8B79502D2187B1608B6D5CE8D7EDC00AED99CF9DB7B006EB6ED2A2B5009F2C0E757D282D74
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Santiago)]} {.. LoadTimeZoneFile America/Santiago..}..set TZData(:Chile/Continental) $TZData(:America/Santiago)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.808907056781067
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG7ZAJWXHAIgObT7ZAiFvRL/0bxOdBx/nUDH7ZAZv:SlSWB9vsM3ycJAUHAIgObJAiRN/04dBn
                                                                                                                                                                                                                                                          MD5:2EC4FDD1EFBAF1D9F9DBAC8B1B5EDD09
                                                                                                                                                                                                                                                          SHA1:FECED8EBC7B666628B7B45C9694FCB3A0B20A42A
                                                                                                                                                                                                                                                          SHA-256:1E2DA1862E0E0F131B7C6EB12FAC5F920852C61C162993A30BC843A464A5AAD4
                                                                                                                                                                                                                                                          SHA-512:74D61141505BAF1ABAD61FB91941C63C169EFE3C85829FEBB4D29A72EA54D1A07EC84E2E9B48E963E65CBF7663245459FAD288D620B1BEFFE682A2D1C243794D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Easter)]} {.. LoadTimeZoneFile Pacific/Easter..}..set TZData(:Chile/EasterIsland) $TZData(:Pacific/Easter)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):175
                                                                                                                                                                                                                                                          Entropy (8bit):4.857134440822812
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx02TEMVFfXHAIg202TEyRRL/0lIAcGE2TEMy:SlSWB9vsM3y76EkHAIgp6EyRN/0l9068
                                                                                                                                                                                                                                                          MD5:3FB16EA4A9B0529220133C4A7B05215B
                                                                                                                                                                                                                                                          SHA1:BD56B6E76A92A5925140CB5CC3D940E1DE90993F
                                                                                                                                                                                                                                                          SHA-256:6F4F2D7F5BCA4E5183460C0153D2B98F5239A99F149DE6638B311C73CEDB1329
                                                                                                                                                                                                                                                          SHA-512:690EC1BCE7FA979BD55725B8ED6DF042BB331CAD332827B2C64B31F107539934AA5A30268B1F03D52697528E68A1BA72E4D56B5199A68B1ED897B75FAFB33A8A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Havana)]} {.. LoadTimeZoneFile America/Havana..}..set TZData(:Cuba) $TZData(:America/Havana)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7440
                                                                                                                                                                                                                                                          Entropy (8bit):3.695300167191082
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:CgDIMcVbf+uO7DVopaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlt:KlfyDjivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                                                                          MD5:34339D40AC889DCB5A09D10F123175AD
                                                                                                                                                                                                                                                          SHA1:57E1F70FA8999106FA3874A9CE1E75A7ACBC81E9
                                                                                                                                                                                                                                                          SHA-256:64E284F9F7A36CC0A352809141D76E73A99344A9F30CFFEA254CBB9D2C589ADA
                                                                                                                                                                                                                                                          SHA-512:2DCF16D9D7593FC3E5844E18FD689AADA157866490CFD37A38A47F747DDA189822055F6DD470CA2D77040D2C5A2527512880C22ED8EC16D9424EDF3DC228AFED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:EET) {.. {-9223372036854775808 7200 0 EET}.. {228877200 10800 1 EEST}.. {243997200 7200 0 EET}.. {260326800 10800 1 EEST}.. {276051600 7200 0 EET}.. {291776400 10800 1 EEST}.. {307501200 7200 0 EET}.. {323830800 10800 1 EEST}.. {338950800 7200 0 EET}.. {354675600 10800 1 EEST}.. {370400400 7200 0 EET}.. {386125200 10800 1 EEST}.. {401850000 7200 0 EET}.. {417574800 10800 1 EEST}.. {433299600 7200 0 EET}.. {449024400 10800 1 EEST}.. {465354000 7200 0 EET}.. {481078800 10800 1 EEST}.. {496803600 7200 0 EET}.. {512528400 10800 1 EEST}.. {528253200 7200 0 EET}.. {543978000 10800 1 EEST}.. {559702800 7200 0 EET}.. {575427600 10800 1 EEST}.. {591152400 7200 0 EET}.. {606877200 10800 1 EEST}.. {622602000 7200 0 EET}.. {638326800 10800 1 EEST}.. {654656400 7200 0 EET}.. {670381200 10800 1 EEST}.. {686106000 7200 0 EET}.. {701830800 10800 1 E
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):111
                                                                                                                                                                                                                                                          Entropy (8bit):4.924838898127838
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yLbNMXGm2OHLVva0v:SlSWB9eg/ylDm2OHLVi0v
                                                                                                                                                                                                                                                          MD5:B221E7141FFC9DEA317F64F81C7BB4E0
                                                                                                                                                                                                                                                          SHA1:B13BBDE790B169D8B9075275523F319D5173E2C7
                                                                                                                                                                                                                                                          SHA-256:6344BE02529C1CC5F7B5FE14B7E9BBCED4DDE68A24B824601EEBCAE207ABFDF2
                                                                                                                                                                                                                                                          SHA-512:FFFA733476D6C7DCF49C0B88C9F5E381DE2B69BAEDF6C7B1D91C6F45CE2D36E06D40F25B6BB65D4B5D650471BB52CD2EC3F68703DAB4BD5414F8D3F831D92BD2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:EST) {.. {-9223372036854775808 -18000 0 EST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8505
                                                                                                                                                                                                                                                          Entropy (8bit):3.8091719283634853
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:R+kNoStCt/cL1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:RXoSItON0HY2iUmUFLqU
                                                                                                                                                                                                                                                          MD5:4578FE48781599B55F4BCF5560019789
                                                                                                                                                                                                                                                          SHA1:4EAA7134621DFDEBFD1405F5CC58227FA7E80C3A
                                                                                                                                                                                                                                                          SHA-256:0BE6161403BC5A96BFAB174F2C3FCBA8A677D4349699B408E9872B9DD0FE15CE
                                                                                                                                                                                                                                                          SHA-512:9ACC2EF396F635D22E3DF6B785831AD74B510049F1BE85F996467A5BBC0DF49A28B2FC3E4CA0CA9DC8FC2C29EA50D909F0B153265B107445D3052E81D9A4D50A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:EST5EDT) {.. {-9223372036854775808 -18000 0 EST}.. {-1633280400 -14400 1 EDT}.. {-1615140000 -18000 0 EST}.. {-1601830800 -14400 1 EDT}.. {-1583690400 -18000 0 EST}.. {-880218000 -14400 1 EWT}.. {-769395600 -14400 1 EPT}.. {-765396000 -18000 0 EST}.. {-84387600 -14400 1 EDT}.. {-68666400 -18000 0 EST}.. {-52938000 -14400 1 EDT}.. {-37216800 -18000 0 EST}.. {-21488400 -14400 1 EDT}.. {-5767200 -18000 0 EST}.. {9961200 -14400 1 EDT}.. {25682400 -18000 0 EST}.. {41410800 -14400 1 EDT}.. {57736800 -18000 0 EST}.. {73465200 -14400 1 EDT}.. {89186400 -18000 0 EST}.. {104914800 -14400 1 EDT}.. {120636000 -18000 0 EST}.. {126687600 -14400 1 EDT}.. {152085600 -18000 0 EST}.. {162370800 -14400 1 EDT}.. {183535200 -18000 0 EST}.. {199263600 -14400 1 EDT}.. {215589600 -18000 0 EST}.. {230713200 -14400 1 EDT}.. {247039200 -18000 0 EST}.. {262767600
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):170
                                                                                                                                                                                                                                                          Entropy (8bit):4.862365884559795
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsPHV5XHAIgNGE7TRRL/yCh0DcPHy:SlSWB9vsM3y7fHAIgNTRN/yg0DH
                                                                                                                                                                                                                                                          MD5:ACD69F34396296BA553243267D06CEE0
                                                                                                                                                                                                                                                          SHA1:9575FFE5E7833B9532F17AC5413EA9DB23F07ECA
                                                                                                                                                                                                                                                          SHA-256:936B6484469351DEF8FAFE8EC180862729F5E43BDE4E53E2E9636E221B54C3C2
                                                                                                                                                                                                                                                          SHA-512:149D23FF35747127E9A2F4056D09472E8E689970BC795D5411C5BF621D949ADDEBDA68674D375A248A63106ABDFF6C54A8AFE5385C45BE2916CAED0C30F7C4A1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Cairo)]} {.. LoadTimeZoneFile Africa/Cairo..}..set TZData(:Egypt) $TZData(:Africa/Cairo)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):172
                                                                                                                                                                                                                                                          Entropy (8bit):4.901791318009318
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV5QH+o3vXHAIgoq6QHFRRL/yMQs/h8QanQHuv:SlSWB9vsM3ymnQeoPHAIgonQzN/yM/hm
                                                                                                                                                                                                                                                          MD5:E9C2C97EB65526F1D4BE1AD7385336FA
                                                                                                                                                                                                                                                          SHA1:09E4000CE320F779E2DFCA2FFD6B9258FFBA6CE4
                                                                                                                                                                                                                                                          SHA-256:B78A833337EFEC8B5F64622F1BFDA21FCB79CF290E9CF32A54B206EB20C6FDE9
                                                                                                                                                                                                                                                          SHA-512:EAEC097B58BF466CC7D6C0C6297628AF910CC308AC822565FD6CDABF96CD4EC57D4CC724FE782B6C1B606DFF9424013F6A890A871339577F7CB68BBB3C425E65
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Dublin)]} {.. LoadTimeZoneFile Europe/Dublin..}..set TZData(:Eire) $TZData(:Europe/Dublin)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):110
                                                                                                                                                                                                                                                          Entropy (8bit):4.928744204623185
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDMbNMXGm2OHvDwy:SlSWB9eg/yRQJDm2OHsy
                                                                                                                                                                                                                                                          MD5:9C08898081382F52CE681B592B8E2C8D
                                                                                                                                                                                                                                                          SHA1:165944424740B1FA9B4B3B8E622198ABD0BDA0F8
                                                                                                                                                                                                                                                          SHA-256:66B0DF8888883BFF44B18728B48CDF24AAED0BB745D601F3422C4F2D4063E0AC
                                                                                                                                                                                                                                                          SHA-512:86EA639F999169F2FBA2457BE5042463A1938031268CCA71FDD03CCBC6194932937BA58B49FBED461E055E9AA668FF6EBF391AA7EC603C0A425416DF2E6CC84D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT) {.. {-9223372036854775808 0 0 GMT}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):159
                                                                                                                                                                                                                                                          Entropy (8bit):4.910789466104329
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/yRDOm7/8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/yRSw8RQy
                                                                                                                                                                                                                                                          MD5:333F2BFA92742A49BB88F11C7CD896A9
                                                                                                                                                                                                                                                          SHA1:BB5BEC010C36427AEEBDDA2FB72083E22A3F5073
                                                                                                                                                                                                                                                          SHA-256:64466EA3759301E88C29AD1A833CDCBBC495EB4A5A3AC45E7B2987FECD6702BD
                                                                                                                                                                                                                                                          SHA-512:E2270F4B57C5F1C849726259B886E8644DCF497FA0D034AD48885146BEDC70DC8899900DA9AC01F2609A2DA881E10F9042CCBF75A3F5DA7344D7E92F1B070806
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/GMT+0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):116
                                                                                                                                                                                                                                                          Entropy (8bit):4.980500771169276
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDOveyXMXGm2OH1VOwVn:SlSWB9eg/yRSvPDm2OH1VOwV
                                                                                                                                                                                                                                                          MD5:A7C3FD06D1E06F125813C9687C42067C
                                                                                                                                                                                                                                                          SHA1:515622C0B63E977AFBFC78AD8466053C4A4A71A6
                                                                                                                                                                                                                                                          SHA-256:3BE1EC71D2CC88FA9A3DB7DC0476475F33FE5BCBE6BC35C0F083859766466C32
                                                                                                                                                                                                                                                          SHA-512:548DA608CFCA5B8539652F94CA2040D624602D2DF64B2C8CCDB8B219B9B384E01386CDF95F3BF77409DF0584FA12A3B73D56D13107D98BEB4C2555F458B3F374
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+1) {.. {-9223372036854775808 -3600 0 -01}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):118
                                                                                                                                                                                                                                                          Entropy (8bit):4.965033464829338
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDOPFNMXGm2OH1VYU7vV:SlSWB9eg/yRSPXDm2OH1VYW9
                                                                                                                                                                                                                                                          MD5:FF71149E56D4CB553D0ED949B5F4C122
                                                                                                                                                                                                                                                          SHA1:3459B47E0EEC80D7A29512CA4F3F236C89E86573
                                                                                                                                                                                                                                                          SHA-256:E61E826E6FBC2396EF152640698098F4477D4FFDFE5F791F62250C3EC5865304
                                                                                                                                                                                                                                                          SHA-512:43B0CC8BD7F1EFC80C3F14F115D651EADD5743B17B854C2FB7AC25995138D3DF8792915C2952B80F35784A7115F8FB335ACE171479B24C668190AC175523DB21
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+10) {.. {-9223372036854775808 -36000 0 -10}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):118
                                                                                                                                                                                                                                                          Entropy (8bit):5.002239901486653
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDOeJMXGm2OHaBByVn:SlSWB9eg/yRSsDm2OHa7yV
                                                                                                                                                                                                                                                          MD5:08AABA917A8D6B3BB3D0DD1637F5ABFC
                                                                                                                                                                                                                                                          SHA1:D1D704F0250D4CBD450922A02D021E0000FBF5CF
                                                                                                                                                                                                                                                          SHA-256:143528946275DDC8B894218D3F1BE56C950F740828CEC13166C3D7E8E1B6BB7E
                                                                                                                                                                                                                                                          SHA-512:F37AE54864A613C830308CB94AB7CEA9534A86A53B52B4A2C28CEEFE6F5BC0518143AAFD77A6DA5EC55D392F5BD34FCD4B5BE51794B1A386ED783B9BA89C10C3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+11) {.. {-9223372036854775808 -39600 0 -11}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):118
                                                                                                                                                                                                                                                          Entropy (8bit):4.97889339723103
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDONdNMXGm2OH3FNyUFFv:SlSWB9eg/yRSNDm2OH3XyMv
                                                                                                                                                                                                                                                          MD5:7374B66D6E883D7581E9561C3815EB92
                                                                                                                                                                                                                                                          SHA1:235E96A7420DF6733F3CA368D4A2D57766656043
                                                                                                                                                                                                                                                          SHA-256:A93EAFAC2C1089C608C8536127D0E8B53D8C7CFD13AE7DD69339E12A89F803C6
                                                                                                                                                                                                                                                          SHA-512:9BA59B17F20D65DFF1A5A2D557B535F69B04C172AECB15F88CA3484D74CC7D53894985C08653CF13D868BCBD5E7E5041E0CB2F457B5B603F3851198E552E33A7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+12) {.. {-9223372036854775808 -43200 0 -12}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):116
                                                                                                                                                                                                                                                          Entropy (8bit):4.922268982357521
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDOcF3vFNMXGm2OHnFQVIyV:SlSWB9eg/yRS0fXDm2OHnFQVb
                                                                                                                                                                                                                                                          MD5:FDDC663E40F8FFFE27959E94625725DF
                                                                                                                                                                                                                                                          SHA1:EE3FBC1F6C8BBCF1BDC9E5DB4D2EA1A57E2E9BB3
                                                                                                                                                                                                                                                          SHA-256:AD5833153446960BDE0653A22AE2111BF80CFD61C3010993CE87B81D40C75C72
                                                                                                                                                                                                                                                          SHA-512:A1B2A153834FEAD7DC27C0918E1B1CB905671F82850C1CAAEBD89F5535703FB259F02F699EA7F82F3044E37668EE93DFA4D4EB862CD437AFF0DABA84867B1963
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+2) {.. {-9223372036854775808 -7200 0 -02}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):4.949132511023475
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDOFfMXGm2OHBFVGAvFv:SlSWB9eg/yRSlDm2OHBFAKV
                                                                                                                                                                                                                                                          MD5:5C6F16F2CFD46030688066F9BFBE675D
                                                                                                                                                                                                                                                          SHA1:1DB5F36584822EB92E75B9AC9F440FD671BD90AE
                                                                                                                                                                                                                                                          SHA-256:C7BEE4C71905EDDB40BAF42C0CD0DC70BB9F298EAAB8B9367D484B8431DD084A
                                                                                                                                                                                                                                                          SHA-512:FFB2C4CD8EA7DE165C3D989454898FF2023D1A1E3B2B34EC23B1B71EFA7BF2538488DA0069E59F1152B8933D2263B762D2D7C56ADBED826C33FC0BA6672E34DB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+3) {.. {-9223372036854775808 -10800 0 -03}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):4.971627677226461
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDOqJMXGm2OHBvGQy:SlSWB9eg/yRSQDm2OHBON
                                                                                                                                                                                                                                                          MD5:E35244C1A6084C7BC1D79E437677C55C
                                                                                                                                                                                                                                                          SHA1:898619DA4B8B9AC72E69C7BD30DEA2ADEF9440FE
                                                                                                                                                                                                                                                          SHA-256:26D1EF512CC5797FC63BA2B83C7D6271025F4D4F5C904D9FA8E97F053393D9A7
                                                                                                                                                                                                                                                          SHA-512:0687758558C4C5FF7802F3A57212694A1515761A8337D4B75FFE81434D2AD8A221B005DEC36BF013F2FC3DE1E46DFBED36352811EB7C5A5AE3A167A2E314F57C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+4) {.. {-9223372036854775808 -14400 0 -04}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):4.956438091983076
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDOJNMXGm2OHLVvyV6Aov:SlSWB9eg/yRSDDm2OHLVKVg
                                                                                                                                                                                                                                                          MD5:7C560A0F3C42E399AC1247CB6C516DC6
                                                                                                                                                                                                                                                          SHA1:C314B09D4E369C69C23A8DC1FB066FD0CFDC7211
                                                                                                                                                                                                                                                          SHA-256:054910BDDFC44D9B806BBD3008C30547FA57ECD3C043418C406A725158144688
                                                                                                                                                                                                                                                          SHA-512:FCE8431B759BD5359847734FD98D9D91394916235B2AF587FC927D5F3196FB283E241A6A9200EA852F9265ECEF81402FF6ACD0FA3A4AAEF6DF9DB1B056B3A9EF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+5) {.. {-9223372036854775808 -18000 0 -05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):4.974743300958087
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDOAkSMXGm2OHvTmULyn:SlSWB9eg/yRSbSDm2OHviX
                                                                                                                                                                                                                                                          MD5:EEB1A3E0FD3339E332587D19C116D4EF
                                                                                                                                                                                                                                                          SHA1:5DBF046031CD354B1EF88E46D3FED74706D21AC6
                                                                                                                                                                                                                                                          SHA-256:D53BB247E0E429A6243AB9A9BDCAE1EE1CF5F271D79748A843631906AB63A988
                                                                                                                                                                                                                                                          SHA-512:07BDF9056DC335C773684E634B1D389FBD139464D4597DE862B7EAC096676A093934682BF911F4E68F299789931218C0E431F0CC6BEBD7275B5FC8015EDD0942
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+6) {.. {-9223372036854775808 -21600 0 -06}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):4.930134062078826
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDONeyFNMXGm2OHrXVYVny:SlSWB9eg/yRSNPDm2OHriVy
                                                                                                                                                                                                                                                          MD5:F92B31548D6BF8CCFA326C0CA6E205A0
                                                                                                                                                                                                                                                          SHA1:3FFC6C214EDBCBE9C2509306CE73B429113E1C8A
                                                                                                                                                                                                                                                          SHA-256:6BA5779E35D581B409F53B14B6E28ECC16F536FFEDD45DDBC8DAE4B8C28F66E7
                                                                                                                                                                                                                                                          SHA-512:317872E986099D02AF083397AE936854043D54CEBF45A70672F02DDC9E2F3B27BC3FA80902F9675131C51A09BBD3C2BD1CD437330935CEA113C643769E0DF20C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+7) {.. {-9223372036854775808 -25200 0 -07}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):4.915798027862021
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDOOF3vXMXGm2OHmFvGpn:SlSWB9eg/yRSqfXDm2OHaOp
                                                                                                                                                                                                                                                          MD5:B31B15E6006F8DF0D7627D6C90FF39AF
                                                                                                                                                                                                                                                          SHA1:7C4137BE11DA84771DF6DC5EBC32D5E5E87E060F
                                                                                                                                                                                                                                                          SHA-256:CA87559B154B165E83482AEE3D753BA8E38ABCA347A005E8504C566433CF4CB3
                                                                                                                                                                                                                                                          SHA-512:220F7E7379EABBC8ACD7ADBB7A4AC8E93E4B268F8F1C0965B7E6A09735EE86E293EF1C492990331EEB4176B8301A91EC20579756B962AE45C858A96C09349CCD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+8) {.. {-9223372036854775808 -28800 0 -08}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):4.95764928386407
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDO3fMXGm2OHNms:SlSWB9eg/yRSPDm2OHNms
                                                                                                                                                                                                                                                          MD5:5B10173EB7119F1219250763504A3526
                                                                                                                                                                                                                                                          SHA1:A845021437C4638079040EF27AEF163C865FF8F8
                                                                                                                                                                                                                                                          SHA-256:A0987A1D078B0993FB3B07208E3F4538A2319DCDDDEB2FAEA32FC463DEAFB8DB
                                                                                                                                                                                                                                                          SHA-512:D213285D0A723B7771263122AFA269C2ABD0325A97D32C3870341255C06597DD6851C22860CFF42BF54E3FF5A36FC88C306F3BF1C69E7BD7FD7F69FE7601ED1A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+9) {.. {-9223372036854775808 -32400 0 -09}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):159
                                                                                                                                                                                                                                                          Entropy (8bit):4.898210849752128
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/yRDIyHp8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/yRUyJ8RQy
                                                                                                                                                                                                                                                          MD5:5AFB7F12BA056619252D48904523DFA9
                                                                                                                                                                                                                                                          SHA1:CD6E6681C8302BF38095975DF556BD14959FDAC8
                                                                                                                                                                                                                                                          SHA-256:EFF27B3DEE9306641FF344801E06BB33FF768CDCCFE2409FA8AF752FF6D39F66
                                                                                                                                                                                                                                                          SHA-512:2869BB347F42667A3D174816466B15916FC61FCB5A6A1BE1DD750C5C1751602FEE0FE5A27651B7A19C9F6764872DD0F00D3D5AA16CA1A743DBA09646D25A4EB2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/GMT-0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):115
                                                                                                                                                                                                                                                          Entropy (8bit):4.979902281541545
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDI/fMXGm2OHMKUrn:SlSWB9eg/yRUXDm2OHtUr
                                                                                                                                                                                                                                                          MD5:4000096844091488200125FC8F50E2F5
                                                                                                                                                                                                                                                          SHA1:9FFEAE66405CFB254180C7DBE185288791DFEE5F
                                                                                                                                                                                                                                                          SHA-256:B4BF883FBE9246EF4079179A746B1F9E59F2C77D4F598794B60732D198DC6044
                                                                                                                                                                                                                                                          SHA-512:25C69E04018C2978A2E5748F0D3C61157453D998C16FA4B3C257A6515B87F5FD2B754893B47604BBC60AB60B60BA162BF2D1463E616E72CB8713C736F1B4D428
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-1) {.. {-9223372036854775808 3600 0 +01}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):4.964101313797091
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDINFeyFNMXGm2OHMUUMy:SlSWB9eg/yRUN5XDm2OHXFy
                                                                                                                                                                                                                                                          MD5:AE6601FACF6BE1E68083F8D353901181
                                                                                                                                                                                                                                                          SHA1:8B3BFA307D2A94BADD3A1A5E42545D6F7C620BCE
                                                                                                                                                                                                                                                          SHA-256:EF3046D7789CAE069B5473D053F3EF0157248F8A359A1282EE02BA613A75FC94
                                                                                                                                                                                                                                                          SHA-512:1859E6A2CB94EFEE7CD5C17803AA4F2DEEBE4DCF43D3B1EA737DF00BA86ECEC79D296D75E69D5829DECB48380B6B650724104FFA7959FD18FE032DF7D002A88B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-10) {.. {-9223372036854775808 36000 0 +10}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):5.00162575418652
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDIVSMXGm2OHlVVtyn:SlSWB9eg/yRUVSDm2OHlVLy
                                                                                                                                                                                                                                                          MD5:D864BA451C9E441BF47D233626C57B99
                                                                                                                                                                                                                                                          SHA1:6C38E6F8BA292575C496124572D187F97C9F8E73
                                                                                                                                                                                                                                                          SHA-256:CCDEADBD18BE81E59A669A460A14AFCBFF733C3A5D164FC2B6B93DEAF009B78A
                                                                                                                                                                                                                                                          SHA-512:5C16BD1189F3FE6789CB3630C841FD168EC87D0498EE6FCC4C8D635F8CF4BCAF0558B44F859C37E418F6BC5A7F6693D6EF1DD218A1DB6DA2D54FF55916685119
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-11) {.. {-9223372036854775808 39600 0 +11}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):4.978079707159482
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDIjbNMXGm2OHwvv0UIoAov:SlSWB9eg/yRUjJDm2OHwvv0YAov
                                                                                                                                                                                                                                                          MD5:C3E7748C7CB9D8A7F7FA5170D5098983
                                                                                                                                                                                                                                                          SHA1:54F5374A32173BEC6EDA430745DCD18749ABC233
                                                                                                                                                                                                                                                          SHA-256:23B61B18C653E25F7245B0BB6E04AD347E038585B145962FD1EEACE26F118D54
                                                                                                                                                                                                                                                          SHA-512:4783A7CD4C94CCC67C1C71F9C5D9CD99A3918EA4792D8CE2443ACE8F034B9023EBC02405B5DEAB919AA35FD1FD29D8980774316AC96D32ECDEBEFA15BBE6878D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-12) {.. {-9223372036854775808 43200 0 +12}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):4.994320173226919
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDIaMXGm2OH1dNv7Dy:SlSWB9eg/yRUaDm2OHty
                                                                                                                                                                                                                                                          MD5:224AAAA8A31C283F50149A090E3970D5
                                                                                                                                                                                                                                                          SHA1:E7E4876EC2474FEFD82D4B174CA8E3A3427062F5
                                                                                                                                                                                                                                                          SHA-256:A9F1AD5A7CB5ED43C5E6E8A7A9B887329890ABB75B9FC9483B8543A367457EBE
                                                                                                                                                                                                                                                          SHA-512:6EE0C6F519AAB2DAA3F7D802F0F838BA9F6BF1D56530000D3C9EA4FDA81DCB9832A3285E36208F29EEB23C27EC5BFD3438DC272929A7531268B7C0626A65D6A5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-13) {.. {-9223372036854775808 46800 0 +13}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):117
                                                                                                                                                                                                                                                          Entropy (8bit):4.9895752453470585
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDIxhfMXGm2OH0FVtXvFv:SlSWB9eg/yRUxJDm2OH8jNv
                                                                                                                                                                                                                                                          MD5:8ADF71739DCADE63433B7BF8321EAC77
                                                                                                                                                                                                                                                          SHA1:AA6BDE83FF0D8BCFDE0426160250F2D17D3AF81D
                                                                                                                                                                                                                                                          SHA-256:A37A7160027BD38356764C4D1AA5B9B17F8D5DC3CFB81EF2ED399E44C41734CE
                                                                                                                                                                                                                                                          SHA-512:AEE3929DE269ADB5265A54841F041E41595359C101539F6309A4E737E3F5DF0BC91560781C7118975398C29A084113682C78F66E07E2E4AC5EAC8DFC33C4F0ED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-14) {.. {-9223372036854775808 50400 0 +14}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):115
                                                                                                                                                                                                                                                          Entropy (8bit):4.921164129348819
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDInWNMXGm2OH/VXF9:SlSWB9eg/yRUnSDm2OH/Vb
                                                                                                                                                                                                                                                          MD5:CABB864F4E76B90928F5C54CD9334DEB
                                                                                                                                                                                                                                                          SHA1:4818D47F83F16B9F7612D1E979B2440C170ECDB9
                                                                                                                                                                                                                                                          SHA-256:7211BF8329B2388563ED8FA8C5140099A171B8A303A9473E9A6F3AF0C5D239CB
                                                                                                                                                                                                                                                          SHA-512:1FDCB05D675F1D28CB52B9F5EAC7EC52FDF2CE7E7411740A6F8FB5E9D443ED636CE268E3AF9E08605CC3E13A49B2D86FF4EA6A85F518D5C79E263BA94263361D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-2) {.. {-9223372036854775808 7200 0 +02}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):116
                                                                                                                                                                                                                                                          Entropy (8bit):4.948161547682094
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDIYyXMXGm2OHkNsWYcv:SlSWB9eg/yRUlDm2OHkKWYe
                                                                                                                                                                                                                                                          MD5:4AE5F29A13A86E4A7064E9200668E43B
                                                                                                                                                                                                                                                          SHA1:2460BD1BB0FF3A3C774A5C7CC3DA10235DA06B0D
                                                                                                                                                                                                                                                          SHA-256:BFC86D65B0B94725DCE4C88EDC4300141ABBCA4B6CDECF037C437DF49F0C1D6A
                                                                                                                                                                                                                                                          SHA-512:190DC38B4A20F964C967866507086317D85D979DFCFA415D1569C485C6476024922BC6E7103273C41889D9D7B22E97933F286FCF4D341248077C1BA777D0EE3B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-3) {.. {-9223372036854775808 10800 0 +03}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):116
                                                                                                                                                                                                                                                          Entropy (8bit):4.970850637731657
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDIQXMXGm2OHkVsRYovV:SlSWB9eg/yRUQXDm2OHkSN
                                                                                                                                                                                                                                                          MD5:BBAF760E27C02D176A675AC3CF2D1E6D
                                                                                                                                                                                                                                                          SHA1:E524FAA7D424A1C1545D1D8EC00169125A68E8E5
                                                                                                                                                                                                                                                          SHA-256:02E2EEAF88EE179EF63DD29ACC7384A4B46DE1E3A151C1F3A5DD31BBB5A05AEE
                                                                                                                                                                                                                                                          SHA-512:6AC7CC0E52E7793C7F2D3DDA9551709DEAE654C1182EAD7108D04F1BAAAB7E1C473B6E8A3A126B0E421D8A246294A03B2EE9E070330924502DF2869CC61C37F7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-4) {.. {-9223372036854775808 14400 0 +04}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):116
                                                                                                                                                                                                                                                          Entropy (8bit):4.955530107787899
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDI7tNMXGm2OHM0VQVFv:SlSWB9eg/yRU7PDm2OHnVQVV
                                                                                                                                                                                                                                                          MD5:17F64A5969D3755211E60C0A9F83974F
                                                                                                                                                                                                                                                          SHA1:FEFA84725EFAE6405F43797296C342B974F2D272
                                                                                                                                                                                                                                                          SHA-256:3A2C75DCA11D1167126F0D44A8682420FAF75B0B82B3DCFC35A9F028A9A759E8
                                                                                                                                                                                                                                                          SHA-512:77DBCD8284A470E4869976E2E8A5EDE28104283F120C863785A6B2E64CF87E06243196817C0055A9B32D6FFFE94A25772F67D58BF8E885F7EC06C34FABE38766
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-5) {.. {-9223372036854775808 18000 0 +05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):116
                                                                                                                                                                                                                                                          Entropy (8bit):4.973993120288556
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDIg3fMXGm2OHETNSTVVn:SlSWB9eg/yRUgPDm2OHETMX
                                                                                                                                                                                                                                                          MD5:51CAF7956E133C8A9788AE0B8C6145AB
                                                                                                                                                                                                                                                          SHA1:47F8B49DF9ED477BD95F908693A483AE4FDE881F
                                                                                                                                                                                                                                                          SHA-256:D22C87321373EC0EFB0F312925476CD0747323EF303E17621A871BF814C8ABB1
                                                                                                                                                                                                                                                          SHA-512:EC4B4BE74C1BA64DEC8EF11DAAA338C52BD67D55E8A2352FBC6C83FA142F8DBE424CC1110E9A9D9A891E1E858D1FFA6D1E3B997D41BBB374556FA1F9A708559E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-6) {.. {-9223372036854775808 21600 0 +06}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):116
                                                                                                                                                                                                                                                          Entropy (8bit):4.928999319005163
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDIpdNMXGm2OHAXUVSYovV:SlSWB9eg/yRURDm2OHAXUVSYyV
                                                                                                                                                                                                                                                          MD5:56D88B54CA33B43E2E7D3EA6AD3A4D6E
                                                                                                                                                                                                                                                          SHA1:9351E0C001C5D83325281AF54363D76D65548B7D
                                                                                                                                                                                                                                                          SHA-256:70CB3A766A2E84148B68613D68687D263D3592ED4B6E672797FB20801ECA8231
                                                                                                                                                                                                                                                          SHA-512:32B58AD16F64590903C7AB49BA4890DAF6F1F3D33187A7654D3DA88A1C0047483EAA58B2498D824A30116E235FCC8F8FB3FADD57F86396240E5D92B2CA337027
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-7) {.. {-9223372036854775808 25200 0 +07}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):116
                                                                                                                                                                                                                                                          Entropy (8bit):4.9145396982864895
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDIlSMXGm2OHN/VsdYLyn:SlSWB9eg/yRUlSDm2OHUp
                                                                                                                                                                                                                                                          MD5:E462AD5E0C046EA6769EDB4B2C80F4D4
                                                                                                                                                                                                                                                          SHA1:6DDB94485648622875E0927BA1E8CFE67CEC1382
                                                                                                                                                                                                                                                          SHA-256:80C85D59416CEC91DB3DAC5FDD2FD7B91D6FC74A37BBBEF6FF58F6F6816E8FC9
                                                                                                                                                                                                                                                          SHA-512:42734FD2DA8BD6E0BC271FF1375A31DEB72EED85AB5EA6E1E0F81EE4E3E7E74380FFC98FAC30409684F736DB580AAAF4F62DB4757AA35C10383584F6144EF363
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-8) {.. {-9223372036854775808 28800 0 +08}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):116
                                                                                                                                                                                                                                                          Entropy (8bit):4.956751740978211
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRDIeyXMXGm2OHENScFAy:SlSWB9eg/yRUPDm2OHsScr
                                                                                                                                                                                                                                                          MD5:98F70EC1B1AC7D38CB8D01705FB0CA56
                                                                                                                                                                                                                                                          SHA1:EDAFA132E48935ACEB8E72D3FF463E4FC857C1A9
                                                                                                                                                                                                                                                          SHA-256:57395BB968AFA5A041EADA4B684B82F0379A9333F9522D69F069A79FDEA2B8D7
                                                                                                                                                                                                                                                          SHA-512:97B8D7603D6B54C075B005B905B2A7A28B8BEA67894F055663C44D2BF730BB937AC8EF5B2DF182BDD2D9EFFDBD135DF9467C813AEE39AA6B34256908A12DC011
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-9) {.. {-9223372036854775808 32400 0 +09}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):158
                                                                                                                                                                                                                                                          Entropy (8bit):4.886484135647838
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/yRDVMFHp8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/yRC1p8RQy
                                                                                                                                                                                                                                                          MD5:F879FB24EA976394B8F4FAF1A9BF268C
                                                                                                                                                                                                                                                          SHA1:903714237EBD395A27EAF00B3DAAA89131267EE5
                                                                                                                                                                                                                                                          SHA-256:AB742F93BE44BD68AB8FE84505FA28120F1808765D9BAED32A3490AF7C83D35B
                                                                                                                                                                                                                                                          SHA-512:F5EE4C331E37036516F2A1BF12F2E088B2E2C7F6475127BF4E7B4937F864550D64D570BC855B6058D4311755E8696EC42095A36AEF13BB29E62192EE0AFB6EAF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/GMT0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):163
                                                                                                                                                                                                                                                          Entropy (8bit):4.911342539638601
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/yRp+FB5yRDMovn:SlSWB9vsM3yFXHAIgnvVHN/yRp6BURQy
                                                                                                                                                                                                                                                          MD5:CDD2DE9CF0FECFEA0CDD32DAC32DCDE2
                                                                                                                                                                                                                                                          SHA1:311CD4C6E819E18BAAACC382F81359BC208E2F73
                                                                                                                                                                                                                                                          SHA-256:F89167B6117838D9679C0397496B6D96D3A7BEAEF0BD99406ABACDBDB658FBCC
                                                                                                                                                                                                                                                          SHA-512:1AF061D07D2F579A089905B6B259AABD7C58F4FA0CD379EE54206164F0DCAEA5C720FB1F5E76F5782F8613E62D8F83BD55F1848D5D7A73D4A5C9F7BC6B9F5DB1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/Greenwich) $TZData(:Etc/GMT)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):157
                                                                                                                                                                                                                                                          Entropy (8bit):4.838936002050477
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/yRKh8RFB:SlSWB9vsM3yzTHAIgm6N/yR68RX
                                                                                                                                                                                                                                                          MD5:0587EB7D1B1C684A4A0F90D3CB0959C8
                                                                                                                                                                                                                                                          SHA1:3F2840AE512774494D9A0B6357C52CCB7DBA5265
                                                                                                                                                                                                                                                          SHA-256:0856D14DBBC53D46460BCD530BD070E9E8966D1C96BA01BA556E215A98C09CD4
                                                                                                                                                                                                                                                          SHA-512:DE38EF28893853219AC24AE4A522307ADAA1502F6D0C129219FAD9D75CFCE03A505C3E0758CFF2D2D4F7101414A5F7E4FC1C1B119B667E6A9C89B60DDA641E86
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Etc/UCT) $TZData(:Etc/UTC)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):110
                                                                                                                                                                                                                                                          Entropy (8bit):4.903699772785336
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/yRF3yFNMXGm2OHvL:SlSWB9eg/yR9SDm2OHj
                                                                                                                                                                                                                                                          MD5:3D3F94B6AC5FA232E509356C703D9177
                                                                                                                                                                                                                                                          SHA1:502B8EE9D4A1EA75A91272181AC87B9B6ECE1F84
                                                                                                                                                                                                                                                          SHA-256:4D74D9EC2397B1708FEF47806294B0BCA26679F3A63149AE24E4E0C641976970
                                                                                                                                                                                                                                                          SHA-512:205A761A01C577F602236CB5C9938C834B7F3F9F681B94036B0A86101119893EF87D206D0C3F7737075ED833D4E35E374ACAE6605163E9C37B705D99BEBC928C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/UTC) {.. {-9223372036854775808 0 0 UTC}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):163
                                                                                                                                                                                                                                                          Entropy (8bit):4.874807282103623
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/yRYzXDJMFfh8RFB:SlSWB9vsM3yzTHAIgm6N/yRY7VMr8RX
                                                                                                                                                                                                                                                          MD5:65E28EFF342B625E79175793FD38F9FD
                                                                                                                                                                                                                                                          SHA1:08B11474822E670DEAB8F0EA168BAED7D5E3DBE1
                                                                                                                                                                                                                                                          SHA-256:A2B62C5914DE169A68A018A5B47C1253DBCA10A251862D17B0781ECFD19B6192
                                                                                                                                                                                                                                                          SHA-512:79641D0E05F81BFB80034937D34E74B7483A790F33C1F9A0FA92C6A7913AC8C03036CFDEFB43850B84EFB3DD3C4A39022DC8F22E5B5DE6353586A546E03A5789
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Etc/Universal) $TZData(:Etc/UTC)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):158
                                                                                                                                                                                                                                                          Entropy (8bit):4.874356623237119
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/yRaQEBURFB:SlSWB9vsM3yzTHAIgm6N/yRYaRX
                                                                                                                                                                                                                                                          MD5:EDABCAC858EC9632D5D8DCCFB28F4D6E
                                                                                                                                                                                                                                                          SHA1:E5BEF1367A97A1900749CE6B1E01CF32F582BDD9
                                                                                                                                                                                                                                                          SHA-256:BBD6E93206FF3B7017AFBE63905B4C932C422B582F3CE2A79A7B885D390EE555
                                                                                                                                                                                                                                                          SHA-512:3A22364D423F2F970123561408018A2B72F43C4978836D3B6DF7517217445605838DCB8DDBDA204FD01C49A4A7D5ADAD4CA8BDA7C3B412D54750BAEAA589B683
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Etc/Zulu) $TZData(:Etc/UTC)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.892809684252761
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/So3vXHAIgoq82yHRL/yQaiFAXowQahCv:SlSWB9vsM3ymhS2HAIgoh26N/ywAXoww
                                                                                                                                                                                                                                                          MD5:B0B409D665190569A56697799FBA5CD3
                                                                                                                                                                                                                                                          SHA1:840AA7D61E64ACE61FDDAB96F716575A61CEDB52
                                                                                                                                                                                                                                                          SHA-256:46141E7BC0F99D2117319C661569F8B38AF7D00108CED5784FA3A3B5090EF8E9
                                                                                                                                                                                                                                                          SHA-512:D7C0588D98AC46B5191D7C7E8F5181E94306EFFCC9E3F2DBA9E0003BAE51D992334527ADDD6D0C9701CFD60169A74984B3401E7A6A1322A734BC3D90DCC933BC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Brussels)]} {.. LoadTimeZoneFile Europe/Brussels..}..set TZData(:Europe/Amsterdam) $TZData(:Europe/Brussels)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6927
                                                                                                                                                                                                                                                          Entropy (8bit):3.8182041031531897
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:CA34elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxOrnW+:CI41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:D897DCA686A03495EB2C3323FAB0BEAD
                                                                                                                                                                                                                                                          SHA1:1433BC303DE92F7B36F881C8595A42B35E0814FC
                                                                                                                                                                                                                                                          SHA-256:F0B48DA7CA3659450D87CC0DDFDDFD28B464543DF1EE40D935C44D5CD7C9B9B3
                                                                                                                                                                                                                                                          SHA-512:A1C4AE1E0EC26B159B0F5D058A7A77B8774F611A4D3C6AECEDD7186957D6BD9F15CDFCBA248FCC8A4B4146BD72CD7D66B9F88A2BF7CDEF416F1831A2F335D48C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Andorra) {.. {-9223372036854775808 364 0 LMT}.. {-2177453164 0 0 WET}.. {-733881600 3600 0 CET}.. {481078800 7200 0 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600 0 CET}.. {606877200 7200 1 CEST}.. {622602000 3600 0 CET}.. {638326800 7200 1 CEST}.. {654656400 3600 0 CET}.. {670381200 7200 1 CEST}.. {686106000 3600 0 CET}.. {701830800 7200 1 CEST}.. {717555600 3600 0 CET}.. {733280400 7200 1 CEST}.. {749005200 3600 0 CET}.. {764730000 7200 1 CEST}.. {780454800 3600 0 CET}.. {796179600 7200 1 CEST}.. {811904400 3600 0 CET}.. {828234000 7200 1 CEST}.. {846378000 3600 0 CET}.. {859683600 7200 1 CEST}.. {877827600 3600 0 CET}.. {891133200 7200 1 CEST}.. {909277200 3600 0 CET}.. {922582800 7200 1 CEST}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2063
                                                                                                                                                                                                                                                          Entropy (8bit):3.679377249443024
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:TvCAs6kKR6aQmF1cSNWrI+AjXgV/Ap40FjDOP:rCAs6kC6aZF1cSN4I+AjXgV/ApDFjDM
                                                                                                                                                                                                                                                          MD5:CB860328FA96A14055BF51A3B2D35A08
                                                                                                                                                                                                                                                          SHA1:CFA49DC861F4AC3D29A78D63D71C2D6D83D68F84
                                                                                                                                                                                                                                                          SHA-256:4B5FB0AF225974D117374028285F20A02B833FF4136E6BFAE7B65E6D6D28829E
                                                                                                                                                                                                                                                          SHA-512:960152826F4245012462E53F80B69B0C45C27D75D46C70D485674CA19071DF268671C7691B614BE53B9E7BD8CFEC5D24F3DCF933F2F14D827F2A32EB347D7540
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Astrakhan) {.. {-9223372036854775808 11532 0 LMT}.. {-1441249932 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 +04}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 14400 0 +04}.. {701820000 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748998000 10800 0 +03}.. {764722800 14400 1 +04}.. {7
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7954
                                                                                                                                                                                                                                                          Entropy (8bit):3.7252594544513795
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:1D/8QdzFu+f+uO7DVopaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYf:Z/8ohvyDjivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                                                                          MD5:8B2C99E1CD04D7559709FDF8D382343C
                                                                                                                                                                                                                                                          SHA1:C595D5159C742B815AF89EC8604376E01291F9F1
                                                                                                                                                                                                                                                          SHA-256:47353319419505AAB205C23F8C97EA0B12E5DED2113147794F77B67349AFF52F
                                                                                                                                                                                                                                                          SHA-512:227CA21A3B6160357988582E261A62AE7B09D46D479EABFAC8039185D710EFA765CD1694F4388EBF8800978A1E1DB69F6AF9BB9BF82C0FCD66E883930E1F8249
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Athens) {.. {-9223372036854775808 5692 0 LMT}.. {-2344642492 5692 0 AMT}.. {-1686101632 7200 0 EET}.. {-1182996000 10800 1 EEST}.. {-1178161200 7200 0 EET}.. {-906861600 10800 1 EEST}.. {-904878000 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844477200 7200 1 CEST}.. {-828237600 3600 0 CET}.. {-812422800 7200 0 EET}.. {-552362400 10800 1 EEST}.. {-541652400 7200 0 EET}.. {166485600 10800 1 EEST}.. {186184800 7200 0 EET}.. {198028800 10800 1 EEST}.. {213753600 7200 0 EET}.. {228873600 10800 1 EEST}.. {244080000 7200 0 EET}.. {260323200 10800 1 EEST}.. {275446800 7200 0 EET}.. {291798000 10800 1 EEST}.. {307407600 7200 0 EET}.. {323388000 10800 1 EEST}.. {338936400 7200 0 EET}.. {347148000 7200 0 EET}.. {354675600 10800 1 EEST}.. {370400400 7200 0 EET}.. {386125200 10800 1 EEST}.. {401850000 7200 0 EET}.. {417574800 10800 1 EEST}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):182
                                                                                                                                                                                                                                                          Entropy (8bit):4.876296755647751
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/yQahs3QavKL81n:SlSWB9vsM3ymvKA2PHAIgovKAH6N/y72
                                                                                                                                                                                                                                                          MD5:7160C6EE32380846653F016AE8AFD52A
                                                                                                                                                                                                                                                          SHA1:DE7805089639C54893F2107FA67342DA72A79BBC
                                                                                                                                                                                                                                                          SHA-256:557023674F6E8376707517103EE69C1DEBBE53CDD4BCAB11E763CC53B9CB1908
                                                                                                                                                                                                                                                          SHA-512:FDBDECBBDB0C419226E2604608FD2923CFB06E4B6948493208FD83FD796880E81F6147C0FAFEB572079C9C916831B7B055620EC939164CCA1DAF76897BE60F2C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Belfast) $TZData(:Europe/London)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7309
                                                                                                                                                                                                                                                          Entropy (8bit):3.8204712502914653
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:lp+/4elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxOrnW+:lY41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:02A003411B61A311896A6407B622152A
                                                                                                                                                                                                                                                          SHA1:3B8BC6D1AF698CE7BB14A08307F5A4295EB8ED03
                                                                                                                                                                                                                                                          SHA-256:74B225511B518B0CED972CBB33D694697712CCB96A6D81E0F50ADA28CF6E2C92
                                                                                                                                                                                                                                                          SHA-512:9E03B3EB1E528E5B1ADBA09F808E73BF9C4314EDCBF6F96E46844D51A5F425BED3EE8FD5BA8706C46A7FB9882485F119F81996F2EAB7E1E9B598978C402DDE0F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Belgrade) {.. {-9223372036854775808 4920 0 LMT}.. {-2713915320 3600 0 CET}.. {-905824800 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-788922000 3600 0 CET}.. {-777942000 7200 1 CEST}.. {-766623600 3600 0 CET}.. {407199600 3600 0 CET}.. {417574800 7200 1 CEST}.. {433299600 3600 0 CET}.. {449024400 7200 1 CEST}.. {465354000 3600 0 CET}.. {481078800 7200 1 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600 0 CET}.. {606877200 7200 1 CEST}.. {622602000 3600 0 CET}.. {638326800 7200 1 CEST}.. {654656400 3600 0 CET}.. {670381200 7200 1 CEST}.. {686106000 3600 0 CET}.. {701830800 7200 1 CEST}.. {717555600 360
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8020
                                                                                                                                                                                                                                                          Entropy (8bit):3.820756136386754
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:Pi9+qFR274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxo:PQs41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:84027C3C8315BD479B38DE11F38E873F
                                                                                                                                                                                                                                                          SHA1:6E92A2A9734A9C6B02ECCD99F114D667C909C5BA
                                                                                                                                                                                                                                                          SHA-256:7E7111F06288069B52A4E1CA0B016216DF9328FB3B1560A740146497CCDD4D24
                                                                                                                                                                                                                                                          SHA-512:5FFDE523021FC0C490261F55999204C9CE6C8C274888525EA6EE7C01BC5CCABC7A3877FD454B4167D81F4B89BACB087E8BA6AB0BAC46C2874ED9257BE2092340
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Berlin) {.. {-9223372036854775808 3208 0 LMT}.. {-2422054408 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-776559600 10800 0 CEMT}.. {-765936000 7200 1 CEST}.. {-761180400 3600 0 CET}.. {-757386000 3600 0 CET}.. {-748479600 7200 1 CEST}.. {-733273200 3600 0 CET}.. {-717631200 7200 1 CEST}.. {-714610800 10800 1 CEMT}.. {-710380800 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654130800 7200 1 CEST}.. {-639010800 3600 0 CET}.. {315529200 3600 0 CET}.. {323830800 7200
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.943205109348136
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVtXrAeovXHAIgoquXrsY6RL/yQahcvEB5yQazXrH:SlSWB9vsM3ymzbAeSHAIgozbsY6N/y7c
                                                                                                                                                                                                                                                          MD5:C69AB60BE74D4BB7E31BE4E5ECCD8FD2
                                                                                                                                                                                                                                                          SHA1:9DD0BA6171080F074858EF88ADA2E91C1F465619
                                                                                                                                                                                                                                                          SHA-256:1D7C539AAA1E3AD5EF3574A629523B5B781F1A91D352C9B39B8DE7316756026E
                                                                                                                                                                                                                                                          SHA-512:C273B97CCFB5F328EB7A13CCA3126DE8D91B3876CBD248990C0BE063DDBE5B0F31EA138E31A1C5C43B1ABCF42EA511448E6DC589EB99E8172D7C2A68BA31A8E7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Prague)]} {.. LoadTimeZoneFile Europe/Prague..}..set TZData(:Europe/Bratislava) $TZData(:Europe/Prague)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9223
                                                                                                                                                                                                                                                          Entropy (8bit):3.8450929464870804
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:RhcSQnG1Czyc1+FdDKDBb0S274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcM:Rh8zyc4Ss41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:E6C1153C3F71C8C005D7A46DDF6461FB
                                                                                                                                                                                                                                                          SHA1:CBDF7D5D36AF57D83859C910B493464617EC9571
                                                                                                                                                                                                                                                          SHA-256:1402A2072ADC9EBB35F4C0368D2E9A7A11493626C667C022614FFB7CC05B6CB6
                                                                                                                                                                                                                                                          SHA-512:8B1B47678F75DBE59DB08E034F0701BD11FF4FD3AD0304C8ABF45E848F717D2787B8E47558D3C334D369E0938C633DC217178D3EAE6486CEFBE25CF1668479F6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Brussels) {.. {-9223372036854775808 1050 0 LMT}.. {-2840141850 1050 0 BMT}.. {-2450995200 0 0 WET}.. {-1740355200 3600 0 CET}.. {-1693702800 7200 0 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1613826000 0 0 WET}.. {-1604278800 3600 1 WEST}.. {-1585530000 0 0 WET}.. {-1574038800 3600 1 WEST}.. {-1552266000 0 0 WET}.. {-1539997200 3600 1 WEST}.. {-1520557200 0 0 WET}.. {-1507510800 3600 1 WEST}.. {-1490576400 0 0 WET}.. {-1473642000 3600 1 WEST}.. {-1459126800 0 0 WET}.. {-1444006800 3600 1 WEST}.. {-1427677200 0 0 WET}.. {-1411952400 3600 1 WEST}.. {-1396227600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364778000 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333328400 0 0 WET}.. {-1316394000 3600 1 WEST}.. {-1301263200 0 0 WET}.. {
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7974
                                                                                                                                                                                                                                                          Entropy (8bit):3.7264631277913853
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:vMSsQMAz5CXNU5paNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBK0:vMS1kdUoivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                                                                          MD5:88DB5686937D3499A8142413B2CF2EB5
                                                                                                                                                                                                                                                          SHA1:E37BAD2127553600D0E38A43053D1B07B2498DA8
                                                                                                                                                                                                                                                          SHA-256:C560D45104A8DD73FC7370B5AC1615E22043DBC93DFB46A9ECC6468C2D38B19A
                                                                                                                                                                                                                                                          SHA-512:375B8A63CFF2E278CD8C78BF9DBC86288FFB1AD57DAED00CD2199F0B05F4FBFA7D17D93C6458B20B86F6D05F3E3A49D594E60AC97DDB47141E21D7CDE10F8456
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Bucharest) {.. {-9223372036854775808 6264 0 LMT}.. {-2469404664 6264 0 BMT}.. {-1213148664 7200 0 EET}.. {-1187056800 10800 1 EEST}.. {-1175479200 7200 0 EET}.. {-1159754400 10800 1 EEST}.. {-1144029600 7200 0 EET}.. {-1127700000 10800 1 EEST}.. {-1111975200 7200 0 EET}.. {-1096250400 10800 1 EEST}.. {-1080525600 7200 0 EET}.. {-1064800800 10800 1 EEST}.. {-1049076000 7200 0 EET}.. {-1033351200 10800 1 EEST}.. {-1017626400 7200 0 EET}.. {-1001901600 10800 1 EEST}.. {-986176800 7200 0 EET}.. {-970452000 10800 1 EEST}.. {-954727200 7200 0 EET}.. {296604000 10800 1 EEST}.. {307486800 7200 0 EET}.. {323816400 10800 1 EEST}.. {338940000 7200 0 EET}.. {354672000 10800 0 EEST}.. {370396800 7200 0 EET}.. {386121600 10800 1 EEST}.. {401846400 7200 0 EET}.. {417571200 10800 1 EEST}.. {433296000 7200 0 EET}.. {449020800 10800 1 EEST}.. {465
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8287
                                                                                                                                                                                                                                                          Entropy (8bit):3.8244305880244567
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:rHw0+D5xp4elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxo:rQXj41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:11468F958796F971ADD5FB1A0C426D78
                                                                                                                                                                                                                                                          SHA1:3FA58BEF391BCF7BAC6A124D093B6505B4EAC452
                                                                                                                                                                                                                                                          SHA-256:B58F3E9066B8B57EB037D509636AA67A06ACC8348BE6C48482D87CDC49844A4E
                                                                                                                                                                                                                                                          SHA-512:0492EABD6EE16392C00A196AF38995E5F9E55E30A82A50EFFB381DC978E9E63E801555CDC219869E6251BD51115972F742D8A7D9524372B8B11702AE4B28BFB7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Budapest) {.. {-9223372036854775808 4580 0 LMT}.. {-2498260580 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1640998800 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1600470000 7200 1 CEST}.. {-1587250800 3600 0 CET}.. {-1569711600 7200 1 CEST}.. {-1555196400 3600 0 CET}.. {-906775200 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-788922000 3600 0 CET}.. {-778471200 7200 1 CEST}.. {-762656400 3600 0 CET}.. {-749689200 7200 1 CEST}.. {-733276800 3600 0 CET}.. {-717634800 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-686185200 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654130800 7200 1 CEST}.. {-639010800 3600 0 CET}.. {-492656400 7
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):183
                                                                                                                                                                                                                                                          Entropy (8bit):4.952483060656419
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVnCMPfXHAIgoqkCM4ARL/yQahDZALMFB5h8Qa5CMS:SlSWB9vsM3ym5XPHAIgo5gAN/y7D17/f
                                                                                                                                                                                                                                                          MD5:CED145F8D9B231234E021D2214C1064B
                                                                                                                                                                                                                                                          SHA1:7B111DC24CA01C78A382CECD3247CF495D71CD34
                                                                                                                                                                                                                                                          SHA-256:F511A80AB70FF93A0EB9F29293F73DF952B773BB33EB85D581E4FB1FE06E4F05
                                                                                                                                                                                                                                                          SHA-512:E2323C04BF99909ABA9A09A66F9B4696519B5F9FE3AF178FB04D5E0053F41CAA8B937DC4148954ED093D317F454E0547786BEC934F2ABF22A60AAA6A24E63BF9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Zurich)]} {.. LoadTimeZoneFile Europe/Zurich..}..set TZData(:Europe/Busingen) $TZData(:Europe/Zurich)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8096
                                                                                                                                                                                                                                                          Entropy (8bit):3.7635458172251406
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:jXSsijEpkv2XkN8qc/OyEie8hF5WQ9VX/Zs1cw27oXqdCA5XqjqFLigTE9s5VpJ:jXS+WeUqKie8hF5f9PwdXM9
                                                                                                                                                                                                                                                          MD5:E7F52393523729CA3916768B3F3B4E55
                                                                                                                                                                                                                                                          SHA1:1524A3E610DCD33AC0006946BAB2929CA7F5A33F
                                                                                                                                                                                                                                                          SHA-256:2BD1C0AB412A5E9C97F533C4D06B773D045215B92568A4E89ADC93C7462D62EC
                                                                                                                                                                                                                                                          SHA-512:218674ECD9FD6C1A1C83EE69AFE6AA5AD0D5A8BB59FF497FDF2573B7CF52DAE98ECE0815CF99668CA4E172FF67D220B227369865076333B3EE802A8839C65279
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Chisinau) {.. {-9223372036854775808 6920 0 LMT}.. {-2840147720 6900 0 CMT}.. {-1637114100 6264 0 BMT}.. {-1213148664 7200 0 EET}.. {-1187056800 10800 1 EEST}.. {-1175479200 7200 0 EET}.. {-1159754400 10800 1 EEST}.. {-1144029600 7200 0 EET}.. {-1127700000 10800 1 EEST}.. {-1111975200 7200 0 EET}.. {-1096250400 10800 1 EEST}.. {-1080525600 7200 0 EET}.. {-1064800800 10800 1 EEST}.. {-1049076000 7200 0 EET}.. {-1033351200 10800 1 EEST}.. {-1017626400 7200 0 EET}.. {-1001901600 10800 1 EEST}.. {-986176800 7200 0 EET}.. {-970452000 10800 1 EEST}.. {-954727200 7200 0 EET}.. {-927165600 10800 1 EEST}.. {-898138800 7200 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-800154000 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.925156646979837
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/y+YF3vXHAIgoq8yFRRL/yQagKVihh8Qahyuv:SlSWB9vsM3ymhVoPHAIgoh6N/yy87Fv
                                                                                                                                                                                                                                                          MD5:3AEDE4B340D0250D496C49CADBA04E62
                                                                                                                                                                                                                                                          SHA1:C466D8275C465752F5B024615268F6D1CBBA4B41
                                                                                                                                                                                                                                                          SHA-256:2B9A0F1775355E311FB63903E3829F98B5F6C73C08F1BECE1A2D471ACC2673E3
                                                                                                                                                                                                                                                          SHA-512:2B08B57D58699C65A9AAA43AC87F29DD1EDCBA9F91E79DF4B1E07832032F5B03A43847E20345484730E8D2323199E7439D8C1FC662E812E8BA6EE19C53C89681
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Europe/Copenhagen) $TZData(:Europe/Berlin)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9810
                                                                                                                                                                                                                                                          Entropy (8bit):3.7678769652077873
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:sExxHZiMU8EKTy74jT56XdEN1+UZBdMN186LPR:sEzZiMUZ6y0jT5bZHMN186LPR
                                                                                                                                                                                                                                                          MD5:E1EB426EA3351AF0D7D563006F9146BC
                                                                                                                                                                                                                                                          SHA1:1E94F3B38366FE43BB031A57D19894B569EBABED
                                                                                                                                                                                                                                                          SHA-256:895957521D6CA4DE7E4089DC587A6C177B803D8ADF63303B1F85DEB279726324
                                                                                                                                                                                                                                                          SHA-512:8F24E9519F5D42F34AEE5C52A94CAC7D035EAE7B31DC3E629C29CFE3BD85F1510188290D35CD327492A030168443FED8BD80EC57ED27811B786C4DC89B4B1181
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Dublin) {.. {-9223372036854775808 -1521 0 LMT}.. {-2821649679 -1521 0 DMT}.. {-1691962479 2079 1 IST}.. {-1680471279 0 0 GMT}.. {-1664143200 3600 1 BST}.. {-1650146400 0 0 GMT}.. {-1633903200 3600 1 BST}.. {-1617487200 0 0 GMT}.. {-1601848800 3600 1 BST}.. {-1586037600 0 0 GMT}.. {-1570399200 3600 1 BST}.. {-1552168800 0 0 GMT}.. {-1538344800 3600 1 BST}.. {-1522533600 0 0 GMT}.. {-1517011200 0 0 IST}.. {-1507500000 3600 1 IST}.. {-1490565600 0 0 IST}.. {-1473631200 3600 1 IST}.. {-1460930400 0 0 IST}.. {-1442786400 3600 1 IST}.. {-1428876000 0 0 IST}.. {-1410732000 3600 1 IST}.. {-1396216800 0 0 IST}.. {-1379282400 3600 1 IST}.. {-1364767200 0 0 IST}.. {-1348437600 3600 1 IST}.. {-1333317600 0 0 IST}.. {-1315778400 3600 1 IST}.. {-1301263200 0 0 IST}.. {-1284328800 3600 1 IST}.. {-1269813600 0 0 IST}.. {-1253484000 3600 1 IST
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9509
                                                                                                                                                                                                                                                          Entropy (8bit):3.8837074152297704
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:QTOKVA1oCobz0W4x2+ZE74elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNA:QyoCvTZ641sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:D04F8EDDA1C3611692FB91E317CCADFE
                                                                                                                                                                                                                                                          SHA1:1C483FC95459EC6F1D5FE4DD275879A9EBCA1718
                                                                                                                                                                                                                                                          SHA-256:0524A31131405347C1D5D86C5EE38A2064AB055C030AB3B43F25DB3B28FFD8D2
                                                                                                                                                                                                                                                          SHA-512:4E2E18EBDE2765F2251B1FE41EF8E6AC79875617348974A28619F5E59EC0467239C682CCE8DEBD7A698BE2F00252C77D1F7FA50B6CAFF920B3BE53A0B836F815
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Gibraltar) {.. {-9223372036854775808 -1284 0 LMT}.. {-2821649916 0 0 GMT}.. {-1691964000 3600 1 BST}.. {-1680472800 0 0 GMT}.. {-1664143200 3600 1 BST}.. {-1650146400 0 0 GMT}.. {-1633903200 3600 1 BST}.. {-1617487200 0 0 GMT}.. {-1601848800 3600 1 BST}.. {-1586037600 0 0 GMT}.. {-1570399200 3600 1 BST}.. {-1552168800 0 0 GMT}.. {-1538344800 3600 1 BST}.. {-1522533600 0 0 GMT}.. {-1507500000 3600 1 BST}.. {-1490565600 0 0 GMT}.. {-1473631200 3600 1 BST}.. {-1460930400 0 0 GMT}.. {-1442786400 3600 1 BST}.. {-1428876000 0 0 GMT}.. {-1410732000 3600 1 BST}.. {-1396216800 0 0 GMT}.. {-1379282400 3600 1 BST}.. {-1364767200 0 0 GMT}.. {-1348437600 3600 1 BST}.. {-1333317600 0 0 GMT}.. {-1315778400 3600 1 BST}.. {-1301263200 0 0 GMT}.. {-1284328800 3600 1 BST}.. {-1269813600 0 0 GMT}.. {-1253484000 3600 1 BST}.. {-1238364000 0 0 GMT}
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):183
                                                                                                                                                                                                                                                          Entropy (8bit):4.879252060643389
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/yQakQAL/yQavKL81n:SlSWB9vsM3ymvKA2PHAIgovKAH6N/yYU
                                                                                                                                                                                                                                                          MD5:07AF23DA01CB963EA9E57534E34E7704
                                                                                                                                                                                                                                                          SHA1:1C4A214FF3B722E80C0ECACA0FFD5DFF302F6AE9
                                                                                                                                                                                                                                                          SHA-256:F7046808A8E80B7AE449D1A49AE3E480096736B7D3F554A240C7DFB10F82076A
                                                                                                                                                                                                                                                          SHA-512:713860D340C0EBA5EEF873ECB9B28CCDE9BFAD31B6A8626EF507E96585F5CC1091BF8D8A2DB7E5CB532E44F4561FBAE1797141724EF934755B69919FEA09A78A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Guernsey) $TZData(:Europe/London)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7368
                                                                                                                                                                                                                                                          Entropy (8bit):3.7258352536809705
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:OsR0uO7DVopaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBKb0hzj:OkyDjivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                                                                          MD5:7FF902B06FA79F14553670A70E77FF8C
                                                                                                                                                                                                                                                          SHA1:0105051541F38956EA6192BD0C7ED4047668005E
                                                                                                                                                                                                                                                          SHA-256:5B5C0A9261A414EA8DC34F594EE05BEE16F695488B230857D2B569A6B603BC39
                                                                                                                                                                                                                                                          SHA-512:551940199783A0FF9D73695B77B10300644F50E91D6B02FE79BB0CD4B78C7BA88CCE56F4B9408EC146361BF408F52D01A1F435183360C801EA5E219FB718247F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Helsinki) {.. {-9223372036854775808 5989 0 LMT}.. {-2890258789 5989 0 HMT}.. {-1535938789 7200 0 EET}.. {-875671200 10800 1 EEST}.. {-859773600 7200 0 EET}.. {354672000 10800 1 EEST}.. {370396800 7200 0 EET}.. {386121600 10800 1 EEST}.. {401846400 7200 0 EET}.. {410220000 7200 0 EET}.. {417574800 10800 1 EEST}.. {433299600 7200 0 EET}.. {449024400 10800 1 EEST}.. {465354000 7200 0 EET}.. {481078800 10800 1 EEST}.. {496803600 7200 0 EET}.. {512528400 10800 1 EEST}.. {528253200 7200 0 EET}.. {543978000 10800 1 EEST}.. {559702800 7200 0 EET}.. {575427600 10800 1 EEST}.. {591152400 7200 0 EET}.. {606877200 10800 1 EEST}.. {622602000 7200 0 EET}.. {638326800 10800 1 EEST}.. {654656400 7200 0 EET}.. {670381200 10800 1 EEST}.. {686106000 7200 0 EET}.. {701830800 10800 1 EEST}.. {717555600 7200 0 EET}.. {733280400 10800 1 EEST}.. {749
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):186
                                                                                                                                                                                                                                                          Entropy (8bit):4.914274131294981
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/yQaqpfioxp8QavKLS:SlSWB9vsM3ymvKA2PHAIgovKAH6N/ycS
                                                                                                                                                                                                                                                          MD5:F9A0F19FAF3131D8A70C50FF21B365B7
                                                                                                                                                                                                                                                          SHA1:7FC2B5302FAD06BC4C633CD22A80A7D40073FFF8
                                                                                                                                                                                                                                                          SHA-256:2F1151B0528A5325443379D4E7CCE32C00213722AD9DF764E1DC90198084B076
                                                                                                                                                                                                                                                          SHA-512:6D04DF4480FE132A6641C4BF7E01936E2E4A71A3A6C2AB9F7DA7A9D8A4B836BC66EE2BB597B8C318D07A06F72C05B07E6785B53308ED9BC1103AE6DBDD0FF24E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Isle_of_Man) $TZData(:Europe/London)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3683
                                                                                                                                                                                                                                                          Entropy (8bit):3.814835316757376
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Qi0p05zvSPBUUl0ZFzo4ay0CREDcxn6nH78BV0QbCgkCPviiM0H7hdli80+j7x9L:Qiq66OFEIFMssCfMsXV3heM2MRlA0
                                                                                                                                                                                                                                                          MD5:A8256656B971F58CB991BC270BF93B26
                                                                                                                                                                                                                                                          SHA1:189796E1B8E29A7A7B8B0E143DD9B44BAF217AB2
                                                                                                                                                                                                                                                          SHA-256:08061A80FC0F1EF375EEFE784EACDF0812E289FD67E8613BDEC36209985CA1D7
                                                                                                                                                                                                                                                          SHA-512:1F11308B5BAC1F3DB75CAC7322BBEA6E51C6B4A2A3450F1DB84DE6AA127F0F1BAA7DAB409FAF1288C100BDA77DA6FA1C6E3C0BA962F9406D1445D7C9E2AA3A60
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Istanbul) {.. {-9223372036854775808 6952 0 LMT}.. {-2840147752 7016 0 IMT}.. {-1869875816 7200 0 EET}.. {-1693706400 10800 1 EEST}.. {-1680490800 7200 0 EET}.. {-1570413600 10800 1 EEST}.. {-1552186800 7200 0 EET}.. {-1538359200 10800 1 EEST}.. {-1522551600 7200 0 EET}.. {-1507514400 10800 1 EEST}.. {-1490583600 7200 0 EET}.. {-1440208800 10800 1 EEST}.. {-1428030000 7200 0 EET}.. {-1409709600 10800 1 EEST}.. {-1396494000 7200 0 EET}.. {-931053600 10800 1 EEST}.. {-922676400 7200 0 EET}.. {-917834400 10800 1 EEST}.. {-892436400 7200 0 EET}.. {-875844000 10800 1 EEST}.. {-764737200 7200 0 EET}.. {-744343200 10800 1 EEST}.. {-733806000 7200 0 EET}.. {-716436000 10800 1 EEST}.. {-701924400 7200 0 EET}.. {-684986400 10800 1 EEST}.. {-670474800 7200 0 EET}.. {-654141600 10800 1 EEST}.. {-639025200 7200 0 EET}.. {-622087200 10800 1 EEST}.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):181
                                                                                                                                                                                                                                                          Entropy (8bit):4.8801202136140915
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/yQap6cEBx/yQavKLS:SlSWB9vsM3ymvKA2PHAIgovKAH6N/yzx
                                                                                                                                                                                                                                                          MD5:FE10770868A75F4F8D76C5E23D99AA81
                                                                                                                                                                                                                                                          SHA1:30AC768BA47AF7A53831F5142B58ECEC41933621
                                                                                                                                                                                                                                                          SHA-256:97EB33915ED7C9C34144F8F42357FAB2262B3CD45287F3CFFD26C33D65F7651E
                                                                                                                                                                                                                                                          SHA-512:1D82DF45AB0CCDFBFAD0431C668794996E01776800F34DD4131C5287D37291657A749D497AA5B0AB81CAFF3190896633FBFF456BFFEB7E93A3420AA841E54842
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Jersey) $TZData(:Europe/London)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2512
                                                                                                                                                                                                                                                          Entropy (8bit):3.941165221943348
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:coNlj+X2uxhuHJkw0QqXknzaVV04v3TfdGY3kNmneVuNlh000sGpdh:coN9+1EpkwCXkSV3A8qc0
                                                                                                                                                                                                                                                          MD5:104CCB93300F40BAF8F4D7CC882EFC05
                                                                                                                                                                                                                                                          SHA1:EA83F3C3791BD6F083844939DC405B248E738FE3
                                                                                                                                                                                                                                                          SHA-256:2387D26DF5429DF9867F42F7D4F872DC146643B4B3CC57DA7298C18561DE8BFE
                                                                                                                                                                                                                                                          SHA-512:12724C5BBEE0835626A98B66BF55C3DF1311F07018C70D76FC5C50E7E7BA5C4A9F064D9EDC376CC3B06C4FFFECA3FAF5B66948615A03DFECA7C361E326D950EA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Kaliningrad) {.. {-9223372036854775808 4920 0 LMT}.. {-2422056120 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-780368400 7200 0 EET}.. {-778730400 10800 1 EEST}.. {-762663600 7200 0 EET}.. {-749095200 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):173
                                                                                                                                                                                                                                                          Entropy (8bit):4.970386708540243
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV2cvXHAIgoq1csFARL/yQaoM2EBUQaocqn:SlSWB9vsM3ym5HAIgoiAN/yOEBUC
                                                                                                                                                                                                                                                          MD5:74ACF46A3248341CFD84B1592F884A8F
                                                                                                                                                                                                                                                          SHA1:888FBB54381A1B5BC19E65AF38A1913635A8E7E4
                                                                                                                                                                                                                                                          SHA-256:05C55F87182F0D5D3E8E6C1F9164EDDBDB8035146A0955C04283BC1347D45B30
                                                                                                                                                                                                                                                          SHA-512:21A752390E023CBD582BC43865D43458B44B036299A2373948269196071742ED7EB6067DD9A288F3A15E808B452FE4192750FAE813F70738FAB0C866219D57CB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Kyiv)]} {.. LoadTimeZoneFile Europe/Kyiv..}..set TZData(:Europe/Kiev) $TZData(:Europe/Kyiv)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2029
                                                                                                                                                                                                                                                          Entropy (8bit):3.8660567822471537
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:FFvCAs6kKR6aQmF1cSNWrI+7VmTeCTU50x0Y7:FhCAs6kC6aZF1cSN4I+7VmTeCTUax0Y7
                                                                                                                                                                                                                                                          MD5:98AF41BC0A39CB3A67286A7EAC4448B8
                                                                                                                                                                                                                                                          SHA1:436DF41B98766653FA6B687509D4DC099722AF66
                                                                                                                                                                                                                                                          SHA-256:71FBA6C221176ED891B3A7895A53A8FE669126A6904F05DBAE2B6CF2B2A01063
                                                                                                                                                                                                                                                          SHA-512:952B7DAB3241753A3958434BC265C3B6C2568054A73BBB19FCB289E8ABD70AC6C1A30380238FFC45598853CEF58E1466FECF652ABA6D79E24E73C44BC3E27B63
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Kirov) {.. {-9223372036854775808 11928 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 MSD}.. {606870000 14400 1 MSD}.. {622594800 10800 0 MSK}.. {638319600 14400 1 MSD}.. {654649200 10800 0 MSK}.. {670374000 14400 0 +04}.. {701820000 10800 0 MSD}.. {701823600 14400 1 MSD}.. {717548400 10800 0 MSK}.. {733273200 14400 1 MSD}.. {748998000 10800 0 MSK}.. {764722800 14400 1 MSD}.. {78044
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7455
                                                                                                                                                                                                                                                          Entropy (8bit):3.7624983280224953
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:vC1LyEpkv8V3MpaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBKb4:vC9VW0bivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                                                                          MD5:F37C7529B53C4C158341AF90F80C3A11
                                                                                                                                                                                                                                                          SHA1:210650A882350D35C72A934749F276C58C572DFA
                                                                                                                                                                                                                                                          SHA-256:591264F69DB19DDCDC90E704525E2D3D3984117B710F482F19DA8F88628EE6A7
                                                                                                                                                                                                                                                          SHA-512:F23B0C5251EB7418A1C80344AB7623D2A0197E681E3B7D152E416187BF66DE09A7A60A65F8ED6A810272CF0C253D63684F08AF594A8C22ABEA89E3BBADC8F0A0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Kyiv) {.. {-9223372036854775808 7324 0 LMT}.. {-2840148124 7324 0 KMT}.. {-1441159324 7200 0 EET}.. {-1247536800 10800 0 MSK}.. {-892522800 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-825382800 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 14400 1 MSD}.. {622594800 10800 0 MSK}.. {638319600 14400 1 MSD}.. {646786800 10800 1 EEST}.. {686102400 7200 0 EET}.. {701827200 10800 1 EEST}.. {7175
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9878
                                                                                                                                                                                                                                                          Entropy (8bit):3.8275310275285723
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:j76abXsyZLEjx82YbtIaFF1w0us4qE3+sSGjT:j77bXsyZLEjx82atysLE3+sSGjT
                                                                                                                                                                                                                                                          MD5:0DA331C2A815739E6758797BD24554EA
                                                                                                                                                                                                                                                          SHA1:3829C441E908BEFDC4ED6AB65FD4ACD0C97D5E1B
                                                                                                                                                                                                                                                          SHA-256:9FAC9812411F88014779D34722F3E0D2750E45BF21595DF1AE14CB9CCFD3F33F
                                                                                                                                                                                                                                                          SHA-512:FEBBA05F64AC1F3066AF6351493DD89768154FD171D447503DAEDB90D16858BEDBCE4A74E24AC0C37B5FF191692AF44AADDE4A92E752F88C48DA646352AD9A0B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Lisbon) {.. {-9223372036854775808 -2205 0 LMT}.. {-2713908195 -2205 0 LMT}.. {-1830384000 0 0 WET}.. {-1689555600 3600 1 WEST}.. {-1677801600 0 0 WET}.. {-1667437200 3600 1 WEST}.. {-1647738000 0 0 WET}.. {-1635814800 3600 1 WEST}.. {-1616202000 0 0 WET}.. {-1604365200 3600 1 WEST}.. {-1584666000 0 0 WET}.. {-1572742800 3600 1 WEST}.. {-1553043600 0 0 WET}.. {-1541206800 3600 1 WEST}.. {-1521507600 0 0 WET}.. {-1442451600 3600 1 WEST}.. {-1426813200 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364778000 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333328400 0 0 WET}.. {-1316394000 3600 1 WEST}.. {-1301274000 0 0 WET}.. {-1284339600 3600 1 WEST}.. {-1269824400 0 0 WET}.. {-1221440400 3600 1 WEST}.. {-1206925200 0 0 WET}.. {-1191200400 3600 1 WEST}.. {-1175475600 0 0 WET}.. {-1127696400 3600 1 WEST}.. {-1111971600 0 0 WET}.. {-1096851
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.948438246006353
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/sUE2tovXHAIgoq8sUE2oAovRL/yQavPSJ5Qahs0:SlSWB9vsM3ymhrE2tSHAIgohrE2LovNl
                                                                                                                                                                                                                                                          MD5:56C6C95484FEAF9BAF755683E7417B58
                                                                                                                                                                                                                                                          SHA1:A43176BEBC5B4D7144A7E1109E0AAEFD95C21EC6
                                                                                                                                                                                                                                                          SHA-256:713A842197516D618F2D86977262542A1CA334D7DF6026539FA2F2980DBF4CD3
                                                                                                                                                                                                                                                          SHA-512:566B6DF2D76A8A4D3405C4785C7A471A23D65CD8838831BD0DEDF5BF194E8A3B304CA9920CB4A8EC9D6CD60EAA9BE0335E38D9547A4D23C7E4E5E5A39A09DDAC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Ljubljana) $TZData(:Europe/Belgrade)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10211
                                                                                                                                                                                                                                                          Entropy (8bit):3.826887992237191
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:GNoCvTZtcf80KYiK3BG0Myj9TYQOeMAwbccM0Fp:GNNTZtcf15iOBG08eNwbccM0Fp
                                                                                                                                                                                                                                                          MD5:0625C99E16D3C956DED1C0C0F867DEC3
                                                                                                                                                                                                                                                          SHA1:6ACDF0DB619B63E21EC89046B9320A85FBD3397A
                                                                                                                                                                                                                                                          SHA-256:D04C4E25DF4DE1C1CFE1EF84B3B6DD746CF08A271AB0958F22C7D580A3ED10E6
                                                                                                                                                                                                                                                          SHA-512:07AC42F0635DF01CC0AFD13F9668B143D4943BA0E4C377D254B5AF034D9DDBAB77BA813187E9AB73D2EEAD86EBAA26DC15599FD74FC82EEF287F5A6AB9C01635
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/London) {.. {-9223372036854775808 -75 0 LMT}.. {-3852662325 0 0 GMT}.. {-1691964000 3600 1 BST}.. {-1680472800 0 0 GMT}.. {-1664143200 3600 1 BST}.. {-1650146400 0 0 GMT}.. {-1633903200 3600 1 BST}.. {-1617487200 0 0 GMT}.. {-1601848800 3600 1 BST}.. {-1586037600 0 0 GMT}.. {-1570399200 3600 1 BST}.. {-1552168800 0 0 GMT}.. {-1538344800 3600 1 BST}.. {-1522533600 0 0 GMT}.. {-1507500000 3600 1 BST}.. {-1490565600 0 0 GMT}.. {-1473631200 3600 1 BST}.. {-1460930400 0 0 GMT}.. {-1442786400 3600 1 BST}.. {-1428876000 0 0 GMT}.. {-1410732000 3600 1 BST}.. {-1396216800 0 0 GMT}.. {-1379282400 3600 1 BST}.. {-1364767200 0 0 GMT}.. {-1348437600 3600 1 BST}.. {-1333317600 0 0 GMT}.. {-1315778400 3600 1 BST}.. {-1301263200 0 0 GMT}.. {-1284328800 3600 1 BST}.. {-1269813600 0 0 GMT}.. {-1253484000 3600 1 BST}.. {-1238364000 0 0 GMT}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):191
                                                                                                                                                                                                                                                          Entropy (8bit):4.920751023999728
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/So3vXHAIgoq82yHRL/yQavQLHKQX9J8QahCv:SlSWB9vsM3ymhS2HAIgoh26N/y1QzKQt
                                                                                                                                                                                                                                                          MD5:E4A8C25756D6C5D2073A51D2B54E3A0C
                                                                                                                                                                                                                                                          SHA1:4A24667ADC9BD31E8CB298BE3787C12301C3F1C8
                                                                                                                                                                                                                                                          SHA-256:8C0486A5B235E8B01069420976E1B8D08D77A4BEF587203AF1B68D7B5333546E
                                                                                                                                                                                                                                                          SHA-512:F3593C3B75C9DA931FB39BC2054EB9691C3A544A74F871425169C3244040D6D060510741FE1E352A1E59F53E5A585307D434A0D7C9D159D065717E78C807787C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Brussels)]} {.. LoadTimeZoneFile Europe/Brussels..}..set TZData(:Europe/Luxembourg) $TZData(:Europe/Brussels)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8517
                                                                                                                                                                                                                                                          Entropy (8bit):3.8326167134909177
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:k5m01LdXKc0TJp+bwS274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOn:+DaNVLSs41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:63263380F57B756A1DFA3796E4188CD3
                                                                                                                                                                                                                                                          SHA1:8EEE707AC4FEA1C098C81AC2D289A46239121A5E
                                                                                                                                                                                                                                                          SHA-256:5337C9843C56DEEC6B91C4468C76EC1C896E80421B72B583B69DE5579063E09A
                                                                                                                                                                                                                                                          SHA-512:ACA4830020715C471741E27EB2292ACF002D2CD7EDCD1061978B64967EB447F61AA095F960D8A75A01B9B87558D83FF409F30BDACA83E063024F1E2381FA64C4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Madrid) {.. {-9223372036854775808 -884 0 LMT}.. {-2177452800 0 0 WET}.. {-1631926800 3600 1 WEST}.. {-1616889600 0 0 WET}.. {-1601168400 3600 1 WEST}.. {-1585353600 0 0 WET}.. {-1442451600 3600 1 WEST}.. {-1427673600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364774400 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333324800 0 0 WET}.. {-1316390400 3600 1 WEST}.. {-1301270400 0 0 WET}.. {-1284339600 3600 1 WEST}.. {-1269820800 0 0 WET}.. {-1026954000 3600 1 WEST}.. {-1017619200 0 0 WET}.. {-1001898000 3600 1 WEST}.. {-999482400 7200 1 WEMT}.. {-986090400 3600 1 WEST}.. {-954115200 0 0 WET}.. {-940208400 3600 0 CET}.. {-873079200 7200 1 CEST}.. {-862621200 3600 0 CET}.. {-842839200 7200 1 CEST}.. {-828320400 3600 0 CET}.. {-811389600 7200 1 CEST}.. {-796870800 3600 0 CET}.. {-779940000 7200 1 CEST}.. {-765421200 3600 0 CET}.. {-74849
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8724
                                                                                                                                                                                                                                                          Entropy (8bit):3.816380386871747
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:KAGvi2GmkwwnpH74elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZN:KLsww141sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:9B09D6EED8F23BAFFB62929C0115E852
                                                                                                                                                                                                                                                          SHA1:4AEF15333C73C2836C09D818FD0E20440D7C4780
                                                                                                                                                                                                                                                          SHA-256:C5C240BAAECE8235D1FBDD251C1A67CB2D2FC8195DD5BBE37FF9CFF0445FCDA2
                                                                                                                                                                                                                                                          SHA-512:43AA3492BD335A290C6EFEE275B47EA18E544199E37A9BBAE2E350D42BDFF42F0E9ED461A4BB1824CA33F84A90D4060906844A3E22DA49C9821E4CB460832D6E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Malta) {.. {-9223372036854775808 3484 0 LMT}.. {-2403478684 3600 0 CET}.. {-1690765200 7200 1 CEST}.. {-1680487200 3600 0 CET}.. {-1664758800 7200 1 CEST}.. {-1648951200 3600 0 CET}.. {-1635123600 7200 1 CEST}.. {-1616896800 3600 0 CET}.. {-1604278800 7200 1 CEST}.. {-1585533600 3600 0 CET}.. {-1571014800 7200 1 CEST}.. {-1555293600 3600 0 CET}.. {-932432400 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812588400 7200 1 CEST}.. {-798073200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766717200 3600 0 CET}.. {-750898800 7200 1 CEST}.. {-733359600 3600 0 CET}.. {-719456400 7200 1 CEST}.. {-701917200 3600 0 CET}.. {-689209200 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-114051600 7200 1 CEST}.. {-103168800 3600 0 CET}.. {-81997200 7200 1 CEST}.. {-71715600 3600 0 CET}.. {-50547600 7200 1
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.959733196757503
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV1AYKjG5XHAIgoq2AYKjo0ARL/yQausWILMFJ8QaC:SlSWB9vsM3ymrAdjGJHAIgorAdjo0ANn
                                                                                                                                                                                                                                                          MD5:C1844961691214F6E6DF6487788A7758
                                                                                                                                                                                                                                                          SHA1:6D08E9FB7B8602A80622148BFACD9676F45F0E2B
                                                                                                                                                                                                                                                          SHA-256:6136C3CFA4A767E7C9DDA23A283AD98B72E9868F192E6A8E3BFE6396F6989BD1
                                                                                                                                                                                                                                                          SHA-512:B2D1EA51AC5B34792AC02820A9D60FD41F3B91AB6505896476FCB0DC339B8DC1DE9E2C89A7627F69E16247661AE8040D789FFD2F8F1CD59F243B57C4845B450F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Helsinki)]} {.. LoadTimeZoneFile Europe/Helsinki..}..set TZData(:Europe/Mariehamn) $TZData(:Europe/Helsinki)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2177
                                                                                                                                                                                                                                                          Entropy (8bit):3.9354590900153172
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:K8cVnR7xhuHJkminzaVV04v3TfdGY3kNmneVuNlh000sGpde:5mnRtEpkmiSV3A8qcN
                                                                                                                                                                                                                                                          MD5:9C10EAE9FA0DE192C5FD4F76E12606F0
                                                                                                                                                                                                                                                          SHA1:AFD5650410EC3E6ED564A8B2ABF91709D090B4AD
                                                                                                                                                                                                                                                          SHA-256:8C95EA696EA578DEF726502AC181AF475A676030878F56B4E2D667757BBD1C49
                                                                                                                                                                                                                                                          SHA-512:3B9ED6B68858485B9A46A0863B7D9D3C1E4C5BBA269457F24A9A12C274F0F9B35E63D8C25EB53E7200DB57DD35ACCB7FD7D8AB005FEE2C4D7FC6E72E8CF57194
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Minsk) {.. {-9223372036854775808 6616 0 LMT}.. {-2840147416 6600 0 MMT}.. {-1441158600 7200 0 EET}.. {-1247536800 10800 0 MSK}.. {-899780400 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-804646800 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 14400 1 MSD}.. {622594800 10800 0 MSK}.. {631141200 10800 0 MSK}.. {670374000 7200 0 EEMMTT}.. {670377600 10800 1 EEST}.. {
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):178
                                                                                                                                                                                                                                                          Entropy (8bit):4.9089012087310095
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVtEXc4o3vXHAIgoquEXeRL/yQauPMFBx6QazEXcov:SlSWB9vsM3ymzESPHAIgozEON/ySRpEB
                                                                                                                                                                                                                                                          MD5:2015CF8BBEEE12AF0D9C82FD2E246C72
                                                                                                                                                                                                                                                          SHA1:062BFFBB266C3EBB5776A509DDB7A6044C82B864
                                                                                                                                                                                                                                                          SHA-256:9DF16BB1C26100635DC4CB1DF409B0FA7B139C22BF09574ED337EE244CA3C546
                                                                                                                                                                                                                                                          SHA-512:FD3479588D4F3B84CF6C8B8A5DB1AB3BFA0A87CA2FFADB4FEBBBB25711C77963BE7CD0D1DA5ED985D729F39C5B44E8CBD429F1E2DA813DF26272D66CAE4F425A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Paris)]} {.. LoadTimeZoneFile Europe/Paris..}..set TZData(:Europe/Monaco) $TZData(:Europe/Paris)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2430
                                                                                                                                                                                                                                                          Entropy (8bit):3.942836780611272
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:7fnjazk7e+LxhuHJkvVineTeCTU50x0Y7:7fnjazk7eoEpkvVieTeCTUax0Y7
                                                                                                                                                                                                                                                          MD5:4547D47E9364ACAFB2A4BEE52D04BFBB
                                                                                                                                                                                                                                                          SHA1:1E7F964692F81D49AEAF581FE70AD22D4E36226B
                                                                                                                                                                                                                                                          SHA-256:31F9C3C2F17B3EE4FA6D9EE6A86BF407AC0377DE4D666C65E86CE5AC591F829F
                                                                                                                                                                                                                                                          SHA-512:7F1D7C80A1BF611D5440EEF9085DA6CDED86B5EF4C2737C105640030E5AA998A0951182E72DC224190A25DA8846CDE856A78EBAA8876AA0B18B1CBCADBB060FF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Moscow) {.. {-9223372036854775808 9017 0 LMT}.. {-2840149817 9017 0 MMT}.. {-1688265017 9079 0 MMT}.. {-1656819079 12679 1 MST}.. {-1641353479 9079 0 MMT}.. {-1627965079 16279 1 MDST}.. {-1618716679 12679 1 MST}.. {-1596429079 16279 1 MDST}.. {-1593820800 14400 0 MSD}.. {-1589860800 10800 0 MSK}.. {-1542427200 14400 1 MSD}.. {-1539493200 18000 1 +05}.. {-1525323600 14400 1 MSD}.. {-1491188400 7200 0 EET}.. {-1247536800 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):179
                                                                                                                                                                                                                                                          Entropy (8bit):4.7873368289068905
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq85GKLlXHAIgNwMGKLZRRL/yQatHefeWFKYGKL8n:SlSWB9vsM3yZdL1HAIgGMdLZRN/y3HeA
                                                                                                                                                                                                                                                          MD5:BE82205480617CF07F76BA0DF06C95BC
                                                                                                                                                                                                                                                          SHA1:46D2D8D9FE4FB570C2A09BC809B02C8960F9601F
                                                                                                                                                                                                                                                          SHA-256:FC93B7516933EDFDC211AC0822EE88BF7ACAD1C58A0643B15294F82EB0F14414
                                                                                                                                                                                                                                                          SHA-512:F490A70053A6011D80FB0A4E96D2871BFEEB168690E21C4EC31F2F5C0E24A67C706528C81322A1D48E71242F0FFA277550192925FDE5B1F34BFCB308290E11FC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Nicosia)]} {.. LoadTimeZoneFile Asia/Nicosia..}..set TZData(:Europe/Nicosia) $TZData(:Asia/Nicosia)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):179
                                                                                                                                                                                                                                                          Entropy (8bit):4.910647918749938
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/y+YF3vXHAIgoq8yFRRL/yQasWJAQahyuv:SlSWB9vsM3ymhVoPHAIgoh6N/yI7Fv
                                                                                                                                                                                                                                                          MD5:242748F361AD524CD8E288BEE8611E19
                                                                                                                                                                                                                                                          SHA1:A636A544BB54851185E2BE83DAC69C813B824827
                                                                                                                                                                                                                                                          SHA-256:C84E9C0D22059573079211CBF487072CAB95C14B5ECEFB596CF1F594ABD3458C
                                                                                                                                                                                                                                                          SHA-512:404B272D0C6B70332052601EA65C0F7AE71C12F62D19FD3010BBA6FB25E4F2F95BB9E5F295D8494CBADB1AE9C7F833C42382AE7488317EA6F0C20E60B63BEFE8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Europe/Oslo) $TZData(:Europe/Berlin)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9152
                                                                                                                                                                                                                                                          Entropy (8bit):3.8506895725632746
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:fySTO1C+4qoMYOKDBb0S274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdi:fdp+3Ss41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:9CAF8C5C5AF630E7F782C0480DD786E7
                                                                                                                                                                                                                                                          SHA1:9FBEF9EEDD8BAFB48B17E3AC388CFEF8DCD10CB0
                                                                                                                                                                                                                                                          SHA-256:AE61491C4A587F56426A9F2118E31060276F2B0231E750C461781577551CA196
                                                                                                                                                                                                                                                          SHA-512:F809744BB597184A2815758A27B6A07C515C65DB96CFFB3625FD059DEBBF05EE903E999483B3459C7C8D3991824746F8530CD1378F8A63B1F54F60CFACE9F89B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Paris) {.. {-9223372036854775808 561 0 LMT}.. {-2486592561 561 0 PMT}.. {-1855958961 0 0 WET}.. {-1689814800 3600 1 WEST}.. {-1680397200 0 0 WET}.. {-1665363600 3600 1 WEST}.. {-1648342800 0 0 WET}.. {-1635123600 3600 1 WEST}.. {-1616893200 0 0 WET}.. {-1604278800 3600 1 WEST}.. {-1585443600 0 0 WET}.. {-1574038800 3600 1 WEST}.. {-1552266000 0 0 WET}.. {-1539997200 3600 1 WEST}.. {-1520557200 0 0 WET}.. {-1507510800 3600 1 WEST}.. {-1490576400 0 0 WET}.. {-1470618000 3600 1 WEST}.. {-1459126800 0 0 WET}.. {-1444006800 3600 1 WEST}.. {-1427677200 0 0 WET}.. {-1411952400 3600 1 WEST}.. {-1396227600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364778000 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333328400 0 0 WET}.. {-1316394000 3600 1 WEST}.. {-1301274000 0 0 WET}.. {-1284339600 3600 1 WEST}.. {-1269824400 0 0 WET}.. {-1253494800 3
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.910162937111088
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/sUE2tovXHAIgoq8sUE2oAovRL/yQazKIGl1/yQ0:SlSWB9vsM3ymhrE2tSHAIgohrE2LovNK
                                                                                                                                                                                                                                                          MD5:52C36955D6BD1D9FE9CB64822D04B6DB
                                                                                                                                                                                                                                                          SHA1:D5FF82EC486409E6FB314AD5ACE608577C9632CF
                                                                                                                                                                                                                                                          SHA-256:B87630FF459DE07EB16CD0C2452660772E3FFC4EEB8419EA77A013B6F63A5900
                                                                                                                                                                                                                                                          SHA-512:ABA49D3F05A41A4982600E4DA5C225D8994251F447401EE6FE8478E008BCD5D41C057034185B5CFF805634D571F3CC98EFE98093ABC8E6271351E11A4DA1E7AD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Podgorica) $TZData(:Europe/Belgrade)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8038
                                                                                                                                                                                                                                                          Entropy (8bit):3.8240363895915914
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:Kr9+neXAS274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlh:KnASs41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:828134FA1263FEFA2B06A8B2F075F564
                                                                                                                                                                                                                                                          SHA1:4B332DE6E0855F8B9517F7098A3FB439671FC349
                                                                                                                                                                                                                                                          SHA-256:5D3AFED5C1B07C6C6635D6BDEB28A0FB4D11A61F25F26C91227B2254BE5F4AA0
                                                                                                                                                                                                                                                          SHA-512:9AB1462CDBD7F13F0CECDCCC2D91A85D8C0576B71508F935D26638C25ED023CF8FF4BA4FFDA402B308E6142B135D1B9D88700A519DBE2381E8E945329A5354F7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Prague) {.. {-9223372036854775808 3464 0 LMT}.. {-3786829064 3464 0 PMT}.. {-2469401864 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-777862800 7200 0 CEST}.. {-765327600 3600 0 CET}.. {-746578800 7200 1 CEST}.. {-733359600 3600 0 CET}.. {-728517600 0 1 GMT}.. {-721260000 0 0 CET}.. {-716425200 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654217200 7200 1 CEST}.. {-639010800 3600 0 CET}.. {283993200 3600 0 CET}.. {291776400 7200 1 CEST}.. {307501200 3600 0 CET}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7658
                                                                                                                                                                                                                                                          Entropy (8bit):3.7750218768791806
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:eq+cEpkjXkSV385aNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBK0:ePWjUS7ivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                                                                          MD5:0D3C919F60081388524BD5DB22E6904B
                                                                                                                                                                                                                                                          SHA1:6691EAB901C8B57D2F2693120A45A67799D05FCB
                                                                                                                                                                                                                                                          SHA-256:8B64A42BAFD90F9255CACFDBAC603D638DD7C18DC27249F9C9B515E1DA634424
                                                                                                                                                                                                                                                          SHA-512:62A2820B8C1C5468AC1F1BB626F9AAAD0BA1DEC5B73740F00FE4DB8CFA3F2BCF9947968E693824FC8770BA20AB962F93F7E5E345AE8A85F99CDB18E2B510308E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Riga) {.. {-9223372036854775808 5794 0 LMT}.. {-2840146594 5794 0 RMT}.. {-1632008194 9394 1 LST}.. {-1618702594 5794 0 RMT}.. {-1601681794 9394 1 LST}.. {-1597275394 5794 0 RMT}.. {-1377308194 7200 0 EET}.. {-928029600 10800 0 MSK}.. {-899521200 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-795834000 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {6
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8813
                                                                                                                                                                                                                                                          Entropy (8bit):3.8168470239811736
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:hhGvC2GmkNXEq74elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhn:hUsF41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:C4F49446D3696301EDB339691DCB2FDB
                                                                                                                                                                                                                                                          SHA1:537963A77B9BE9BE6B997A812A6E6DD120F6F247
                                                                                                                                                                                                                                                          SHA-256:DCD2D9144507311E573568598E1FFD0E0574FB677AA0DAFC5641D80A19EB6E58
                                                                                                                                                                                                                                                          SHA-512:1F0A9A549FA0995C51E90AC392671E3F09744B268F1EE6A27CA7E3C41C2B02A4BA0F98369BE40BA482FBA1FED8F1EE712F0B3217AD86164D1AD498E369C24D76
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Rome) {.. {-9223372036854775808 2996 0 LMT}.. {-3252098996 2996 0 RMT}.. {-2403565200 3600 0 CET}.. {-1690765200 7200 1 CEST}.. {-1680487200 3600 0 CET}.. {-1664758800 7200 1 CEST}.. {-1648951200 3600 0 CET}.. {-1635123600 7200 1 CEST}.. {-1616896800 3600 0 CET}.. {-1604278800 7200 1 CEST}.. {-1585533600 3600 0 CET}.. {-1571014800 7200 1 CEST}.. {-1555293600 3600 0 CET}.. {-932432400 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-830307600 7200 0 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-807152400 7200 0 CEST}.. {-798073200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766717200 3600 0 CET}.. {-750898800 7200 1 CEST}.. {-733359600 3600 0 CET}.. {-719456400 7200 1 CEST}.. {-701917200 3600 0 CET}.. {-689209200 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-114051600 7200 1 CEST}.. {-103168800 36
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2118
                                                                                                                                                                                                                                                          Entropy (8bit):3.664269700453612
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:7PvCAs6kKR6aQmF1cSNWrI+AjQnTRYZ/YF0LUdt/LkajuZbIJltiabs2Tb:7HCAs6kC6aZF1cSN4I+AjQTRYZ/YF0Lw
                                                                                                                                                                                                                                                          MD5:965D987F6576F66A08871697144D4CDB
                                                                                                                                                                                                                                                          SHA1:AF7226DF81C2B3C3A5832F59FC708A6BCBF389CA
                                                                                                                                                                                                                                                          SHA-256:8F395352AA05D35E7D13380E73659A0D5B56FFC17E3F4E40E4F678A902F0E49B
                                                                                                                                                                                                                                                          SHA-512:B82E0CFA5EDA0FCDF03609AE439255F8937A7E9EFA0AFE15EA8877316782AFC74514BCD2B4F06F1B5F0F3C5A64A933D73CB50D5AED2BB1491BD6CACBB77B10E8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Samara) {.. {-9223372036854775808 12020 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +04}.. {-1102305600 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 +04}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 7200 0 +03}.. {670377600 10800 1 +03}.. {686102400 10800 0 +03}.. {687916800 14400 0 +04}.. {701820000 18000 1 +05}.. {717544800 14400 0 +04}.. {733
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):179
                                                                                                                                                                                                                                                          Entropy (8bit):4.955758257767983
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVvjF3vXHAIgoqspvVHRL/yQawELDX7x/yQaxE:SlSWB9vsM3ymx5PHAIgoxvN/yt/yrE
                                                                                                                                                                                                                                                          MD5:D253DA6880630A31D39DB0CFA4933ABD
                                                                                                                                                                                                                                                          SHA1:E5798DAAE574729685FE489F296B964BC1CCF2E4
                                                                                                                                                                                                                                                          SHA-256:B6856A0E38C2404F7D5FA1821559503F8AE70923A562F0D993124D131515F395
                                                                                                                                                                                                                                                          SHA-512:CFB6005F3E8D1C585AF36EB7A8C9F49760EF6F446C97E7804EB61EFD0804424C4FB6AE81B71C5A867274EF89A17DAC0D2A0FF882A0F6AEA1D5FFD51593726C5F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Rome)]} {.. LoadTimeZoneFile Europe/Rome..}..set TZData(:Europe/San_Marino) $TZData(:Europe/Rome)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.937834327554967
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/sUE2tovXHAIgoq8sUE2oAovRL/yQawEX3GEaQa5:SlSWB9vsM3ymhrE2tSHAIgohrE2LovNZ
                                                                                                                                                                                                                                                          MD5:F7C7DAE9C5D371EF9EE1F490246ED3CC
                                                                                                                                                                                                                                                          SHA1:40C388FE2A55078C8E0524A4385B3F8846960E24
                                                                                                                                                                                                                                                          SHA-256:BC00D953C2F3E55E40EDA13838AB66B9E9D0BDAD620E4EB917637761ABB06FB1
                                                                                                                                                                                                                                                          SHA-512:EB22C59F4D58D96797A718FC59B010795F587626E456D44A3E6398E0FBF4ECD97BCDC151BC1359151798B5AF2964FE5708233F8ECD0D344C3E27629F2645687F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Sarajevo) $TZData(:Europe/Belgrade)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2061
                                                                                                                                                                                                                                                          Entropy (8bit):3.6638125261109824
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:yFvCAs6kKR6aQmF1cSNWJjXgV/Ap40FjDQ:yhCAs6kC6aZF1cSNcjXgV/ApDFjDQ
                                                                                                                                                                                                                                                          MD5:CC4D7C478790588D232568CAB12D8E67
                                                                                                                                                                                                                                                          SHA1:07A7CFCFFFF91D124EDFC99F5053BAFC79FBB12B
                                                                                                                                                                                                                                                          SHA-256:AB90363DEE5077C39EC55FE8E519593FF08223E5A8E593F6CCE01FB5B8B35BAE
                                                                                                                                                                                                                                                          SHA-512:23944D20624C942CFDE58F1019160D64401BD0AFB8C3EC49F904038482FAA6741812548C860A2DAE050B8D17A7E08ED9C6EBE7FF19393CFA46D78B1D21B1CACA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Saratov) {.. {-9223372036854775808 11058 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 10800 0 +04}.. {575420400 14400 1 +04}.. {591145200 10800 0 +03}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 14400 0 +04}.. {701820000 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748998000 10800 0 +03}.. {764722800 14400 1 +04}.. {780
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2389
                                                                                                                                                                                                                                                          Entropy (8bit):3.9491446081772748
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:wM2wE0xhuHJkYaVV0XOnbdSisa0ewEKGfUslIYtq8X:UwEAEpkzVFgaNl7
                                                                                                                                                                                                                                                          MD5:03E05E60E064198BF6562B2E6E8DA8D2
                                                                                                                                                                                                                                                          SHA1:51461207B671536CD4A7587BA283DE2D0017AA4A
                                                                                                                                                                                                                                                          SHA-256:D51CD3DE50C50BCA1624EFC952ADD15D418A09EC213760DF5BC3097E35C5A7A0
                                                                                                                                                                                                                                                          SHA-512:73B7773DABE19F20DD211E178B822FD35620DC4AC8B9D20259971B1157ED7A60A5A41026258FAA8B15016268D241ED804AC1307CACDA00D6FE657407D254B02C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Simferopol) {.. {-9223372036854775808 8184 0 LMT}.. {-2840148984 8160 0 SMT}.. {-1441160160 7200 0 EET}.. {-1247536800 10800 0 MSK}.. {-888894000 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-811645200 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 14400 1 MSD}.. {622594800 10800 0 MSK}.. {631141200 10800 0 MSK}.. {646786800 7200 0 EET}.. {701042400 7200 0 EET}.. {
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):187
                                                                                                                                                                                                                                                          Entropy (8bit):4.953089768975736
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/sUE2tovXHAIgoq8sUE2oAovRL/yQawOgpr8Qahr:SlSWB9vsM3ymhrE2tSHAIgohrE2LovNO
                                                                                                                                                                                                                                                          MD5:0BF8ADBB63F5D6187C75FF1B0BAC761E
                                                                                                                                                                                                                                                          SHA1:7DE15E767D34812F784CE6E85438A592E2CBA418
                                                                                                                                                                                                                                                          SHA-256:52F20858433261B15797B64F0A09CEE95D552EF93B5DAA7C141BFAB6D718C345
                                                                                                                                                                                                                                                          SHA-512:27D395635427C8FA1A4E0063A32F482701D2CC7C7724B4A06E661D4A419D23E219672888D37367FE5E70B6872914EB9EE034AE359DCB6A4C4CE05CA34C3589A9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Skopje) $TZData(:Europe/Belgrade)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7654
                                                                                                                                                                                                                                                          Entropy (8bit):3.727428614069594
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:8lmG4+K7Gjz5CXNUatpaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYf:8lmGWwkdUasivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                                                                          MD5:91357DFC23ADB0CE80C463E4B6D896BE
                                                                                                                                                                                                                                                          SHA1:273F51BE4C67A9AC1182F86AC060E963684151D5
                                                                                                                                                                                                                                                          SHA-256:6415F279CB143EA598CF8272263AC5B502827B10CEEB242B39E6EFCC23A2EE12
                                                                                                                                                                                                                                                          SHA-512:8EA7E2D4C2239879A4D6CCE302C38A6D2A9093A2CADEF4F4294E60D373AB9A2C468BA6E3D54DEC7F73D954CE5226EF2B022F8BDEF29B3B4AAB3838B05C72EA29
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Sofia) {.. {-9223372036854775808 5596 0 LMT}.. {-2840146396 7016 0 IMT}.. {-2369527016 7200 0 EET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-788922000 3600 0 CET}.. {-781048800 7200 0 EET}.. {291762000 10800 0 EEST}.. {307576800 7200 0 EET}.. {323816400 10800 1 EEST}.. {339026400 7200 0 EET}.. {355266000 10800 1 EEST}.. {370393200 7200 0 EET}.. {386715600 10800 1 EEST}.. {401846400 7200 0 EET}.. {417571200 10800 1 EEST}.. {433296000 7200 0 EET}.. {449020800 10800 1 EEST}.. {465350400 7200 0 EET}.. {481075200 10800 1 EEST}.. {496800000 7200 0 EET}.. {512524800 10800 1 EEST}.. {528249600 7200 0 EET}.. {543974400 10800 1 EEST}.. {559699200 7200 0 EET}.. {575424000 10800 1 EEST}.. {591148800 7200 0 EET}.. {606873600 10800 1 EEST}.. {62259
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.956798438511978
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/y+YF3vXHAIgoq8yFRRL/yQawRMNSTyQahyuv:SlSWB9vsM3ymhVoPHAIgoh6N/yqMNSTm
                                                                                                                                                                                                                                                          MD5:ACFB8E2D1D4BA0D2D46410F2F2823B21
                                                                                                                                                                                                                                                          SHA1:4AC3A19E94DE606DFF7D93BC6C7F113F3D2D083A
                                                                                                                                                                                                                                                          SHA-256:64615AEA9EF14A2609D2C804901281C83FDDC0A8BCA9B377D6CAD62D81801C66
                                                                                                                                                                                                                                                          SHA-512:2E23AC0DE7D3D0CF2BA4FE3EE31E15EB614A7442097578209D38CE2FF2E3DF006881463866FE67DD4DDEAB179E5CD2946E8A9E8F7401F1B953E9AB216EC753F0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Europe/Stockholm) $TZData(:Europe/Berlin)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7549
                                                                                                                                                                                                                                                          Entropy (8bit):3.76585669030767
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:dUusEpkjXkSV3AMaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBK0:O0WjUSWivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                                                                          MD5:54EF0224F5E28FA78F212EC97D4AE561
                                                                                                                                                                                                                                                          SHA1:FA7C9A951ED943F1E1E609D2253582016BC26B57
                                                                                                                                                                                                                                                          SHA-256:6F3594CCDA78B02B2EE14C8FAE29E668E47193AF2DFCF5AF1ECD210F13BCE9CE
                                                                                                                                                                                                                                                          SHA-512:2D1CA2BB1945AE5E3F56AF8FA7F950CE7169F215C783E683634581C5EC01B54159E47A0E9551897077BBEAB06158906029A4E4B0051A263D9E5D903EA9DA1692
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Tallinn) {.. {-9223372036854775808 5940 0 LMT}.. {-2840146740 5940 0 TMT}.. {-1638322740 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1593824400 5940 0 TMT}.. {-1535938740 7200 0 EET}.. {-927943200 10800 0 MSK}.. {-892954800 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-797648400 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 10800 1 EEST}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7675
                                                                                                                                                                                                                                                          Entropy (8bit):3.809498345470167
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:n05NWKIHBJ9AE4elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhlt:0iKqxAE41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:1983B88075A92942209BB2B80E565F4E
                                                                                                                                                                                                                                                          SHA1:12A0401026C5C036144FD1D544173AAB39969F61
                                                                                                                                                                                                                                                          SHA-256:C62686BF598138FEFB72E8CC6632BA75A5FE147F2A30124EE3583BE1F732E38D
                                                                                                                                                                                                                                                          SHA-512:E95C38FA0A2B526C00B9DCF5CDF53059DECF64B085AA18BE000968DA626561944415D053CF7A5C32BC672085538920CFD67A3A3B627CFD5B1A4C9CEC49AA3F96
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Tirane) {.. {-9223372036854775808 4760 0 LMT}.. {-1767230360 3600 0 CET}.. {-932346000 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-843519600 3600 0 CET}.. {136854000 7200 1 CEST}.. {149896800 3600 0 CET}.. {168130800 7200 1 CEST}.. {181432800 3600 0 CET}.. {199839600 7200 1 CEST}.. {213141600 3600 0 CET}.. {231894000 7200 1 CEST}.. {244591200 3600 0 CET}.. {263257200 7200 1 CEST}.. {276040800 3600 0 CET}.. {294706800 7200 1 CEST}.. {307490400 3600 0 CET}.. {326156400 7200 1 CEST}.. {339458400 3600 0 CET}.. {357087600 7200 1 CEST}.. {370389600 3600 0 CET}.. {389142000 7200 1 CEST}.. {402444000 3600 0 CET}.. {419468400 7200 1 CEST}.. {433807200 3600 0 CET}.. {449622000 7200 1 CEST}.. {457480800 7200 0 CEST}.. {465354000 3600 0 CET}.. {481078800 7200 1 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 C
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.906212162381389
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV+NM/LWXHAIgoq9NM/HARL/yQa3MPgJM1p8QagNMj:SlSWB9vsM3ymI6CHAIgoI6HAN/ytM4MO
                                                                                                                                                                                                                                                          MD5:E0C99DB7673EEE440BA1848046455BA1
                                                                                                                                                                                                                                                          SHA1:1BCCC1BE46306DEF8A9CA249DE8FA11FC57CC04D
                                                                                                                                                                                                                                                          SHA-256:FDD53FDB5F754BBBA8FF98F0B1555FE0BAEB7852843220A7CF93A190B641A9AD
                                                                                                                                                                                                                                                          SHA-512:CD56B540AE9084DEAA9D0A1DBBAF89733C465424C22CE74696B9AE90FD4FEFAB265CF23C5B13A7F04597D75FD0147BD593E0552B56D87372170CB4CA1BFC8259
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Chisinau)]} {.. LoadTimeZoneFile Europe/Chisinau..}..set TZData(:Europe/Tiraspol) $TZData(:Europe/Chisinau)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2119
                                                                                                                                                                                                                                                          Entropy (8bit):3.680951255407528
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:kFvCAs6kKR6aQmF1cSNWrI+AjQndgV/Ap40FjDOP:khCAs6kC6aZF1cSN4I+AjQdgV/ApDFj4
                                                                                                                                                                                                                                                          MD5:83C86E437B5FBA1DC9CC5235396AC381
                                                                                                                                                                                                                                                          SHA1:5493A59C3A5A1B55ACD493E67F9E29D2A415A8DB
                                                                                                                                                                                                                                                          SHA-256:9FA9D09509B4F8F5A9C8E422DBA02605070C3EBDAEB7C1DF8527C8EEF5E3632D
                                                                                                                                                                                                                                                          SHA-512:86222489C65C87646939DECF91C2EC336EB46F64B644526A3FA8A4854B9D11819F6FD253107AB8A3DE911E254C88092D25137442164A6E437CDAF258A7CBB66C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Ulyanovsk) {.. {-9223372036854775808 11616 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 +04}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 7200 0 +03}.. {670377600 10800 1 +03}.. {686102400 7200 0 +02}.. {695779200 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):177
                                                                                                                                                                                                                                                          Entropy (8bit):5.051734481833866
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV2cvXHAIgoq1csFARL/yQa2rUQaocqn:SlSWB9vsM3ym5HAIgoiAN/yFC
                                                                                                                                                                                                                                                          MD5:17A0CC51331756920B13FFA3FF556751
                                                                                                                                                                                                                                                          SHA1:C575FEF4F053393C57B34C7C7B0C1E9605413792
                                                                                                                                                                                                                                                          SHA-256:F8CAF5DBE12F1647B28E7CCDDB2E09E36788A766690D12E770A8ABD82E708644
                                                                                                                                                                                                                                                          SHA-512:E73F0FE5BE4DD91948A88DC895E148D81267576BA3BCFEA777E25C01EAE9C06845DBFFB651526045B70B7A3CCDB195DFFF60486C01E0A115DFB856873970008E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Kyiv)]} {.. LoadTimeZoneFile Europe/Kyiv..}..set TZData(:Europe/Uzhgorod) $TZData(:Europe/Kyiv)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):180
                                                                                                                                                                                                                                                          Entropy (8bit):4.953146873643623
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVnCMPfXHAIgoqkCM4ARL/yQa1NEHp8Qa5CMS:SlSWB9vsM3ym5XPHAIgo5gAN/yvNEJ8G
                                                                                                                                                                                                                                                          MD5:A0BAEC8B6AF1589ECBE52667DDB2A153
                                                                                                                                                                                                                                                          SHA1:37093F4F885CBFA90A1F136D082E8B7546244ACC
                                                                                                                                                                                                                                                          SHA-256:06B235BF047FC2303102BC3DC609A5754A6103321D28440B74EEC1C9E3D24642
                                                                                                                                                                                                                                                          SHA-512:DBEC235AFB413FA8D116FA1AFFE73706762E7458038B6D68E0BFD71C339510D766825BA97055A06DEE14D5880EAE6CD035BFE0C935C0DF44B0107A356D293A78
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Zurich)]} {.. LoadTimeZoneFile Europe/Zurich..}..set TZData(:Europe/Vaduz) $TZData(:Europe/Zurich)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):176
                                                                                                                                                                                                                                                          Entropy (8bit):4.914414313741477
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVvjF3vXHAIgoqspvVHRL/yQa1xLM1p8QaxE:SlSWB9vsM3ymx5PHAIgoxvN/yvN+8rE
                                                                                                                                                                                                                                                          MD5:2404265F8DE1F7D7745893DD4752BA1C
                                                                                                                                                                                                                                                          SHA1:C07E7F72DBDC7F5F746385523EA733C2714F5DA2
                                                                                                                                                                                                                                                          SHA-256:C203E94465BD1D91018FC7670437226EF9A4BB41D59DDE49095363865CA33D00
                                                                                                                                                                                                                                                          SHA-512:5C20834542B74041AAB1DBE35686781B32EEB5814B1A35A942E87D1FC3B6D8F9264CB90433C44A480EA86DDEA65D8C152F41CE3E983C1DE5FA74D6FB5208F701
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Rome)]} {.. LoadTimeZoneFile Europe/Rome..}..set TZData(:Europe/Vatican) $TZData(:Europe/Rome)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7930
                                                                                                                                                                                                                                                          Entropy (8bit):3.8193566380830273
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:8F6zq+gH74elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxo:8ozE41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:6A3A8055DD67174E853C7A208BABAC9B
                                                                                                                                                                                                                                                          SHA1:64445543DE9D6C01FA858442976E249E37BE23EF
                                                                                                                                                                                                                                                          SHA-256:A8165313C9B51DAEF130401439CBA60DAA9887FC5EAA61A5AFD4F7BAD1AD934F
                                                                                                                                                                                                                                                          SHA-512:4407B9E8709A8DD05337A10030895AA9876EAF64EF5347952249EE2A541E304331B46D38532FD7CDFF9E633BF8C9884282F0A5ED259EBA1D99DC0914AF1A50C6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Vienna) {.. {-9223372036854775808 3921 0 LMT}.. {-2422055121 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1577926800 3600 0 CET}.. {-1569711600 7200 1 CEST}.. {-1555801200 3600 0 CET}.. {-938905200 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-780188400 3600 0 CET}.. {-757386000 3600 0 CET}.. {-748479600 7200 1 CEST}.. {-733273200 3600 0 CET}.. {-717634800 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {323823600 7200 1 CEST}.. {338940000 3600 0 CET}.. {347151600 3600 0 CET}.. {354675600 7200 1 CEST}.. {370400400 3600 0 CE
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7485
                                                                                                                                                                                                                                                          Entropy (8bit):3.7711709848169592
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:FAhEpkwCXkSV3A/PplKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBK0:FfWHUSKivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                                                                          MD5:1AB5FCEACC4E09074BA9F72F0B7747D5
                                                                                                                                                                                                                                                          SHA1:E0134E61EC0ADC60BF6DB4544EA7B7FFA4EC7857
                                                                                                                                                                                                                                                          SHA-256:B762DB4A068DC79FA57691E070D7026086E5A6D2FC273D5C1872E7C8E3711533
                                                                                                                                                                                                                                                          SHA-512:07565071D05CF972DD64F6060599EB68A00BF264172873BA310168AD07CE0CFCF90D0019B775433EC910DA748B89F0C614E7FD4E821993DA53C7E33F194C6A97
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Vilnius) {.. {-9223372036854775808 6076 0 LMT}.. {-2840146876 5040 0 WMT}.. {-1672536240 5736 0 KMT}.. {-1585100136 3600 0 CET}.. {-1561251600 7200 0 EET}.. {-1553565600 3600 0 CET}.. {-928198800 10800 0 MSK}.. {-900126000 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-802141200 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 7200 0 EEMMTT}.. {606873600 10800 1 EEST}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2123
                                                                                                                                                                                                                                                          Entropy (8bit):3.8686829358191845
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:menvCAs6kKR6aQmF1cSNWwVmTeCTU50x0YdS:mevCAs6kC6aZF1cSNZVmTeCTUax0YdS
                                                                                                                                                                                                                                                          MD5:3DC74C5B34E76D0A758B82C49F6FED1F
                                                                                                                                                                                                                                                          SHA1:98C0BD29E13C1F4453A1652FC9F206794846B6BD
                                                                                                                                                                                                                                                          SHA-256:2551A50EB75D83E6F04A9FF65A78029B05A36167AFA9F28E02B3914B5EE6B8E8
                                                                                                                                                                                                                                                          SHA-512:B10250033A72EE0E51285132662D5E5264A1045C204BC6CD777892C1C6A6454ED8097956CDB9B6FBA4AB51E3FC27619B53EC4D8080C53193EB0D817A51572052
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Volgograd) {.. {-9223372036854775808 10660 0 LMT}.. {-1577761060 10800 0 +03}.. {-1247540400 14400 0 +04}.. {-256881600 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 10800 0 MSD}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 14400 1 MSD}.. {622594800 10800 0 MSK}.. {638319600 14400 1 MSD}.. {654649200 10800 0 MSK}.. {670374000 14400 0 +04}.. {701820000 10800 0 MSD}.. {701823600 14400 1 MSD}.. {717548400 10800 0 MSK}.. {733273200 14400 1 MSD}.. {748998000 10800 0 MSK}.. {
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8662
                                                                                                                                                                                                                                                          Entropy (8bit):3.8187545871488995
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:ELn9M9Nivtctwwoy4qelPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCso:E6Nivtctgq1sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:992C1D268E336AF1FB8200966C111644
                                                                                                                                                                                                                                                          SHA1:C893B82224C8EF282DB2E16A5BBCC3A21C49B6FE
                                                                                                                                                                                                                                                          SHA-256:F9DC10EC2AE2CC810A6C08837059B34BE651900BA4E1CEDB93C209972CCFB5A2
                                                                                                                                                                                                                                                          SHA-512:EC4E0D8684D57FA66144F11D8E8C80E5272D4A7304300FEBE20E236476C1B8B33BBC5E479BF96D9ED12900FE6D41DD1DC0D11CBE02B89E0C4C7A153B4BFBCB1F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Warsaw) {.. {-9223372036854775808 5040 0 LMT}.. {-2840145840 5040 0 WMT}.. {-1717032240 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618696800 7200 0 EET}.. {-1600473600 10800 1 EEST}.. {-1587168000 7200 0 EET}.. {-931734000 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796870800 7200 0 CEST}.. {-796608000 3600 0 CET}.. {-778726800 7200 1 CEST}.. {-762660000 3600 0 CET}.. {-748486800 7200 1 CEST}.. {-733273200 3600 0 CET}.. {-715215600 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654130800 7200 1 CEST}.. {-639010800 3600 0 CET}.. {-397094400 7200 1 CEST}.. {-386812800 3600 0 CET}.. {-371088000 72
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):187
                                                                                                                                                                                                                                                          Entropy (8bit):4.899266605519742
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/sUE2tovXHAIgoq8sUE2oAovRL/yQa5rXv1/h8Q0:SlSWB9vsM3ymhrE2tSHAIgohrE2LovNB
                                                                                                                                                                                                                                                          MD5:B07D9D3A5B0D11A578F77995A5FBE12B
                                                                                                                                                                                                                                                          SHA1:1C4E186F2D53C0A1E6A82A6D33B172E403A41D6D
                                                                                                                                                                                                                                                          SHA-256:A49B3894EB84F003EB357647D6A40CEAF6213523196CC1EC24EEFD7D9D6D3C3E
                                                                                                                                                                                                                                                          SHA-512:43520AE325980B236C47C866620D1DA200AC0CD794E8EB642D2936D4B0ECEFE2DA0A93C9559D08581B3CCE2BC75251A4D5B967D376B16EB0C042B0ADCE1DCD01
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Zagreb) $TZData(:Europe/Belgrade)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):179
                                                                                                                                                                                                                                                          Entropy (8bit):4.999265802825238
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV2cvXHAIgoq1csFARL/yQa58KXkcAEfh8Qaocqn:SlSWB9vsM3ym5HAIgoiAN/yjzVbh8C
                                                                                                                                                                                                                                                          MD5:5B150E25521FE5DD8B83DD9B1B8F3A7A
                                                                                                                                                                                                                                                          SHA1:0BB6F73F2C4B2464F3B1E62138843389AF1A07BC
                                                                                                                                                                                                                                                          SHA-256:EF928AC09B9A366FD015F488B6A19FEFD72DE1BAF34E5CADFB8334946BCF19FE
                                                                                                                                                                                                                                                          SHA-512:4A85A4E929EC6FE66AE60899FA55A75156D075CB2FE41C19337A128F5FA7363B9208AC2DC1BF4E44B76D5F115143D73F6D923E255EA78538D1BE4E45DEBA2049
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Kyiv)]} {.. LoadTimeZoneFile Europe/Kyiv..}..set TZData(:Europe/Zaporozhye) $TZData(:Europe/Kyiv)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7305
                                                                                                                                                                                                                                                          Entropy (8bit):3.8199799674700277
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:94hH74elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxOrnW+:9Y41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                                                                          MD5:EBD66FAEA63E1B90122CC1EB21634ECE
                                                                                                                                                                                                                                                          SHA1:C6487BB8AB2A6A72B2170B220F383ADB6B9AC91C
                                                                                                                                                                                                                                                          SHA-256:95AFA61E439CA38551306D8FDB11C2788D935C42768D0407C9E4337F105A3E93
                                                                                                                                                                                                                                                          SHA-512:25A8D0ED9BBE6BF23A1A76CC6D5378CF4D50544AA22DA97DDCD0673D7A5CCFEFFD81B660A1AEFB254B8BBEA55F6EF734BBBD3F0CB903E0721BE107667CA1E328
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Zurich) {.. {-9223372036854775808 2048 0 LMT}.. {-3675198848 1786 0 BMT}.. {-2385246586 3600 0 CET}.. {-904435200 7200 1 CEST}.. {-891129600 3600 0 CET}.. {-872985600 7200 1 CEST}.. {-859680000 3600 0 CET}.. {347151600 3600 0 CET}.. {354675600 7200 1 CEST}.. {370400400 3600 0 CET}.. {386125200 7200 1 CEST}.. {401850000 3600 0 CET}.. {417574800 7200 1 CEST}.. {433299600 3600 0 CET}.. {449024400 7200 1 CEST}.. {465354000 3600 0 CET}.. {481078800 7200 1 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600 0 CET}.. {606877200 7200 1 CEST}.. {622602000 3600 0 CET}.. {638326800 7200 1 CEST}.. {654656400 3600 0 CET}.. {670381200 7200 1 CEST}.. {686106000 3600 0 CET}.. {701830800 7200 1 CEST}.. {717555600 3600 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):170
                                                                                                                                                                                                                                                          Entropy (8bit):4.8978035005721265
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/wox6QavKL81n:SlSWB9vsM3ymvKA2PHAIgovKAH6N/wRj
                                                                                                                                                                                                                                                          MD5:68667037110E713DB3F51922DDE929FE
                                                                                                                                                                                                                                                          SHA1:2EB02BE3FD35F105B59847892A78F1AA21754541
                                                                                                                                                                                                                                                          SHA-256:E20D829C605A7C5B2A96B83C3480DF28C964A13381A8BD2C72C2A37295131FA7
                                                                                                                                                                                                                                                          SHA-512:3A8CC2EC9E3053283F996CA2C4B422061D47F1D16CA07985CBA2C838DF322C23CC9DD28033646F22EAE0E401781480B9D3AF82A539444166A4DD9B7BCCAE45FE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:GB) $TZData(:Europe/London)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):175
                                                                                                                                                                                                                                                          Entropy (8bit):4.90874180513438
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/w4b/h8QavKL81n:SlSWB9vsM3ymvKA2PHAIgovKAH6N/w4E
                                                                                                                                                                                                                                                          MD5:625520BAAB774520AC54BFB9EDCF9FCA
                                                                                                                                                                                                                                                          SHA1:C72F0FD45F448901C6B2E24243175729591B9A54
                                                                                                                                                                                                                                                          SHA-256:C9334480D0A970254B6BA6FF22E958DC8DD8BF06288229461A551C7C094C3F1D
                                                                                                                                                                                                                                                          SHA-512:1B672218FF9C86168E065A98C3B5F67DAB710D1C2A319E9D6599B397C4B4C00D3721B76C735C8AB04BCB618C1832B07F6CCDAF4266CC0D12A461A3A862D1AEB2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:GB-Eire) $TZData(:Europe/London)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):153
                                                                                                                                                                                                                                                          Entropy (8bit):4.867609984313873
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/wZ8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/wZ8RQy
                                                                                                                                                                                                                                                          MD5:A01FE6FC260711F0E11C85DC3DE3550A
                                                                                                                                                                                                                                                          SHA1:988311B71498591425C63669DC3F802F270B2C44
                                                                                                                                                                                                                                                          SHA-256:747C15CDC239855D5380B7A7F47112F2A26C61B0BF300EEB9711E6521550D189
                                                                                                                                                                                                                                                          SHA-512:BE4678DCBAE5DBC72865665413206C1909F28BA54F4943257870EFFBA6525457866DED7A985E89F2689C810B314DE4AA2FA3A0A1826A664727F5F7113AA56595
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT) $TZData(:Etc/GMT)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):155
                                                                                                                                                                                                                                                          Entropy (8bit):4.917182390229381
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/we7/8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/wI8RQy
                                                                                                                                                                                                                                                          MD5:3327B1BF3118AC6AFC02C31DF5B67CD9
                                                                                                                                                                                                                                                          SHA1:3932577E66801AD31519B0BB56CCE7B9E36221A9
                                                                                                                                                                                                                                                          SHA-256:BE48462CCFBB3AEE19597F082A17C2C5D2FD8BB1C9122245EFAB0A51F8F413B0
                                                                                                                                                                                                                                                          SHA-512:53866FD513B039E8203E51FF3434D5736D3A4C4E0A46874D1C99A17115181AF749F0D079C2E14C5B0538D3DFA52B1645C977CD6599DA3EDA57CC7F84EEAB2D06
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT+0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):155
                                                                                                                                                                                                                                                          Entropy (8bit):4.904279164422928
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/w4Hp8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/w4J8RQy
                                                                                                                                                                                                                                                          MD5:0CFFC5655F031D954BD623CC4C74DC9C
                                                                                                                                                                                                                                                          SHA1:CE5E7AD67252F52D7E70719725FF5BE393DD6EF0
                                                                                                                                                                                                                                                          SHA-256:944C86F516141DDC3AEC1AE4A963E9769879C48ED12DADDF4ED63A01313ACD00
                                                                                                                                                                                                                                                          SHA-512:C7352D1394E8B8AC90CD19EE753D5277259BE5512ADDCAED2A2DEF144762CF20BE7A9FA09AAA1829EE401DD195C2AED8C967A7FF46739236E042AF4298EC84A2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT-0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):154
                                                                                                                                                                                                                                                          Entropy (8bit):4.892526720357546
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/wPHp8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/wvp8RQy
                                                                                                                                                                                                                                                          MD5:565B41A5DB28F9FE7D220E9BA39062A4
                                                                                                                                                                                                                                                          SHA1:5183689210F07C8A71F880DCE8E5C2CB62CEB17D
                                                                                                                                                                                                                                                          SHA-256:54850A5F488205DB01FBB46E2DA9FFF951C4571029EA64D35932DDEA5346DAAF
                                                                                                                                                                                                                                                          SHA-512:BD6E5141F06B03D62DCF725E9E48D6AA8ECD6E8E47A4015B25DC3F672392065FFFD80D688C6695324DC105EA528025CF447FA77E6D17E15D438E61DC51879CB7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):159
                                                                                                                                                                                                                                                          Entropy (8bit):4.917976058206477
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/wE+FB5yRDMovn:SlSWB9vsM3yFXHAIgnvVHN/wE6BURQy
                                                                                                                                                                                                                                                          MD5:443FA76F107ED438F9571A044B848C6A
                                                                                                                                                                                                                                                          SHA1:1CF508429DFC40643B1FAB336A249A3A287D8C7C
                                                                                                                                                                                                                                                          SHA-256:9E7A8DAA26CE36E8F7D7F13460915C063EE98E2A4DB276AD9D15CA5C7C06815F
                                                                                                                                                                                                                                                          SHA-512:6C0C5FF513A742FBDA349AC3A2581D456701B5348A54ECF38E496DAA1EFC74D937982B6F69F1761CC2FC4B88D9A971EFA2B16096E71EAF002EC5CE4130B533DE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Greenwich) $TZData(:Etc/GMT)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):111
                                                                                                                                                                                                                                                          Entropy (8bit):4.90682088010982
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x//LhdNMXGm2OH1V90v:SlSWB9eg/jJDm2OH1VGv
                                                                                                                                                                                                                                                          MD5:79C82A5F8B034E71D0582371E3218DBB
                                                                                                                                                                                                                                                          SHA1:1476CE8EA223095094B6D25D171E6319C96669F4
                                                                                                                                                                                                                                                          SHA-256:8D710699AF319E0DDB83E9F3A32D07AE8082EA2F7EABBD345EFFFFB0F563062E
                                                                                                                                                                                                                                                          SHA-512:ADEE55581D1A158929F09A63B03883ABE9193337DDF225C61AFDBB8A2C7D0BD248ADC4714E0EEFD334826C54C1AFFC8B1E6C2B0D6EF830C3CCA50CC79834F473
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:HST) {.. {-9223372036854775808 -36000 0 HST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):179
                                                                                                                                                                                                                                                          Entropy (8bit):4.913328649996328
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8Li0vXHAIgN2qfvRL//XF1p4WFKQyvn:SlSWB9vsM3yW2HAIgAOvN///p4wKlvn
                                                                                                                                                                                                                                                          MD5:6A307B229C302B1BAE783C8143809269
                                                                                                                                                                                                                                                          SHA1:EA169AF81AD12380A69FB6B7A12479BA8B82878B
                                                                                                                                                                                                                                                          SHA-256:359C9C02A9FA3DE10BA48FA0AB47D8D7AFF3B47F950CFAF5EB68F842EA52AB21
                                                                                                                                                                                                                                                          SHA-512:505445FD0B3E140384EDC27993923BBF9ACD23A244B0F14D58804BFAA946D0BC4C0D301FBCCB492BAFDA42C8A92F4163FB96F4D75DD7374858D1C66183BEC24B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Hong_Kong)]} {.. LoadTimeZoneFile Asia/Hong_Kong..}..set TZData(:Hongkong) $TZData(:Asia/Hong_Kong)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):178
                                                                                                                                                                                                                                                          Entropy (8bit):4.853280551555672
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/+GAKyx/2DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/+XZx+D4
                                                                                                                                                                                                                                                          MD5:710D3A32EA8EAD11B45D4911DA8F2676
                                                                                                                                                                                                                                                          SHA1:146D2A6D48940E58567EFA3BCA134D195E4649E6
                                                                                                                                                                                                                                                          SHA-256:8A531293F672D8FE38996989FC4EEB22B5EFE6E046E2F58E94D01DA9CE56EF68
                                                                                                                                                                                                                                                          SHA-512:70432973549C1A83036E0658AEE81C883F19D0D631E35F4C70F2EC69C9384E99340004618EF8B414D8EA9090C6C3120CF46A5D9ABDE4113917995B2844337988
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Iceland) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.807410166086502
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/+L6EL/liEi2eDcVVMB:SlSWB9vsM3y7VTHAIgNTxcAN/+LzM2eV
                                                                                                                                                                                                                                                          MD5:0F20CBF1F7600D05F85D4D90FDAB2465
                                                                                                                                                                                                                                                          SHA1:2F3C9479C4F4CD7999B19C07359B89A5FB1B9839
                                                                                                                                                                                                                                                          SHA-256:1B1177CE4D59D7CBCAE9B0421EB00AD341ECB299BD15773D4ED077F0F2CE7B38
                                                                                                                                                                                                                                                          SHA-512:657341FC2CCD6A4F7B405ABC8E24C651F6FFEFD68EBD6E2086ADF44834DCBF21D1B9D414436E42C8DCE46FFB88116B98C1D073782E214B3996D49EC00DFF4383
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Indian/Antananarivo) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):180
                                                                                                                                                                                                                                                          Entropy (8bit):4.853088038233057
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/+L6EL9WJx3vFNMXGm2OHi/FvoHscfJ7XH0VQVFV6VVFSTVV:SlSWB9eg/+LxWJxPDm2OHqFvoH9+VQV3
                                                                                                                                                                                                                                                          MD5:06143C3DFD86B3FE4F2A3060C0E05BB6
                                                                                                                                                                                                                                                          SHA1:88E0E30CEE4AB8117860A35AD03B16AF48988789
                                                                                                                                                                                                                                                          SHA-256:11044AD7CB0848CC734D2A67128AA6AC07CB89268399AA0A71A99024DE4B8879
                                                                                                                                                                                                                                                          SHA-512:79195D3D0D475BEA982F40683D4BA14AC33B3FA91311F513DCED955C9297C2B0F12D94CCA930FAE0FB7F95DB34CD4E74B5AF0233E792122646592B7EFF0F3163
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Indian/Chagos) {.. {-9223372036854775808 17380 0 LMT}.. {-1988167780 18000 0 +05}.. {820436400 21600 0 +06}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):181
                                                                                                                                                                                                                                                          Entropy (8bit):4.910217468889087
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8VLYO5YFfXHAIgN8ELYOJARL/+L6EL9FBIEWoxp4Wx:SlSWB9vsM3y1LePHAIgKELtAN/+LxpWg
                                                                                                                                                                                                                                                          MD5:39CB9E58C0086B80FB12AC10A6D371E2
                                                                                                                                                                                                                                                          SHA1:2A9A5CCA411779615A62D9E82023B6A066CB3CF3
                                                                                                                                                                                                                                                          SHA-256:78A208B73426A1B6D7CF2FE89A0EF3F01721F877D569BC43F2E5B6625A947299
                                                                                                                                                                                                                                                          SHA-512:BB6C8CF2B6AF9F93A7F7382A453261FA43E6E42E9ED1223F25A70DAD2ABBBF2F5777288553F4BC0155944754655D2C3F81BD81E5B1F611C4B2CCDB729B67AAC5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Bangkok)]} {.. LoadTimeZoneFile Asia/Bangkok..}..set TZData(:Indian/Christmas) $TZData(:Asia/Bangkok)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):174
                                                                                                                                                                                                                                                          Entropy (8bit):4.818886812441817
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8nv3vXHAIgNnDA6RL/+L6EL9dEh4WFKsyn:SlSWB9vsM3yHvPHAIg15N/+Lxah4wKsy
                                                                                                                                                                                                                                                          MD5:9462E9CFC88C3DA3CCCDA18C92E49A97
                                                                                                                                                                                                                                                          SHA1:B50C82C6C7361BD6F028F82E2FEAF8486D798137
                                                                                                                                                                                                                                                          SHA-256:EB301EE97A9FDE8ACE0243941C0FAC9ED0E3ACFD6497ABE408F08E95FAE3B732
                                                                                                                                                                                                                                                          SHA-512:A48EBDA0A93C3505BC6149863F4A7B1043F856A8EB516CF42C050A95E81CD152BC1C0313B3DD115D53DABA95413AF34902D7D11C984DE5A03FC5FFADAF8EA89F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Yangon)]} {.. LoadTimeZoneFile Asia/Yangon..}..set TZData(:Indian/Cocos) $TZData(:Asia/Yangon)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.825881690094318
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/+L6EL9TKlBx+DcVVMB:SlSWB9vsM3y7VTHAIgNTxcAN/+LxGV+V
                                                                                                                                                                                                                                                          MD5:7EBDFA311C7852AFADF880395071DE48
                                                                                                                                                                                                                                                          SHA1:F6EC21FDFB75EC1BE45B1C4170147CBA3E870E7B
                                                                                                                                                                                                                                                          SHA-256:53FA58E32DC2E4ABB574B2F78011815EEB7F89F453CC63C6B6C1460ABBB4CA5C
                                                                                                                                                                                                                                                          SHA-512:DFBCD4EA4AFFA1D1CAE7308168874527FD36B5CAE76153AADA9C5E5F628258AB26654A16C8A5F8906FC5918398FD880B15B6DD4E3EF6AD3BE63D4A2455701FA8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Indian/Comoro) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.822075418239496
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqKGE4YF3vXHAIgnGED9HRL/+L6EL12h6hwL6ELzEov:SlSWB9vsM3ypGEVFPHAIgnGEtN/+L5Ry
                                                                                                                                                                                                                                                          MD5:9AB222C67E079B55DDF3ACAE67BD0261
                                                                                                                                                                                                                                                          SHA1:F9E6C34A00F9F1B152CEA729F087BD24993CA2E8
                                                                                                                                                                                                                                                          SHA-256:138C7FFBFC520372658CA0CD1B42C4E5A240E9D9B98A277B02481DE5701222FC
                                                                                                                                                                                                                                                          SHA-512:5F3EFF78506056F981DB0446436B39953D90265227890176D8287E2149B176B9DCCA14E795083B1EBC202D02AA88D584A9BB49868F30895EF17E92AA98ACB7C7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Indian/Maldives)]} {.. LoadTimeZoneFile Indian/Maldives..}..set TZData(:Indian/Kerguelen) $TZData(:Indian/Maldives)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):170
                                                                                                                                                                                                                                                          Entropy (8bit):4.84472938642971
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8DeXHAIgN6S7ARL/+L6ELzJM1h4WFKQ3n:SlSWB9vsM3yj+HAIgMS7AN/+L/Yh4wKC
                                                                                                                                                                                                                                                          MD5:C866B2A879786B7D9341FA904FC7D01A
                                                                                                                                                                                                                                                          SHA1:DAF7B405E6DAA0C88C6F3A26AAA172E38CE5CAF3
                                                                                                                                                                                                                                                          SHA-256:613C5C05A8867E4B59A97A3D8C7235DDC0CA23239F2D57A5BFD42E4AB94FD510
                                                                                                                                                                                                                                                          SHA-512:BB01A464366F1F93591F48C42F300421AF774E50E5B5232AB0C755482E3306EDDB54A9BCF6E9D325EAE63AAC6D3857F4D754FC28A34F90AC728B7158B61E2C57
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dubai)]} {.. LoadTimeZoneFile Asia/Dubai..}..set TZData(:Indian/Mahe) $TZData(:Asia/Dubai)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):183
                                                                                                                                                                                                                                                          Entropy (8bit):4.883092265054605
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/+L6ELzE5FNMXGm2OHnz8eoHvZT5lxV/uUQwGN0VQVFv:SlSWB9eg/+L/EJDm2OHnz8eoHvZT5rdI
                                                                                                                                                                                                                                                          MD5:4DF975C040D78FA8F9C92E5565D63A73
                                                                                                                                                                                                                                                          SHA1:48488F076871530D32278084F1C9CB90CB1E6AB4
                                                                                                                                                                                                                                                          SHA-256:9FAC69DC609CC6074ECD67E0BE8AE62E33D8D9C7F055A3E0DEE1430C7FFC54F6
                                                                                                                                                                                                                                                          SHA-512:880B920FB51F48731BA8C741B9583038A3276221C55F1CE0B464D2797D71EF9D22B4E166841BAB0544B7091CE683697BFCA5A4235FF1E6264B0619DBDD4BB619
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Indian/Maldives) {.. {-9223372036854775808 17640 0 LMT}.. {-2840158440 17640 0 MMT}.. {-315636840 18000 0 +05}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):272
                                                                                                                                                                                                                                                          Entropy (8bit):4.5144164346164715
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/+L/GDm2OHlNnoH9SvulvSNFF+c0FSFFMVhvSNFFVBjvVFSFFVGlvSN:MB86+L/CmdHlNnCy6qB0FScZq9BjVFSL
                                                                                                                                                                                                                                                          MD5:05362B6A17C5F4F4E8CBE5A676D5D0DE
                                                                                                                                                                                                                                                          SHA1:84675D5E8D1425A5E9DB07D1BC1E6A5921B5AC91
                                                                                                                                                                                                                                                          SHA-256:A2B1B93CBEECBD900ED71E61A4932509EB52688E97A6015DAD067066D0D42072
                                                                                                                                                                                                                                                          SHA-512:351D2BC5F5888D8E842BF160D11D57E059811186D63B0413061768C7FE348CECB700748A0C0125F0ABCBB039FC74FF7BEEFDD42088BA1E28C785E545ED2CDF24
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Indian/Mauritius) {.. {-9223372036854775808 13800 0 LMT}.. {-1988164200 14400 0 +04}.. {403041600 18000 1 +04}.. {417034800 14400 0 +04}.. {1224972000 18000 1 +04}.. {1238274000 14400 0 +04}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.828945679595274
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/+L6ELzO1h4DcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/+L/O1hm
                                                                                                                                                                                                                                                          MD5:8ABBEC0E138C1A68CB5D096E822DE75E
                                                                                                                                                                                                                                                          SHA1:E9C5CE1A249F6DC0F6EDBB3F5B00F3106E3BD6CA
                                                                                                                                                                                                                                                          SHA-256:845C45FD7B6F0604B03A3C72DB117878B568FB537BCA078304727964157B96AB
                                                                                                                                                                                                                                                          SHA-512:15790CCA70140D3139F3E2A202DC8F12E68466A367C68458D6A78CDDC7822FB5EDB87D630926B51F3DE48D95DE7CA3FCB946CD7B762FE5B15866DAA9DBA40B46
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Indian/Mayotte) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):173
                                                                                                                                                                                                                                                          Entropy (8bit):4.825214661273383
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8DeXHAIgN6S7ARL/+L6ELsAceh4WFKQ3n:SlSWB9vsM3yj+HAIgMS7AN/+Lj4wKQ3
                                                                                                                                                                                                                                                          MD5:7B22FE05231A5721C939B6018F8A2814
                                                                                                                                                                                                                                                          SHA1:E272C25E79ABE705B2DB106D70DEAB3245EA9D35
                                                                                                                                                                                                                                                          SHA-256:5560B0D4A2D8A13D9FE9787FFFE31200D405A8C875F046C8FDDF850AF98662B6
                                                                                                                                                                                                                                                          SHA-512:26244855D029151B84A4D57E2FA69632B4F19F8C00B2E500A394D76A29857BE2A412344794BA0DFF50A2863FF17889210A151D0E231A67E55091F4909EC4AE79
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dubai)]} {.. LoadTimeZoneFile Asia/Dubai..}..set TZData(:Indian/Reunion) $TZData(:Asia/Dubai)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):166
                                                                                                                                                                                                                                                          Entropy (8bit):4.809541513808179
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8g5YFeovXHAIgNqjyVHRL/+XiMr4WFKBpv:SlSWB9vsM3yA5oPHAIgcjeHN/+Xvr4wY
                                                                                                                                                                                                                                                          MD5:A90C26358FEF60E49044E3BE02866FAC
                                                                                                                                                                                                                                                          SHA1:137AC8CCA23F39E7A16C4050EA9A3A8731E9AAD7
                                                                                                                                                                                                                                                          SHA-256:FE7F4453CB5F6B81B23C1C795356B91FE319F0762BE7868FAFE361DB1F9C2A2B
                                                                                                                                                                                                                                                          SHA-512:D6C74CACF69D29E14CB46E5DD885234AC50EE2E258E0C5E3AC76465061622F064F974D33E91A6A020B9D618D90799DDA6EB1EA53022EDB6E26A9CB6ADFE0AA30
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Tehran)]} {.. LoadTimeZoneFile Asia/Tehran..}..set TZData(:Iran) $TZData(:Asia/Tehran)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):177
                                                                                                                                                                                                                                                          Entropy (8bit):4.8290104377288925
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq85zFFfXHAIgN0AzFFVHRL/+WXnMr4WFKYzFgn:SlSWB9vsM3yZbPHAIgCAXRN/+zr4wKY+
                                                                                                                                                                                                                                                          MD5:6BCC43951637D86ED54585BE0819E39C
                                                                                                                                                                                                                                                          SHA1:6F04F306B3AB2A6419377294238B3164F86EF4A3
                                                                                                                                                                                                                                                          SHA-256:805105F5F17B78929F8476BAE83ED972128633FF6F74B7748B063E3C810C27A6
                                                                                                                                                                                                                                                          SHA-512:ABB9F4308BF4BD5C62C215A7ECD95042CBFB3005AF1E75F640962B022574C930DD5A12CD0CE0AF8A3D7E38B999E37C3A45A55091683F6A87E9D0CDA9EE417293
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Jerusalem)]} {.. LoadTimeZoneFile Asia/Jerusalem..}..set TZData(:Israel) $TZData(:Asia/Jerusalem)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):181
                                                                                                                                                                                                                                                          Entropy (8bit):4.722012123002917
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx00EIECWXHAIg200EIE/vHRL/9S//2IAcGE0EIESvn:SlSWB9vsM3y795VHAIgp95HN/029095c
                                                                                                                                                                                                                                                          MD5:1F020341AD51AA82794B8018F214DE0D
                                                                                                                                                                                                                                                          SHA1:4414E56C1277B4D31FE557F8652D522C0594F4B2
                                                                                                                                                                                                                                                          SHA-256:F01B00D52BD7B2694BF5CB55A17028C30A41BD22A774CA54740E8B1DDE4FCB2E
                                                                                                                                                                                                                                                          SHA-512:CC41848A851D4992AE9F27C38669CB87CE2FD05A33AB6989EA21AFCB1A2707DE0CB4D62BCC45E536DD944859991D7564847205F47509A42D41932370496A77D7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Jamaica)]} {.. LoadTimeZoneFile America/Jamaica..}..set TZData(:Jamaica) $TZData(:America/Jamaica)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):164
                                                                                                                                                                                                                                                          Entropy (8bit):4.8422204749795545
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8aofXHAIgNqsRL/9hM7/4WFK9vn:SlSWB9vsM3ypPHAIgcsN/4r4wKNn
                                                                                                                                                                                                                                                          MD5:9554A65BFFCFFCFB2C1588569BB4638E
                                                                                                                                                                                                                                                          SHA1:B377ECB04586396D37093856AEF8BBDC93192F66
                                                                                                                                                                                                                                                          SHA-256:98DBD07AE3B9251B9091F4D265336CE98BDFB492AF863C1F3FF25248A2CADF35
                                                                                                                                                                                                                                                          SHA-512:E2E761B8B1995B68721BC714A546E0F45EEC025FAF81DE579FF0D73D37783D0E031B9E78BA2FAC6B097E3673C47AFB8761FBC58E42E33018FD44B77F2871E0C6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Tokyo)]} {.. LoadTimeZoneFile Asia/Tokyo..}..set TZData(:Japan) $TZData(:Asia/Tokyo)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.810216093939366
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG1/EOM23vXHAIgObT1/EOMH6RL/8/FMKpUDH1/Ex:SlSWB9vsM3yc1EiPHAIgOb1E+N/8xMEx
                                                                                                                                                                                                                                                          MD5:05C0C40F2AA456F580EAAFC4F7E49B56
                                                                                                                                                                                                                                                          SHA1:5796A9122693B2D6010BC5E617A6091F46330B0C
                                                                                                                                                                                                                                                          SHA-256:85E95363ACF468043CD5146927A97B2D9E3B141EDA0A7993DADA9382D1D6DD54
                                                                                                                                                                                                                                                          SHA-512:2155F8E3EB73312F0AFD5CDDF4B19EBB67A15658101870C2CEDF96955470DBC7B30F34E143D9C14CBFA7A138F63324009581BD0B807AE295C68588CA0470D7AD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Kwajalein)]} {.. LoadTimeZoneFile Pacific/Kwajalein..}..set TZData(:Kwajalein) $TZData(:Pacific/Kwajalein)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):176
                                                                                                                                                                                                                                                          Entropy (8bit):4.829980800076139
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsbKJqYkyXHAIgNGEnKJp0ARL/7beDcbKJ6v:SlSWB9vsM3y7JSHAIgNTxAN/PeDE
                                                                                                                                                                                                                                                          MD5:4D44D88336212E162CCEFADE6321EDBC
                                                                                                                                                                                                                                                          SHA1:B9EE7AFE26DC61AA9EA37EB99A3C10DD176E8063
                                                                                                                                                                                                                                                          SHA-256:F776839C1999056E6A0D2ECFDF9054FC309454AFDFF8E8BC803F33EC423B7361
                                                                                                                                                                                                                                                          SHA-512:FDDCBD194DE07B51DEBBDEF4FD96762EE3507117443FB9F7975FB56E0AE97B0D1F8657FE26B092021FB12B5A5D3EFFAB9E0A54B1C2AFCEC1029855442A0A95AB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Tripoli)]} {.. LoadTimeZoneFile Africa/Tripoli..}..set TZData(:Libya) $TZData(:Africa/Tripoli)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7736
                                                                                                                                                                                                                                                          Entropy (8bit):3.799706947156251
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:aJCP8D3pCS2JWk55EyqJNSPTub3NDOyFyJYVtLbTxdqs0xcQVq+O7JSAmwQZjltB:FSyWBSPTujlOyqc3JuzVNvTN
                                                                                                                                                                                                                                                          MD5:02B993B4A6956014A2DB844E8A5498C0
                                                                                                                                                                                                                                                          SHA1:378333547254AC43BEB4FA2CBC24B8DE241B3078
                                                                                                                                                                                                                                                          SHA-256:DF45F5414F1636B1856C7534BB5F3D4387C32D56283A68BB47D8C48C1DDAD5BC
                                                                                                                                                                                                                                                          SHA-512:CC3ABCC1FB5ABD10A685F140931DE38D6875142D3595F8D9A581F5B31A7F354FA4CCC9727B69F58E0D2F773EA0F76D9ACFDF7ACBAFC6BAA6E93A46EAE8F18672
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:MET) {.. {-9223372036854775808 3600 0 MET}.. {-1693706400 7200 1 MEST}.. {-1680483600 3600 0 MET}.. {-1663455600 7200 1 MEST}.. {-1650150000 3600 0 MET}.. {-1632006000 7200 1 MEST}.. {-1618700400 3600 0 MET}.. {-938905200 7200 1 MEST}.. {-857257200 3600 0 MET}.. {-844556400 7200 1 MEST}.. {-828226800 3600 0 MET}.. {-812502000 7200 1 MEST}.. {-796777200 3600 0 MET}.. {-781052400 7200 1 MEST}.. {-766623600 3600 0 MET}.. {228877200 7200 1 MEST}.. {243997200 3600 0 MET}.. {260326800 7200 1 MEST}.. {276051600 3600 0 MET}.. {291776400 7200 1 MEST}.. {307501200 3600 0 MET}.. {323830800 7200 1 MEST}.. {338950800 3600 0 MET}.. {354675600 7200 1 MEST}.. {370400400 3600 0 MET}.. {386125200 7200 1 MEST}.. {401850000 3600 0 MET}.. {417574800 7200 1 MEST}.. {433299600 3600 0 MET}.. {449024400 7200 1 MEST}.. {465354000 3600 0 MET}.. {481078800 7200
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):111
                                                                                                                                                                                                                                                          Entropy (8bit):4.902637155364683
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/6xtNMXGm2OHrXV4foAov:SlSWB9eg/6lDm2OHrCAAov
                                                                                                                                                                                                                                                          MD5:36119516E87814F3C219193069CD6A90
                                                                                                                                                                                                                                                          SHA1:BDB25531B30E6FC454100F37177EC9D4A0FB4E39
                                                                                                                                                                                                                                                          SHA-256:E57746D5DB479A8B30973F2BC16E2B8DFB6E2BFAECBFF0FB956F04526E4B935B
                                                                                                                                                                                                                                                          SHA-512:2730C5DABA0B2CCFD32A799C48EE07351659F51B9C2B91DCD145675AF276F2D0B5AA51ACF7D283C0DC236D3AFA3A75E58EB9F970B1831A6E36F02139CAF6A655
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:MST) {.. {-9223372036854775808 -25200 0 MST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8505
                                                                                                                                                                                                                                                          Entropy (8bit):3.8405400251137207
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:T1ktwmGaLV911sF7Lv/PCewtA8CzSPyDLbrcUia:TswDPlLv/PCenJzS6cy
                                                                                                                                                                                                                                                          MD5:87B3BCD4A793BA383889ECFDB44C846E
                                                                                                                                                                                                                                                          SHA1:3EA34B5E6E3078A9501653BA069D5E5E879D7FE4
                                                                                                                                                                                                                                                          SHA-256:A5DEB89D59613D9A54C1E146056A805B3DE9F2A2593AEC2B8A25F863328699C0
                                                                                                                                                                                                                                                          SHA-512:AA4DAC2614661EF18A2A60A5BD4D5BBBCCB5D721F90A25E9D11C5B6AF8C39FD475B3E23894719E2F8F74469F13D5492FF31DDD193D9E3172182FBCBCDD860A41
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:MST7MDT) {.. {-9223372036854775808 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126694800 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {230720400 -21600 1 MDT}.. {247046400 -25200 0 MST}.. {262774800
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.884776849010803
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qfSfXHAIg20qfORL/6AdMSKBbh4IAcGEqfBn:SlSWB9vsM3y7ekHAIgpeON/68K5h490m
                                                                                                                                                                                                                                                          MD5:3050A0100A2313C1D3AB4278B464F17A
                                                                                                                                                                                                                                                          SHA1:1A140447B3972900F13768659FD6979F68126E97
                                                                                                                                                                                                                                                          SHA-256:F8CA38A845CD01BF785EE222277DAD9325AB6BD17E44A362C450855AEB522814
                                                                                                                                                                                                                                                          SHA-512:C91C4BF2318C50D473E6051855C12F0E11CBAA8580B88115CDDE054D36476A1D8DDC5D17A7A123BD84148C20B96BD839511EAD573F5FD2C9A8556646B9CDE5E5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Tijuana)]} {.. LoadTimeZoneFile America/Tijuana..}..set TZData(:Mexico/BajaNorte) $TZData(:America/Tijuana)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):191
                                                                                                                                                                                                                                                          Entropy (8bit):4.8897674180962145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0zjRJ+ovXHAIg20zjRJ8yHRL/6AdMPCoQIAcGEzjy:SlSWB9vsM3y7zjRJvHAIgpzjRJ8yHN/Z
                                                                                                                                                                                                                                                          MD5:FAFD9727A0E153AFCB726690D215DA76
                                                                                                                                                                                                                                                          SHA1:3CD3B2737FC781F38DE26E255968CBB88B773CBF
                                                                                                                                                                                                                                                          SHA-256:2E6E32A40487F0146B59150B66FF74901CA853B12D47922819AF23EEA5B4149C
                                                                                                                                                                                                                                                          SHA-512:76D110494D4EB76961C818B2A2CCB2303B31DA161664FA712C87B95B81DE7B8F3E50DC7B2836C6ECC6437AE9595668E62E4E706F1B343EFEA12C32210F113540
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Mazatlan)]} {.. LoadTimeZoneFile America/Mazatlan..}..set TZData(:Mexico/BajaSur) $TZData(:America/Mazatlan)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):200
                                                                                                                                                                                                                                                          Entropy (8bit):4.877941255622543
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y7zBDSHAIgpzBx6N/6BXl490zBf:MByMYzppzH6t6Bi90z1
                                                                                                                                                                                                                                                          MD5:29ACBFCD0FD521EC0C9523906B9E2252
                                                                                                                                                                                                                                                          SHA1:BBC1AD3F78CAA634A2F0BC38059975EF8E4A2CE9
                                                                                                                                                                                                                                                          SHA-256:2DFF1B83FECFAD5C27EC47B206696C29B91398F8185B5D406A66FA9E0AECA93F
                                                                                                                                                                                                                                                          SHA-512:802502010CFB6F1F4E60C22ECB0E6CA22750975E5838BE7E7DC9D12EA019CB6508F0F87465A113A98356CC9E145E32E6633AE2B45B93412A358C4AD13E923EFE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Mexico_City)]} {.. LoadTimeZoneFile America/Mexico_City..}..set TZData(:Mexico/General) $TZData(:America/Mexico_City)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):179
                                                                                                                                                                                                                                                          Entropy (8bit):4.888611285267583
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG/u4WXHAIgObT/KvRRL/5E1nUDH/uov:SlSWB9vsM3ycqXHAIgObOvRN/iy
                                                                                                                                                                                                                                                          MD5:92548E239012515D756E002768CA876A
                                                                                                                                                                                                                                                          SHA1:6BDC73DBD7356C3F82C5C76E6E2D58656FA9E21D
                                                                                                                                                                                                                                                          SHA-256:E22D629D53C54960AD156C377DE0AE461C27F554990A3D1305724CA8F869BCE4
                                                                                                                                                                                                                                                          SHA-512:42AD074EE08E083EE91270F203707698A8B3308005C94514B8B2D950F4C6F0B37D7D32973EC9F6AB49A0875209076FB40341B31433A27E47B3CC0EA711ECE321
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Auckland)]} {.. LoadTimeZoneFile Pacific/Auckland..}..set TZData(:NZ) $TZData(:Pacific/Auckland)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):181
                                                                                                                                                                                                                                                          Entropy (8bit):4.881663364410736
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG9WQ+DyXHAIgObT9WQiovRL/5AmtBFB/pUDH9WQg:SlSWB9vsM3ycwQ+DSHAIgObwQTN/zzJ7
                                                                                                                                                                                                                                                          MD5:3811C133C6311E33FDAF93660E1EAED5
                                                                                                                                                                                                                                                          SHA1:64756FF877B2EB91BAED2889B3924DAB6784DF43
                                                                                                                                                                                                                                                          SHA-256:83F4CA3522B64F9B151EDEFAE53E0F28C2E6C4CE16D0982186B3344F2A268724
                                                                                                                                                                                                                                                          SHA-512:7724D6CD08E13E116CCDF073F86CE317C0D4A849C5FE81DF3127D435704507FBF554BFC6E7A50CCA3852F6001D8654B7FF90466878DB8C3298338BE16149FD32
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Chatham)]} {.. LoadTimeZoneFile Pacific/Chatham..}..set TZData(:NZ-CHAT) $TZData(:Pacific/Chatham)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):177
                                                                                                                                                                                                                                                          Entropy (8bit):4.8545620422964015
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx06RGFfXHAIg206RORL/5vf1+IAcGE6RB:SlSWB9vsM3y7+SPHAIgp+ON/pd+90+B
                                                                                                                                                                                                                                                          MD5:5E9F3294F68873BF503F3DDDDF6713B0
                                                                                                                                                                                                                                                          SHA1:954CD6F123C043E64F5E49733327E2C78877BDFB
                                                                                                                                                                                                                                                          SHA-256:2CC8CE235F2EE3160E6AFD04A4E28AA0312494EBB6FED08D8CC81D414EC540EE
                                                                                                                                                                                                                                                          SHA-512:200FC489989CA57219D5B28FB135BE5BDAC67239F3D243C496545D86D68089E51856CEAC4D2E700C0E47BAE4D5FEAB18A367C554235615B2B860F4E5E1BB08C3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Denver)]} {.. LoadTimeZoneFile America/Denver..}..set TZData(:Navajo) $TZData(:America/Denver)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):171
                                                                                                                                                                                                                                                          Entropy (8bit):4.902914099699953
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8qvfXHAIgNtaYFARL/nL75h4WFKdy:SlSWB9vsM3yMPHAIgO8AN/H5h4wKU
                                                                                                                                                                                                                                                          MD5:87C439DC623BF5C7EB01ADA6E67FB63A
                                                                                                                                                                                                                                                          SHA1:1CC357558E09CDEA49F821826D2AEA9A6EF2C824
                                                                                                                                                                                                                                                          SHA-256:6A5BAA9CA54B2A2C6D21287443BE0B1064AA79B5C4C62939933F8A0AD842B73E
                                                                                                                                                                                                                                                          SHA-512:E628B8F1C967AABAEFBB68A33416F6FE47422970BA18414BB3396AC063E65A4DC892595D4071395194AF320633EE915A494E1F8D4216EE8194A034739D275C49
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:PRC) $TZData(:Asia/Shanghai)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8505
                                                                                                                                                                                                                                                          Entropy (8bit):3.836877329152454
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:0KhTG0hjvZkR/bvtw+N6IkWq/WHQlb/RYRWVIKr7cRRL:0sG0U9bFzN6IkWq/WHQt/RY4yP
                                                                                                                                                                                                                                                          MD5:45E7E9E183A990F56E17C04FA48CE620
                                                                                                                                                                                                                                                          SHA1:A1F39E0ECEA3C64E761A9A3159E331FA51B625F9
                                                                                                                                                                                                                                                          SHA-256:D148708F1E70EEFA51E88E5823776CBE710535D4D6D6356E7753A44463A1C5AB
                                                                                                                                                                                                                                                          SHA-512:1D1F4BA90D07D7EE12DFD0E37DBFD5410A4EAFFBA8960B816FDD5963CD6B20938080A4248E7B249AAE02F068E817AB9A85735D226F7DA8DD2C5462A70B18E8EF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:PST8PDT) {.. {-9223372036854775808 -28800 0 PST}.. {-1633269600 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-1601820000 -25200 1 PDT}.. {-1583679600 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-84376800 -25200 1 PDT}.. {-68655600 -28800 0 PST}.. {-52927200 -25200 1 PDT}.. {-37206000 -28800 0 PST}.. {-21477600 -25200 1 PDT}.. {-5756400 -28800 0 PST}.. {9972000 -25200 1 PDT}.. {25693200 -28800 0 PST}.. {41421600 -25200 1 PDT}.. {57747600 -28800 0 PST}.. {73476000 -25200 1 PDT}.. {89197200 -28800 0 PST}.. {104925600 -25200 1 PDT}.. {120646800 -28800 0 PST}.. {126698400 -25200 1 PDT}.. {152096400 -28800 0 PST}.. {162381600 -25200 1 PDT}.. {183546000 -28800 0 PST}.. {199274400 -25200 1 PDT}.. {215600400 -28800 0 PST}.. {230724000 -25200 1 PDT}.. {247050000 -28800 0 PST}.. {262778400
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):909
                                                                                                                                                                                                                                                          Entropy (8bit):4.042826306713664
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86HbmdH2oVCvcCfdf3NaDyTb6Dye78ubUt1NEUtszIVbUtoUtoUt3mbUt4qUt6:Yekv5fcfem+Cuy
                                                                                                                                                                                                                                                          MD5:E5B913965F72AB807BAE67BD20C0A699
                                                                                                                                                                                                                                                          SHA1:2161B73EC868C8D18C09970766D19A8583FF7981
                                                                                                                                                                                                                                                          SHA-256:983884249ACC11C3FE740D78E72B1A89BE9C8B077283549BF6BCD8C93FA71731
                                                                                                                                                                                                                                                          SHA-512:F8807C52DB852C48C62F25569C990C31D977BC7D0DF502CF2B92F9ED6BCB89A6DD8A6758FBD1185E0B5C34DE5450D5C748B71760AC93E72DC3976B3B31D1A605
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Apia) {.. {-9223372036854775808 45184 0 LMT}.. {-2445424384 -41216 0 LMT}.. {-1861878784 -41400 0 -1130}.. {-631110600 -39600 0 -11}.. {1285498800 -36000 1 -11}.. {1301752800 -39600 0 -11}.. {1316872800 -36000 1 -11}.. {1325239200 50400 0 +13}.. {1333202400 46800 0 +13}.. {1348927200 50400 1 +13}.. {1365256800 46800 0 +13}.. {1380376800 50400 1 +13}.. {1396706400 46800 0 +13}.. {1411826400 50400 1 +13}.. {1428156000 46800 0 +13}.. {1443276000 50400 1 +13}.. {1459605600 46800 0 +13}.. {1474725600 50400 1 +13}.. {1491055200 46800 0 +13}.. {1506175200 50400 1 +13}.. {1522504800 46800 0 +13}.. {1538229600 50400 1 +13}.. {1554559200 46800 0 +13}.. {1569679200 50400 1 +13}.. {1586008800 46800 0 +13}.. {1601128800 50400 1 +13}.. {1617458400 46800 0 +13}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8772
                                                                                                                                                                                                                                                          Entropy (8bit):3.900078030355782
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:pj4hKuZaqaaiFKgjGeGV3atL67G9kJGsU+mpe7Vy:Cla1KgjGeGcQMsa
                                                                                                                                                                                                                                                          MD5:8174D7205622711F58E0B515246FE89D
                                                                                                                                                                                                                                                          SHA1:9777B2633ACF5588268D5072F817E65C879358AC
                                                                                                                                                                                                                                                          SHA-256:201CFADB00FBCD3283249DAD73872ED75C5BEC07F5A5B157726638C20728B833
                                                                                                                                                                                                                                                          SHA-512:64121ED1EE70D5423710319E806B19261576AECC89A64CBEC44A29BF4AC9FEE21C6484CC3C4550CC92C315B3855BE265F696F8CD4D95027226D608B3ADD022F1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Auckland) {.. {-9223372036854775808 41944 0 LMT}.. {-3192435544 41400 0 NZMT}.. {-1330335000 45000 1 NZST}.. {-1320057000 41400 0 NZMT}.. {-1300699800 43200 1 NZST}.. {-1287396000 41400 0 NZMT}.. {-1269250200 43200 1 NZST}.. {-1255946400 41400 0 NZMT}.. {-1237800600 43200 1 NZST}.. {-1224496800 41400 0 NZMT}.. {-1206351000 43200 1 NZST}.. {-1192442400 41400 0 NZMT}.. {-1174901400 43200 1 NZST}.. {-1160992800 41400 0 NZMT}.. {-1143451800 43200 1 NZST}.. {-1125914400 41400 0 NZMT}.. {-1112607000 43200 1 NZST}.. {-1094464800 41400 0 NZMT}.. {-1081157400 43200 1 NZST}.. {-1063015200 41400 0 NZMT}.. {-1049707800 43200 1 NZST}.. {-1031565600 41400 0 NZMT}.. {-1018258200 43200 1 NZST}.. {-1000116000 41400 0 NZMT}.. {-986808600 43200 1 NZST}.. {-968061600 41400 0 NZMT}.. {-955359000 43200 1 NZST}.. {-936612000 41400 0 NZMT}.. {-923304600 4320
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):280
                                                                                                                                                                                                                                                          Entropy (8bit):4.715653436088026
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/FtTfDm2OHHhp5oHvZiuo2HvDVeEU8vScH9syZEizy:MB86FtTLmdHf5CvZiIvJeJ8HH9F6izy
                                                                                                                                                                                                                                                          MD5:4E858B3754BD8864719A61839ACA64E6
                                                                                                                                                                                                                                                          SHA1:597025A8DAFD5AE75EBD162AC0E9DA71815816BA
                                                                                                                                                                                                                                                          SHA-256:2D3BFDED297214BA25CFD8C6F508D0C8B1A1CD7D46701A78EC5E510076185EB6
                                                                                                                                                                                                                                                          SHA-512:720F301B73C852EA8EEFA79DEF6B6762554E50222DE114FE87EB5178507F1895A9A39B3872A1A4B9DFF58D1CC6460BA4A82F2C165E3659E13036451F22E389C3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Bougainville) {.. {-9223372036854775808 37336 0 LMT}.. {-2840178136 35312 0 PMMT}.. {-2366790512 36000 0 +10}.. {-868010400 32400 0 +09}.. {-768906000 36000 0 +10}.. {1419696000 39600 0 +11}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8165
                                                                                                                                                                                                                                                          Entropy (8bit):3.6566720439018874
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:gpvlGCcn6AadFurBrioCdL49mq9X4a2t3I/KVE:gOCBdFurBr0soaz
                                                                                                                                                                                                                                                          MD5:8105A806A1762932897AB59C47BBE89E
                                                                                                                                                                                                                                                          SHA1:386E41A4A83FA84DBFCA994F679242D067CEED64
                                                                                                                                                                                                                                                          SHA-256:CA0EEF84DBC5964EF2265E9252237BE58BB8D75C34817CC2305CCCFAEC7E690C
                                                                                                                                                                                                                                                          SHA-512:8A609E7F4868BD455DA811E62142FECD792D0CA0DAAF7C10C4E4254C9EC44B8EB92D388D9224C8FD3CC3FB326A106D831B80F5E1264CCF3EABBCE177BB82E9D6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Chatham) {.. {-9223372036854775808 44028 0 LMT}.. {-3192437628 44100 0 +1215}.. {-757426500 45900 0 +1245}.. {152632800 49500 1 +1245}.. {162309600 45900 0 +1245}.. {183477600 49500 1 +1245}.. {194968800 45900 0 +1245}.. {215532000 49500 1 +1245}.. {226418400 45900 0 +1245}.. {246981600 49500 1 +1245}.. {257868000 45900 0 +1245}.. {278431200 49500 1 +1245}.. {289317600 45900 0 +1245}.. {309880800 49500 1 +1245}.. {320767200 45900 0 +1245}.. {341330400 49500 1 +1245}.. {352216800 45900 0 +1245}.. {372780000 49500 1 +1245}.. {384271200 45900 0 +1245}.. {404834400 49500 1 +1245}.. {415720800 45900 0 +1245}.. {436284000 49500 1 +1245}.. {447170400 45900 0 +1245}.. {467733600 49500 1 +1245}.. {478620000 45900 0 +1245}.. {499183200 49500 1 +1245}.. {510069600 45900 0 +1245}.. {530632800 49500 1 +1245}.. {541519200 45900 0 +1245}.. {56208
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):202
                                                                                                                                                                                                                                                          Entropy (8bit):4.943709180393636
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yci/452HAIgObi/4oA6N/ZE/4pv:MByMdNXiU5tVv
                                                                                                                                                                                                                                                          MD5:7D9980F68F044EB9B7FA7ED2883645F2
                                                                                                                                                                                                                                                          SHA1:9444DA9D3139F51C6DFDA174C8C52A231215D71E
                                                                                                                                                                                                                                                          SHA-256:F324CA637180F50DB79FFA25204D974C6A7A6FAEFDA69FD1A280B9F366349A09
                                                                                                                                                                                                                                                          SHA-512:850577ABD3A3653076797D46AF481343CDF8103AC597EB68F575C5FF4931242C6ACEB054D14E0F6A9A90E5D22069F78027215A4E44FC900292445FDEAFB8F92D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Port_Moresby)]} {.. LoadTimeZoneFile Pacific/Port_Moresby..}..set TZData(:Pacific/Chuuk) $TZData(:Pacific/Port_Moresby)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8203
                                                                                                                                                                                                                                                          Entropy (8bit):3.5469404823178463
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:QXn3AWkHkPp2YXaVU+POtUn4n6MSmSmiTpk9eL6Z5waKkhWILTc:QXn3AWJB2m+POtUnOSmSmS6ZaILg
                                                                                                                                                                                                                                                          MD5:002F3607DE2061A2E1A8EB8EBCB6E492
                                                                                                                                                                                                                                                          SHA1:6521B47847CFA76FE45AE5CC649109E4AD6C5262
                                                                                                                                                                                                                                                          SHA-256:D79A2A67606F25D6420F31129FAE966A54287DE96C661003CCE5F82B618014BC
                                                                                                                                                                                                                                                          SHA-512:03F3F262538FAF5A1B38832EFA62E3CC41A70BF54E73DE59BC99DCCA035AB002142F42BEDA5BFC2102CD556601E0A278908FDCC838A2211AC63C49A8483CE72B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Easter) {.. {-9223372036854775808 -26248 0 LMT}.. {-2524495352 -26248 0 EMT}.. {-1178124152 -25200 0 -07}.. {-36619200 -21600 1 -07}.. {-23922000 -25200 0 -07}.. {-3355200 -21600 1 -07}.. {7527600 -25200 0 -07}.. {24465600 -21600 1 -07}.. {37767600 -25200 0 -07}.. {55915200 -21600 1 -07}.. {69217200 -25200 0 -07}.. {87969600 -21600 1 -07}.. {100666800 -25200 0 -07}.. {118209600 -21600 1 -07}.. {132116400 -25200 0 -07}.. {150868800 -21600 1 -07}.. {163566000 -25200 0 -07}.. {182318400 -21600 1 -07}.. {195620400 -25200 0 -07}.. {213768000 -21600 1 -07}.. {227070000 -25200 0 -07}.. {245217600 -21600 1 -07}.. {258519600 -25200 0 -07}.. {277272000 -21600 1 -07}.. {289969200 -25200 0 -07}.. {308721600 -21600 1 -07}.. {321418800 -25200 0 -07}.. {340171200 -21600 1 -07}.. {353473200 -25200 0 -07}.. {371620800 -21600 1 -07}.. {384922800
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):789
                                                                                                                                                                                                                                                          Entropy (8bit):4.0457106900970325
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86HmdH6mvCON3Xj/kw2eX/xtDedjX24ots0FX2ud5KRGkpFxy:uegazZBzCdXUFQzy
                                                                                                                                                                                                                                                          MD5:6841B8A2FB9BBF464AA00088CBDCEC80
                                                                                                                                                                                                                                                          SHA1:26CC5CCE00A765F8B6493ED24F50957AA7F0089B
                                                                                                                                                                                                                                                          SHA-256:332372E5EFB46123FBB66F9F32F91B59EBD88ADB956249DB3F14CAAB01CE2655
                                                                                                                                                                                                                                                          SHA-512:A6C67A0F7361E599369597E9A8A52FC7D5C96DE6B5A7C1BE1D02F5DF11051F448289786C7F0E82E71CDEB825215E64E072CF034C45D6E2F822D7201AB8B41B57
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Efate) {.. {-9223372036854775808 40396 0 LMT}.. {-1829387596 39600 0 +11}.. {125409600 43200 1 +11}.. {133876800 39600 0 +11}.. {433256400 43200 1 +11}.. {448977600 39600 0 +11}.. {464706000 43200 1 +11}.. {480427200 39600 0 +11}.. {496760400 43200 1 +11}.. {511876800 39600 0 +11}.. {528210000 43200 1 +11}.. {543931200 39600 0 +11}.. {559659600 43200 1 +11}.. {575380800 39600 0 +11}.. {591109200 43200 1 +11}.. {606830400 39600 0 +11}.. {622558800 43200 1 +11}.. {638280000 39600 0 +11}.. {654008400 43200 1 +11}.. {669729600 39600 0 +11}.. {686062800 43200 1 +11}.. {696340800 39600 0 +11}.. {719931600 43200 1 +11}.. {727790400 39600 0 +11}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):188
                                                                                                                                                                                                                                                          Entropy (8bit):4.82787610497142
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG11avXHAIgObT11ORL/nUDH7/UDH11B:SlSWB9vsM3yckHAIgObON/h
                                                                                                                                                                                                                                                          MD5:CD1AC50AADC3CF9C0E7A055D587E790D
                                                                                                                                                                                                                                                          SHA1:BEE0E16D3954DF33C697DEA469A130BD9875AB8B
                                                                                                                                                                                                                                                          SHA-256:790E6B48B261D6DEF7D183CC8F38FB8D8A6E3EFB8844281EFABB2DFD621E53B5
                                                                                                                                                                                                                                                          SHA-512:B6A93DFB4CBE2F35268AACA88FDCC4D19949A2E8DC9464D8341C38065C6FF48A3C49FE756FFCE777C8F806DE309C8AFC4CE4BC4ABD183C28808F995A0F89B091
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Kanton)]} {.. LoadTimeZoneFile Pacific/Kanton..}..set TZData(:Pacific/Enderbury) $TZData(:Pacific/Kanton)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.913439535905759
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/nUDH4ErKYofMXGm2OH18VkeoHvmUENBBy/aCPFVFv7Dy:SlSWB9eg/BE3ofDm2OH1VeoHvmH7y/Fy
                                                                                                                                                                                                                                                          MD5:6250F332356787613A2D1853EF6D1AC3
                                                                                                                                                                                                                                                          SHA1:0464B9EE8B691990022295D2DEFE1AAE4B247E63
                                                                                                                                                                                                                                                          SHA-256:336058DCA4802C79ED43F6177ADB73085D4FA0754B94051CAE2A19346B0C4904
                                                                                                                                                                                                                                                          SHA-512:B8FAB5E128D2EF3CB7050DA717D80247045BE09F7F6542AA154CB85F4A56884F195EE2776421890A3F86D133106DCA4672D7D9329E0DE6F4A7CF8F4030822988
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Fakaofo) {.. {-9223372036854775808 -41096 0 LMT}.. {-2177411704 -39600 0 -11}.. {1325242800 46800 0 +13}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):986
                                                                                                                                                                                                                                                          Entropy (8bit):3.950865906618592
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:CKeaEa+TkUqOL1X7dMUhSXUmxY8yiUKEMH0Mkxu:9pW15Mmk59NQMk0
                                                                                                                                                                                                                                                          MD5:E329ACBF859B35950B27F434D725B3F8
                                                                                                                                                                                                                                                          SHA1:9B46C4318CA0F03E016F8FF68FEE50EA93B22360
                                                                                                                                                                                                                                                          SHA-256:0FF7AF55C92806751473CBF7A55E860850719BA7255CD65FD630B99E05C7C177
                                                                                                                                                                                                                                                          SHA-512:84A7491E2C8A6866B40A3673C084ABF3F1E344CB0290C607A0BB06FF19D43EF0B9648CDA6489D10C410D39C700D8C62A8BA11EEF07AD36F5A9AD85C596205939
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Fiji) {.. {-9223372036854775808 42944 0 LMT}.. {-1709985344 43200 0 +12}.. {909842400 46800 1 +12}.. {920124000 43200 0 +12}.. {941896800 46800 1 +12}.. {951573600 43200 0 +12}.. {1259416800 46800 1 +12}.. {1269698400 43200 0 +12}.. {1287842400 46800 1 +12}.. {1299333600 43200 0 +12}.. {1319292000 46800 1 +12}.. {1327154400 43200 0 +12}.. {1350741600 46800 1 +12}.. {1358604000 43200 0 +12}.. {1382796000 46800 1 +12}.. {1390050000 43200 0 +12}.. {1414850400 46800 1 +12}.. {1421503200 43200 0 +12}.. {1446300000 46800 1 +12}.. {1452952800 43200 0 +12}.. {1478354400 46800 1 +12}.. {1484402400 43200 0 +12}.. {1509804000 46800 1 +12}.. {1515852000 43200 0 +12}.. {1541253600 46800 1 +12}.. {1547301600 43200 0 +12}.. {1573308000 46800 1 +12}.. {1578751200 43200 0 +12}.. {1608386400 46800 1 +12}.. {1610805600 43200 0 +12}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):187
                                                                                                                                                                                                                                                          Entropy (8bit):4.770127787944403
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGqhyXHAIgObTq0vFvRL/nUDH4QwyFPUDHqNn:SlSWB9vsM3ycmhSHAIgObmSN/BCLNn
                                                                                                                                                                                                                                                          MD5:BBB00369FA8DCC23A7824EDB964BF48D
                                                                                                                                                                                                                                                          SHA1:A97E42B3CC45860CC0DFC62F468B24A628B43973
                                                                                                                                                                                                                                                          SHA-256:AFFB0A5D9CBD5949F2FC5047820FA2A2798F7C303F7BC972EC49CCF27837B00E
                                                                                                                                                                                                                                                          SHA-512:2D4C8616308522C987437C39C74E250973C2AC7AA1499C60321F42E84CE52C28D1F6AE81E6390B116C92C7B208EA0F211EB3C5A86E6E4CEE0620014DE5359F4F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Funafuti) $TZData(:Pacific/Tarawa)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):247
                                                                                                                                                                                                                                                          Entropy (8bit):4.687336389955113
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/fEGDm2OHvQYeoHTie7KVQRncRvinrN5/uFifriX:MB86fhmdH0CTV7OcdrN5/uFiGX
                                                                                                                                                                                                                                                          MD5:0557D164DCD8DF5D99F7AF5A2AB1AD4F
                                                                                                                                                                                                                                                          SHA1:68AFD04303E5F541480425405D82E1827F78A8DF
                                                                                                                                                                                                                                                          SHA-256:192545659F971084ADC8489A2B96A6439FF391599DC962AA13375ACCFB3C09D9
                                                                                                                                                                                                                                                          SHA-512:1DA004E51F8E7A712EDE920CBB62E81F9F55450FB52B62F78F1CD4F8F4E342B4DAB2C28AA5161E8B24942A7A5BD55F978AFDA1C5E1949241E71D738079DEF9B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Galapagos) {.. {-9223372036854775808 -21504 0 LMT}.. {-1230746496 -18000 0 -05}.. {504939600 -21600 0 -06}.. {722930400 -18000 1 -06}.. {728888400 -21600 0 -06}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):155
                                                                                                                                                                                                                                                          Entropy (8bit):4.976931060677737
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/nUDH5hBYfMXGm2OHKToxYoHsdNfis:SlSWB9eg/DDm2OHPxYoH4qs
                                                                                                                                                                                                                                                          MD5:45330CE0FA604304C6ACF8EF8CAF51EC
                                                                                                                                                                                                                                                          SHA1:20EEF9646996C2EC9B2641EBCCBE4766BF38B17B
                                                                                                                                                                                                                                                          SHA-256:190E02A0C00D165FA45C73AEF9C0D6C82B1720E7406E5610DD860AED10A021A5
                                                                                                                                                                                                                                                          SHA-512:51C7931B503405DA0B4078F6BE411895DD00E86AC7C5BE475030664D5302AD614293541DEE7FFC3D86A9DDB1BDA32BCAA746CF1D207DB063FBA2F9E9BE12836C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Gambier) {.. {-9223372036854775808 -32388 0 LMT}.. {-1806678012 -32400 0 -09}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):157
                                                                                                                                                                                                                                                          Entropy (8bit):4.9796189407775255
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/nUDH5RyJTLJ5FNMXGm2OHddHvpoxYoHsdMWdHPVtyn:SlSWB9eg/LJHjXDm2OHdFGxYoHgHPLy
                                                                                                                                                                                                                                                          MD5:DF09960360D8CEDCA2A4DC19A177C4A6
                                                                                                                                                                                                                                                          SHA1:9F73F271B8C85B25FE6392B8BF7465C92EFFE621
                                                                                                                                                                                                                                                          SHA-256:161762334DFF48B1D58824911E1FF4171386EA18234DD3DD5B0798515593086A
                                                                                                                                                                                                                                                          SHA-512:1BE9E0F90DA529C99E317F399BFDB913A076651CF8801A1849247B26A350A76D8B5807AB139F3DBB97790DDFC332BDBEB57B364BF67FA2BB440AFEDC4130A648
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Guadalcanal) {.. {-9223372036854775808 38388 0 LMT}.. {-1806748788 39600 0 +11}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):733
                                                                                                                                                                                                                                                          Entropy (8bit):4.244282318063802
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB862mdHanCTCtBCv1yWQkHHLTaWJ+x+87W0x+8+yWSi+JW7+sWU0dwaW1j+FaW2:FeaC2twvY3knLGs+I87p+8d9i+J7s70c
                                                                                                                                                                                                                                                          MD5:BA319E451BE323C852A8ABFC299DDA28
                                                                                                                                                                                                                                                          SHA1:FC9314C162FF1FE1ED5E2C5DF962A55D4D6D8115
                                                                                                                                                                                                                                                          SHA-256:42CB69ABC83415F63CA7D2A3E5314A41817AEE3206ECCC7172C50A74B1597DB0
                                                                                                                                                                                                                                                          SHA-512:3BF733B9ED2A57B01BE173A8421B2D5A45888A230461EA0BD8C5B4AC7DC010BB527346731196141C70AFECDF88DD47AFE48636243DFC395D88E58231BEDF7D2A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Guam) {.. {-9223372036854775808 -51660 0 LMT}.. {-3944626740 34740 0 LMT}.. {-2177487540 36000 0 GST}.. {-885549600 32400 0 +09}.. {-802256400 36000 0 GST}.. {-331891200 39600 1 GDT}.. {-281610000 36000 0 GST}.. {-73728000 39600 1 GDT}.. {-29415540 36000 0 GST}.. {-16704000 39600 1 GDT}.. {-10659600 36000 0 GST}.. {9907200 39600 1 GDT}.. {21394800 36000 0 GST}.. {41356800 39600 1 GDT}.. {52844400 36000 0 GST}.. {124819200 39600 1 GDT}.. {130863600 36000 0 GST}.. {201888000 39600 1 GDT}.. {209487660 36000 0 GST}.. {230659200 39600 1 GDT}.. {241542000 36000 0 GST}.. {977493600 36000 0 ChST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):344
                                                                                                                                                                                                                                                          Entropy (8bit):4.640604617840767
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/PeDDm2OHsVVoHvBrai3UNFv+rUXaWFvAHovj/0nvCv7p+v:MB86WXmdH0VCvBz0GOTA0/0y74v
                                                                                                                                                                                                                                                          MD5:F3F0E64655FAA79E40860765EEBB5B77
                                                                                                                                                                                                                                                          SHA1:7F6C2FC100AEABC26B7205AB53C1E016B12E4D60
                                                                                                                                                                                                                                                          SHA-256:69319015799D32D3CF7C0A3E9991B4B1F3E0C5D1B4FBF400517350CCA9D2C3B7
                                                                                                                                                                                                                                                          SHA-512:7C9238BCCB13B90D4DC9B5E776C421A42C25D21B4E026406F57FA1E70983E8F6BF1CE927AB9D0D6261C5C1802A8B810399F506915262F82F487417CFD704B2F1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Honolulu) {.. {-9223372036854775808 -37886 0 LMT}.. {-2334101314 -37800 0 HST}.. {-1157283000 -34200 1 HDT}.. {-1155436200 -34200 0 HST}.. {-880201800 -34200 1 HWT}.. {-769395600 -34200 1 HPT}.. {-765376200 -37800 0 HST}.. {-712150200 -36000 0 HST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):193
                                                                                                                                                                                                                                                          Entropy (8bit):4.844454917943834
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yc6e8SHAIgOb6eKAN/NWyVheo:MByMdniinbtNWzo
                                                                                                                                                                                                                                                          MD5:4244078A03C2493009EF2F6BDA2F326F
                                                                                                                                                                                                                                                          SHA1:AC2FF3E91A8831A479B33DF32A0118BC2EB255D0
                                                                                                                                                                                                                                                          SHA-256:6E52B361AC8A6A578C709F6D58AA7535F06C0CB1707081C2D5A63FA8545D955C
                                                                                                                                                                                                                                                          SHA-512:398B32E0FAF80E40DF3ACD203DF380D61DC39322F0BA0388A18281BC26973945F45683A104B9A785BB9DF5E514322F6994F934289E4B56B7982F94D4528D4272
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Honolulu)]} {.. LoadTimeZoneFile Pacific/Honolulu..}..set TZData(:Pacific/Johnston) $TZData(:Pacific/Honolulu)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):208
                                                                                                                                                                                                                                                          Entropy (8bit):4.669308556946547
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/KyXDm2OHEMmzQwXy29BVyv7y/fTVVFty:MB86KyTmdHEZzQUBVyDy/fZvty
                                                                                                                                                                                                                                                          MD5:544A0A83241333805192A6F03888E359
                                                                                                                                                                                                                                                          SHA1:99D2BE79D57B44BD538386F9E7551C9E1874D7E3
                                                                                                                                                                                                                                                          SHA-256:0B1345555EC2B4738CC4DEBFE496C287966F238386263032FF1E27912CCBFBA6
                                                                                                                                                                                                                                                          SHA-512:61C91265632D01FBB7F4C739368756C428258FA6C141E49E88B6C78ABEA6150A74B8DFCF14C5AADDA03C1EA6F04D122734654495C26B8614561786B1C5C7EF10
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kanton) {.. {-9223372036854775808 0 0 -00}.. {-1020470400 -43200 0 -12}.. {307627200 -39600 0 -11}.. {788871600 46800 0 +13}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):219
                                                                                                                                                                                                                                                          Entropy (8bit):4.739672105601744
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/iSDm2OHjkeoHvmLVFFz4YWXfSzvjNv:MB86iGmdHpCvU4VfSbxv
                                                                                                                                                                                                                                                          MD5:1B695BBB9C50F6AFC05F67DE30374160
                                                                                                                                                                                                                                                          SHA1:08AD8BBB6C99EB36FC3E462DB41C6896F52F150C
                                                                                                                                                                                                                                                          SHA-256:4F7235B956A5A01676BE05275E086D5157EBC24FD91022E87817020669F915F7
                                                                                                                                                                                                                                                          SHA-512:DC35CB1C2E5E035A82F91D1B1F4B48D7B112D9B7A1A7DB9C4A4C42C4D58002E1ECD9D24B2EA5B624DBB526ADDF9A8AB37D4315843207C34C16B2EFE33A254752
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kiritimati) {.. {-9223372036854775808 -37760 0 LMT}.. {-2177415040 -38400 0 -1040}.. {307622400 -36000 0 -10}.. {788868000 50400 0 +14}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):394
                                                                                                                                                                                                                                                          Entropy (8bit):4.441317927120857
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB869nmdHlCTvrvCvKcHwzHHI/HKOjHHwZaLYkcy:2ecrrqvGznISknwZaLxcy
                                                                                                                                                                                                                                                          MD5:B489D7BDE8EB805B2A24726A6FB0C441
                                                                                                                                                                                                                                                          SHA1:7997A33AA56857EC52B1198DBEF4CE1DB50D69FD
                                                                                                                                                                                                                                                          SHA-256:B528E5E712E5F878603183E7CCFF55E5DB97CB47D7628BCB635342796317B899
                                                                                                                                                                                                                                                          SHA-512:4898AC2747FB8620BE29933CC7AA344AF1A3B7777D1AFF08BB4C6CE6E7AF205581937CCB488F3CB39CC8CA7FB42EDC8E1CAD8BADC9FCA40E3CAD23271CD66FCB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kosrae) {.. {-9223372036854775808 -47284 0 LMT}.. {-3944631116 39116 0 LMT}.. {-2177491916 39600 0 +11}.. {-1743678000 32400 0 +09}.. {-1606813200 39600 0 +11}.. {-1041418800 36000 0 +10}.. {-907408800 32400 0 +09}.. {-770634000 39600 0 +11}.. {-7988400 43200 0 +12}.. {915105600 39600 0 +11}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):304
                                                                                                                                                                                                                                                          Entropy (8bit):4.5947337310364835
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/yEyDm2OH4T2eoHvmfKnOjvScHrkL/Xy2185k0YAov:MB86XmmdHWCv6KOjHHgLN8tby
                                                                                                                                                                                                                                                          MD5:7D1FC9913941693ACBD6A3CCB2F34555
                                                                                                                                                                                                                                                          SHA1:D07C8AAED1DF9614BCA6EEF0F72FB98BE46CF5EF
                                                                                                                                                                                                                                                          SHA-256:38133BE70100D7DC244A680827879E6B240646C7C0B68F58652051E681A71985
                                                                                                                                                                                                                                                          SHA-512:419F0A1D1D71C8F84765C7B54271D7EFD6A81F428751523A214ABB24A8770DD5A7666F634A20AF97D5AAB8F21C0DEF23DCDE068CF4C1CCC7639ABC43864A9DBC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kwajalein) {.. {-9223372036854775808 40160 0 LMT}.. {-2177492960 39600 0 +11}.. {-1041418800 36000 0 +10}.. {-907408800 32400 0 +09}.. {-817462800 39600 0 +11}.. {-7988400 -43200 0 -12}.. {745934400 43200 0 +12}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.7986219497241995
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGqhyXHAIgObTq0vFvRL/nUDHznHlUDHqNn:SlSWB9vsM3ycmhSHAIgObmSN/QxNn
                                                                                                                                                                                                                                                          MD5:EB409C340A475B60993965A0E2892B6E
                                                                                                                                                                                                                                                          SHA1:819881A078F34EF8FC55D71D829B82C56E6723D7
                                                                                                                                                                                                                                                          SHA-256:935BC00C13863715D09463E54DC2A6FF0F1A7EEA8D5895C87836AA59716CBD57
                                                                                                                                                                                                                                                          SHA-512:A28AF85022F8B3C2EE5F93BF6FDC0C349B73F25D88BA151ACE424EED1A95FA29608A6B1AD3D5FD952B2FB7F48DF6FDF8E6504F2B53E6782E4FF73335AF9A15C0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Majuro) $TZData(:Pacific/Tarawa)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):159
                                                                                                                                                                                                                                                          Entropy (8bit):4.976348164850869
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/nUDHzrHeWNMXGm2OHOx5oHsdNpNFvvIVVFvYy:SlSWB9eg/cHeSDm2OHOnoH4/FvQVVFAy
                                                                                                                                                                                                                                                          MD5:80CB45F42BAB1AA72CD7C7BC394DF3F8
                                                                                                                                                                                                                                                          SHA1:8B5ED2BCCA1AEB41F22AFD14F46533959828B2BE
                                                                                                                                                                                                                                                          SHA-256:AE0B5055C6E57516F23749B13681205EAD376E682959716A457B1377AF8160BA
                                                                                                                                                                                                                                                          SHA-512:71562E340B7A96B91D04FCBCAF71B66EA725CA1BD1094343C4442F8F9A8C67A3BE378034849197407D21C3EE74E2C753B1FD3BAFF2378714B993AD9336236A0E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Marquesas) {.. {-9223372036854775808 -33480 0 LMT}.. {-1806676920 -34200 0 -0930}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):194
                                                                                                                                                                                                                                                          Entropy (8bit):4.81307101485774
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGurKeTnXHAIgObTurKefVHRL/nUDHz0HvUDHurKv:SlSWB9vsM3yciemHAIgObiecN/Zevn
                                                                                                                                                                                                                                                          MD5:13CE48F8FF74BFCEFCB8D217D6357E38
                                                                                                                                                                                                                                                          SHA1:296D31E3F868934C6EB34BF1BF4C23F3E1839294
                                                                                                                                                                                                                                                          SHA-256:F62C6A2DEC1E9EC78115D5F14E5B9DB7C86F788662D2E68F7E6714F4A05DC974
                                                                                                                                                                                                                                                          SHA-512:778813FC08EF803743F392000BECE73C1C079883DAFC26FAC0AF8FA3FA4AE1D94BA8F3CAA5E82DD4DB1A5F12AD49E123901908F5483E0E325952622AB4C4A26A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pago_Pago)]} {.. LoadTimeZoneFile Pacific/Pago_Pago..}..set TZData(:Pacific/Midway) $TZData(:Pacific/Pago_Pago)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):244
                                                                                                                                                                                                                                                          Entropy (8bit):4.702705620563736
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/JdDm2OHceoHx6sCH/ZdqvScH9cd0YAov:MB86J5mdH9CMhcHHauby
                                                                                                                                                                                                                                                          MD5:30A8285FCCE2E98889E53DF60B906C3D
                                                                                                                                                                                                                                                          SHA1:C7789CB11A2C8FE3861FF3C0A7A41F6CAFD87631
                                                                                                                                                                                                                                                          SHA-256:22C367F3219B5FC736260D9DBFEF5FCB767F1A6BDA991C9352F790A3D1FFE884
                                                                                                                                                                                                                                                          SHA-512:02DA82680588839B06F820979AECC78B7FBEAB9D6D49176B513B80F1C8BA2D55FB3674B19EFDD574EE6FC01539EF7C3081A4B34D14A54DACF367D816B62E5843
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Nauru) {.. {-9223372036854775808 40060 0 LMT}.. {-1545131260 41400 0 +1130}.. {-862918200 32400 0 +09}.. {-767350800 41400 0 +1130}.. {287418600 43200 0 +12}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.846897598147338
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/nUDHwMQA3WNMXGm2OH0SNoHoRWVGXyOyovFaSUGFAZvBByV:SlSWB9eg/Jm3SDm2OHJoHFGXCodZUGFd
                                                                                                                                                                                                                                                          MD5:6E8EC957423917AE7A7EF503661C1A77
                                                                                                                                                                                                                                                          SHA1:B4FA3C3E3F96C28B7DB87BFD441D2EE99CC81B6F
                                                                                                                                                                                                                                                          SHA-256:869CCA656BE88E4E7481C75737C3656BAB6924AD1751505815AC719C59269842
                                                                                                                                                                                                                                                          SHA-512:9047ABE673259699C7A548BC7B5636DD646DD382C751B796522F65404162AB1B0BB022FD274653921E5B23C847EE248AEF6749E15ED2CFC1DCE35BBA294D8251
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Niue) {.. {-9223372036854775808 -40780 0 LMT}.. {-543069620 -40800 0 -1120}.. {-173623200 -39600 0 -11}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5139
                                                                                                                                                                                                                                                          Entropy (8bit):3.65794255179185
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:K/yg8hZbeS07HbbYTqge+gDrWnAxhejtB0e+Pwn1UVimqNQrKvyXrStkCDv:K/y7hNeS07sq0Erk10lINQrKvyXrwv
                                                                                                                                                                                                                                                          MD5:E19700A894AA64715D14F501D8D2FA98
                                                                                                                                                                                                                                                          SHA1:57CFC96E2EBB985720DB290F59181860AF2AC1AA
                                                                                                                                                                                                                                                          SHA-256:5D16C3EF1DB996C1B8E33AD884C33946F77DA872F35F41EC3BD5B288F43CC9AF
                                                                                                                                                                                                                                                          SHA-512:E11EAF2A7B217CDBEECB57635184F04171F0DB088FCC4702AA8D40A3A5453904592F5869849913E2EB02DC5941C84203A76D270E8930B0B691A3B9C39B78BF30
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Norfolk) {.. {-9223372036854775808 40312 0 LMT}.. {-2177493112 40320 0 +1112}.. {-599656320 41400 0 +1130}.. {152029800 45000 1 +1230}.. {162916200 41400 0 +1130}.. {1443882600 39600 0 +11}.. {1561899600 39600 0 +12}.. {1570287600 43200 1 +12}.. {1586012400 39600 0 +12}.. {1601737200 43200 1 +12}.. {1617462000 39600 0 +12}.. {1633186800 43200 1 +12}.. {1648911600 39600 0 +12}.. {1664636400 43200 1 +12}.. {1680361200 39600 0 +12}.. {1696086000 43200 1 +12}.. {1712415600 39600 0 +12}.. {1728140400 43200 1 +12}.. {1743865200 39600 0 +12}.. {1759590000 43200 1 +12}.. {1775314800 39600 0 +12}.. {1791039600 43200 1 +12}.. {1806764400 39600 0 +12}.. {1822489200 43200 1 +12}.. {1838214000 39600 0 +12}.. {1853938800 43200 1 +12}.. {1869663600 39600 0 +12}.. {1885993200 43200 1 +12}.. {1901718000 39600 0 +12}.. {1917442800 43200 1 +12}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):326
                                                                                                                                                                                                                                                          Entropy (8bit):4.531117764974758
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9eg/JcSDm2OHTYoHgnX2czO/FxgV62JFy:MB86JcGmdHTYCgX2czUjgM2ny
                                                                                                                                                                                                                                                          MD5:2F1E92A11DF44C72DC305C13111DEA35
                                                                                                                                                                                                                                                          SHA1:847F551C3D6C75CD2D0D6D87FCF3294CA8DD90B2
                                                                                                                                                                                                                                                          SHA-256:238683C027D2319C33D975A837E9FC9D24DD53B1A67108EDBF7ABDF0DB050881
                                                                                                                                                                                                                                                          SHA-512:E35D8C71AFDBB9A7507E873925001AEDE3734B1D235F509D19952E85279CBCC233A73412EA1F79CB534A45D36FEAA8AFDA98D9964DC93C7892B318F4AFC9A076
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Noumea) {.. {-9223372036854775808 39948 0 LMT}.. {-1829387148 39600 0 +11}.. {250002000 43200 1 +11}.. {257342400 39600 0 +11}.. {281451600 43200 1 +11}.. {288878400 39600 0 +11}.. {849366000 43200 1 +11}.. {857228400 39600 0 +11}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):188
                                                                                                                                                                                                                                                          Entropy (8bit):4.985607855830399
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/nUDHurKeTFfXMXGm2OH2ivkeoHvUPi1TsYoHsdfWTVvvVFv:SlSWB9eg/XecDm2OH23eoHvWieYoHiWB
                                                                                                                                                                                                                                                          MD5:E86D90DAA694B0EAC42F8C01346BC95B
                                                                                                                                                                                                                                                          SHA1:CD29DEFC291C939296E86DC7EF5D0654D85285E8
                                                                                                                                                                                                                                                          SHA-256:CCA96640AB3BC707224FA86D9AF66F9D53A204A97B370B2785BA8208688BF8B6
                                                                                                                                                                                                                                                          SHA-512:937BA420061E3781F831779B458E914A0FC465C4B41796F8B7CB1E548822F5777A6450FC6002AB13EBC5C9F54E374D3ED731D05B2B302B95359BE34094E5062B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Pago_Pago) {.. {-9223372036854775808 45432 0 LMT}.. {-2445424632 -40968 0 LMT}.. {-1861879032 -39600 0 SST}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):183
                                                                                                                                                                                                                                                          Entropy (8bit):4.919381181565273
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/nUDHugEZF3fMXGm2OHKvkeoHucRbgnJnoHvmdQ4+vScFAy:SlSWB9eg/Xg2PDm2OHK8eoHTWJnoHvmi
                                                                                                                                                                                                                                                          MD5:2E6C7EC61C7E29A147475C223B163F6B
                                                                                                                                                                                                                                                          SHA1:3A98D3441335224E7EBC0648990BCA1DE3BDF5C6
                                                                                                                                                                                                                                                          SHA-256:97DE6C2C717BFEAD00F83B5D39D654C32CEE580226F5F084484EBAD57BBCE7FF
                                                                                                                                                                                                                                                          SHA-512:5868C43966DDEBA8EC4BBBB29CDFDDFF0C7B01FD4D579FF655F3363029059F969B39C9221190672B6A2F7938583594AA0B103FC2A7ED573E2BC1C3A1623DE8DD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Palau) {.. {-9223372036854775808 -54124 0 LMT}.. {-3944624276 32276 0 LMT}.. {-2177485076 32400 0 +09}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):188
                                                                                                                                                                                                                                                          Entropy (8bit):4.809907977056877
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/nUDHuQTWLMbNMXGm2OHUVFvoHvmXUlgloWkcyf/vGpn:SlSWB9eg/XQyLMJDm2OHUVVoHvmXUKm2
                                                                                                                                                                                                                                                          MD5:3F4987676F9C461895EDF9985AD22E06
                                                                                                                                                                                                                                                          SHA1:A96E470209010B837EF5BB3AC93BAE74BF2CCF64
                                                                                                                                                                                                                                                          SHA-256:5D363729A986E24C79F4B817CC88D2B22ACCCE3ADD20138D51C4422C4297AD6F
                                                                                                                                                                                                                                                          SHA-512:988FB98EFD3F57F5D66A932CC6B9D0387E9B0951FC590E08DAF19ACF5E4F39BC1B25265F16E14930BCF394902F5F0EF507E0E91C98902DFB10FA16D716091AB0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Pitcairn) {.. {-9223372036854775808 -31220 0 LMT}.. {-2177421580 -30600 0 -0830}.. {893665800 -28800 0 -08}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):201
                                                                                                                                                                                                                                                          Entropy (8bit):4.7682565894416005
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3ycaJHNPHAIgObaJHa6N/XyopJHYn:MByMdaJyiaJrtCopJ4n
                                                                                                                                                                                                                                                          MD5:1B418E3A4239AAFE1E15B57FFF913FA1
                                                                                                                                                                                                                                                          SHA1:0E278FCC058DE1B3F4715771819F14568A6C10BB
                                                                                                                                                                                                                                                          SHA-256:F744CD8337C5C72023D61F348DD03F48824F817D62F54ACC6A23DDD8B0F9EDC4
                                                                                                                                                                                                                                                          SHA-512:8E3E10B41CF64A07411B272C0BCA6DC7AA9FFBF625B31075651603B7D0A52A719F7174A67593BFDE45725C243D347D01560B2BC7813C2ABD2F4BF4B1BAD57E56
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Guadalcanal)]} {.. LoadTimeZoneFile Pacific/Guadalcanal..}..set TZData(:Pacific/Pohnpei) $TZData(:Pacific/Guadalcanal)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):200
                                                                                                                                                                                                                                                          Entropy (8bit):4.742862539020017
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3ycaJHNPHAIgObaJHa6N/X3HpBJHYn:MByMdaJyiaJrtHpBJ4n
                                                                                                                                                                                                                                                          MD5:514C399D990C87271812440A4B19FB21
                                                                                                                                                                                                                                                          SHA1:E1512482D10C8984DCD69C883F07C412E144081A
                                                                                                                                                                                                                                                          SHA-256:5BB11553F711BD591617F657A9D1811CC3E3FB46374F6867316A7C8F6B3765D9
                                                                                                                                                                                                                                                          SHA-512:DB227134822EA73407B6C0259FF7413D4961B558F3018BFF51E4E426DDB2DF581DCF7A6DE9E4890CE35F785BC3D07CC880DA883C93D73FFB249F403701BD8023
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Guadalcanal)]} {.. LoadTimeZoneFile Pacific/Guadalcanal..}..set TZData(:Pacific/Ponape) $TZData(:Pacific/Guadalcanal)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.945354510868153
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/nUDHuwKXI3SMXGm2OHwdvoHvZUeQTnoo3v/vnqMVVMUMy:SlSWB9eg/X/43SDm2OHwdvoHvZZQTnoQ
                                                                                                                                                                                                                                                          MD5:2CFB7C2A3D26D7AF0F6AE32ADD81C364
                                                                                                                                                                                                                                                          SHA1:80C96E50D23A9A9531E4EE33744CF445C054B901
                                                                                                                                                                                                                                                          SHA-256:124C137B091D9D54D5E0579131485428FAAE040ACC978D20D6A8C8E4DE9889AA
                                                                                                                                                                                                                                                          SHA-512:A215FF5A69BD3E786BD3F8C952C8593396402EFA85005F5342093028617A6862EAE8BFD7B6D5737F90D90897AB62CF785544A4157A222AE4D0F70797FFBEC2CB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Port_Moresby) {.. {-9223372036854775808 35320 0 LMT}.. {-2840176120 35312 0 PMMT}.. {-2366790512 36000 0 +10}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):969
                                                                                                                                                                                                                                                          Entropy (8bit):3.943959457262612
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86VrjmdHI5Cvn9HCFkN00hjNFq++UE+q0hwA+A7VxVnDEFn:IeZv8w0MNFq+xE+uAtx1c
                                                                                                                                                                                                                                                          MD5:64AD3A103F4D145C48484BF8FACF41C2
                                                                                                                                                                                                                                                          SHA1:40C00CFA56C87E506C254A93A164D7227DFF3BD5
                                                                                                                                                                                                                                                          SHA-256:5AB006A686E564E30C94884FF8A9D728AEC74681DA8772E9722B6FE203630B5D
                                                                                                                                                                                                                                                          SHA-512:D1088C3B673B5456A8706B69BE4D7AB18615EE53A82BF4ABE76E86700837E6BAD0BD79C13EDA9B04776B08A95B835BA755AA565F86E45BFE507E8783896C1EE2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Rarotonga) {.. {-9223372036854775808 48056 0 LMT}.. {-2209555256 -38344 0 LMT}.. {-543072056 -37800 0 -1030}.. {279714600 -34200 0 -10}.. {289387800 -36000 0 -10}.. {309952800 -34200 1 -10}.. {320837400 -36000 0 -10}.. {341402400 -34200 1 -10}.. {352287000 -36000 0 -10}.. {372852000 -34200 1 -10}.. {384341400 -36000 0 -10}.. {404906400 -34200 1 -10}.. {415791000 -36000 0 -10}.. {436356000 -34200 1 -10}.. {447240600 -36000 0 -10}.. {467805600 -34200 1 -10}.. {478690200 -36000 0 -10}.. {499255200 -34200 1 -10}.. {510139800 -36000 0 -10}.. {530704800 -34200 1 -10}.. {541589400 -36000 0 -10}.. {562154400 -34200 1 -10}.. {573643800 -36000 0 -10}.. {594208800 -34200 1 -10}.. {605093400 -36000 0 -10}.. {625658400 -34200 1 -10}.. {636543000 -36000 0 -10}.. {657108000 -34200 1 -10}.. {667992600 -36000 0 -10}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):179
                                                                                                                                                                                                                                                          Entropy (8bit):4.854594370903023
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG5RFeyXHAIgObT5RV5RL/nUDHtluKpUDH5Rgn:SlSWB9vsM3ycdeSHAIgOb7N/vKbn
                                                                                                                                                                                                                                                          MD5:EFC985F07B24BEDA22993C9D0EA7E022
                                                                                                                                                                                                                                                          SHA1:6D05D12925621F1D05999A5DCC81B8C6F4D18945
                                                                                                                                                                                                                                                          SHA-256:4F6A1C20A11E186012466091CD4B3C09D89D35E7560F93874DEC2D7F99365589
                                                                                                                                                                                                                                                          SHA-512:5FB4D8784D2EB8AEF660D6CBC7C403561EE5874BEC0439762F3688C64830B52B1F557B467CA65B64B1210E82F385E134BF676F3CA443FB480702A2C90B3C3757
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Guam)]} {.. LoadTimeZoneFile Pacific/Guam..}..set TZData(:Pacific/Saipan) $TZData(:Pacific/Guam)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):193
                                                                                                                                                                                                                                                          Entropy (8bit):4.78073436515702
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGurKeTnXHAIgObTurKefVHRL/nUDHthA5nUDHurK:SlSWB9vsM3yciemHAIgObiecN/NXevn
                                                                                                                                                                                                                                                          MD5:8E335F5D0A2082BB673E7FEB56167A89
                                                                                                                                                                                                                                                          SHA1:EF37235922D4477AC9B3D9576888CDE41E700741
                                                                                                                                                                                                                                                          SHA-256:98D06302EFC18FAD7751F7E5A059FE4ABAFBC361FDC365FE1EB576209D92C658
                                                                                                                                                                                                                                                          SHA-512:2572D99EE8BAF264B8A2EF3D7647D33A387EE83E036F9E7BDB21F64C2FCB43317AF9C899C8CDD822A2A5A207EF17504E71B217370473ED95AE925BBA2CFA90F9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pago_Pago)]} {.. LoadTimeZoneFile Pacific/Pago_Pago..}..set TZData(:Pacific/Samoa) $TZData(:Pacific/Pago_Pago)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):154
                                                                                                                                                                                                                                                          Entropy (8bit):4.946903999617555
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/nUDHqhFPMXGm2OHl/oeoHsdNqRU7vV:SlSWB9eg/TTPDm2OHloeoH4qRW9
                                                                                                                                                                                                                                                          MD5:341B0F535043051A91A21297BFA39DC0
                                                                                                                                                                                                                                                          SHA1:6AD9177FC237503E6D36DE5408790A68D5D36E2C
                                                                                                                                                                                                                                                          SHA-256:440A87DDB4F304DCBEAED1B0DE8F6058840E597918B688E0782F584DA03B1BBC
                                                                                                                                                                                                                                                          SHA-512:D97D399A0F1B4347F8AE5F15E43A8787697339AB0EFB4E1106C790528FFC529ADC5B44B231D95449D39DB464D84A5DDF7B61E7D190E3E2B0091D1EC204B530A2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Tahiti) {.. {-9223372036854775808 -35896 0 LMT}.. {-1806674504 -36000 0 -10}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):152
                                                                                                                                                                                                                                                          Entropy (8bit):4.969953728206455
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QF08x/nUDHqQ3fMXGm2OHyyFpoeoHvmciRrWFN0UIoAov:SlSWB9eg/T+Dm2OHyyFGeoHvmbu0YAov
                                                                                                                                                                                                                                                          MD5:AA67FBBB6A02F5B30486C54E3A5C11D7
                                                                                                                                                                                                                                                          SHA1:C64FD3654A47A0ECDD681B8A4D9B621AC6D97DBE
                                                                                                                                                                                                                                                          SHA-256:91AA5DA8D5D1E72B1F561D0AEAB4B07E02EDD4EB95AE8C9F1C503C820460599F
                                                                                                                                                                                                                                                          SHA-512:FC170904098011C091622A263CA554CEE952D64888D3573EB324E0A262E1A0C0885C059429F0FFF9219FEB8F1B6B97EC34661DD8DD547124D0C6C0A1C8EE24B7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Tarawa) {.. {-9223372036854775808 41524 0 LMT}.. {-2177494324 43200 0 +12}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):451
                                                                                                                                                                                                                                                          Entropy (8bit):4.343299747430587
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:MB86PmdHmCdC/V7XZXw8Ut2rbUtGiAUtb4bUtqVy:iemn/VbKeOSy
                                                                                                                                                                                                                                                          MD5:87CFDA2399A8126117E5BFC018B06518
                                                                                                                                                                                                                                                          SHA1:6291611BCFB34293F9C20BA77170A13C1502C2ED
                                                                                                                                                                                                                                                          SHA-256:ECC9D2E7AD7B5E5D6599CF442941595C99C4D69E802A4DDB4DA321898CDDE91D
                                                                                                                                                                                                                                                          SHA-512:846FE07FEB82EC5F87FAE137D23074934246DBB7C7EE30F44F6C5373183B5FD2211B58E5CF1AB9A47938D282CA322FBDE80B58054FE6517CDC549992439F19A8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Tongatapu) {.. {-9223372036854775808 44352 0 LMT}.. {-767189952 44400 0 +1220}.. {-284041200 46800 0 +13}.. {915102000 46800 0 +13}.. {939214800 50400 1 +13}.. {953384400 46800 0 +13}.. {973342800 50400 1 +13}.. {980596800 46800 0 +13}.. {1004792400 50400 1 +13}.. {1012046400 46800 0 +13}.. {1478350800 50400 1 +13}.. {1484398800 46800 0 +13}..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):201
                                                                                                                                                                                                                                                          Entropy (8bit):4.903352083734246
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yci/452HAIgObi/4oA6N/TAOA/4pv:MByMdNXiU5trv
                                                                                                                                                                                                                                                          MD5:443F5FFA58C5DB1F02695C5B76DF4F5E
                                                                                                                                                                                                                                                          SHA1:115AFE9C3EB36F836E2DF95AF42C43EA5C21C1E6
                                                                                                                                                                                                                                                          SHA-256:323A858946A2E8EC67C28176977D646C0A0F6DC8B48F9C4A3F8E7112C9B1B71D
                                                                                                                                                                                                                                                          SHA-512:33717F3423CE06D827445FEA85BE8A989712CF8C06C54A17B9610A4DAD50BF64CAE80DE15AB12AB0610CD6B5582A897DD9C543098108543FA3E6273AAD9467DE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Port_Moresby)]} {.. LoadTimeZoneFile Pacific/Port_Moresby..}..set TZData(:Pacific/Truk) $TZData(:Pacific/Port_Moresby)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):183
                                                                                                                                                                                                                                                          Entropy (8bit):4.771810884789573
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGqhyXHAIgObTq0vFvRL/nUDHpbhpUDHqNn:SlSWB9vsM3ycmhSHAIgObmSN/0h9Nn
                                                                                                                                                                                                                                                          MD5:992D44D728747D79E1F7EF47E3CB2EF2
                                                                                                                                                                                                                                                          SHA1:8F05E8DA2A2A45F04B9B89BB34F0B7833B56A261
                                                                                                                                                                                                                                                          SHA-256:B6041BC18B595E38953632ACAD1D25F7394BF7C759A72FCCD81AF637F8016373
                                                                                                                                                                                                                                                          SHA-512:C59D360941240C8B11D892A930B6CFE141B1A55007483683AF400B1A0C98EF0BBBE7EF595EF6BA73A6EECB8E3D0658A681CF3203E5E32DE80DD61EDB9C6CBDB0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Wake) $TZData(:Pacific/Tarawa)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.752883303864462
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGqhyXHAIgObTq0vFvRL/nUDHpEsppUDHqNn:SlSWB9vsM3ycmhSHAIgObmSN/t+9Nn
                                                                                                                                                                                                                                                          MD5:862ADA129322E53235ED5099A72FE8EE
                                                                                                                                                                                                                                                          SHA1:7DAB7BF451CF0FE483EA512C0C733B090FF22EFF
                                                                                                                                                                                                                                                          SHA-256:9601B749413D591D820AFAD431B3C30E577ACAB000EA11EC03DEB36EF0738DC3
                                                                                                                                                                                                                                                          SHA-512:D9C94BE2F08220E49A336A5760DBF43FCB889ADA95E29117AE5E237E33E9EE50BD32203D2743346A21354AF3F1ADDA43A2953FB55205B6FA998A6294CC57F063
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Wallis) $TZData(:Pacific/Tarawa)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):200
                                                                                                                                                                                                                                                          Entropy (8bit):4.896778032757086
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3yci/452HAIgObi/4oA6N/eP/4pv:MByMdNXiU5teev
                                                                                                                                                                                                                                                          MD5:343CCAC12AEB0DD78FC60405DF938729
                                                                                                                                                                                                                                                          SHA1:B7B4DF0178DEEC2BA6F23AF5CD896CF16CEAF224
                                                                                                                                                                                                                                                          SHA-256:16CF9FAB116E5E1732B4B601DA919798985A0C15803F0964844C7040894C5DBA
                                                                                                                                                                                                                                                          SHA-512:041609C63E95322460A31AC83BCC4F8F90B8D44B2740A5CF7E37F66CCD9F928416D74D313370516D7B1780DF2C9C9A78B7069CE2DA6BFFE88C46FB47CE1A4CB2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Port_Moresby)]} {.. LoadTimeZoneFile Pacific/Port_Moresby..}..set TZData(:Pacific/Yap) $TZData(:Pacific/Port_Moresby)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):174
                                                                                                                                                                                                                                                          Entropy (8bit):4.940195299412468
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVqEGIV5XHAIgoqpEGYvWARL/nSi67x/yQa0EGIy:SlSWB9vsM3ymc4HAIgocVAN/27x6qF
                                                                                                                                                                                                                                                          MD5:E6AA2F6A05B57AA9B4AEF8E98552EEB2
                                                                                                                                                                                                                                                          SHA1:22470C204152702D8826CA52299E942F572C85ED
                                                                                                                                                                                                                                                          SHA-256:C27E1179B55BF0C7DB6F1C334C0C20C4AFA4DBB84DB6F46244B118F7EAB9C76E
                                                                                                                                                                                                                                                          SHA-512:B28A264907C32F848D356FB0F5776C2CE819DCB6BC08A5E2DCD4FA455EE1616966E816748079C7A55485BABFFB292D567E6F958168F945889E33A267B0E7EDA9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Warsaw)]} {.. LoadTimeZoneFile Europe/Warsaw..}..set TZData(:Poland) $TZData(:Europe/Warsaw)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):176
                                                                                                                                                                                                                                                          Entropy (8bit):4.9353841548970205
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxMvLS3vXHAIgoqyMvLL6RL/nM24h8QavMvLBn:SlSWB9vsM3ymvMv2PHAIgovMvH6N/e8i
                                                                                                                                                                                                                                                          MD5:7D7BD6E40D3ADCA04754255D69B5CC9D
                                                                                                                                                                                                                                                          SHA1:EE32167B450DE7B0F1A15199795AEF9524BE623B
                                                                                                                                                                                                                                                          SHA-256:EFD666F3062D52C5D0B4F83B1A206E6840C1EAEC356CD77A0A71C7EDFA78C964
                                                                                                                                                                                                                                                          SHA-512:6056AAF078316A89079D19555F0BAEFB4C1CDBAA5426A8BEE76E0BFA5C69A5DAAFD199DEF978ABD67287AE1B80F754B7845EAFD5CC0995FE10E44D1F34D5435C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Lisbon)]} {.. LoadTimeZoneFile Europe/Lisbon..}..set TZData(:Portugal) $TZData(:Europe/Lisbon)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):165
                                                                                                                                                                                                                                                          Entropy (8bit):4.795776391333205
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8qMveyXHAIgNqBLFARL/lOr4WFKfMy:SlSWB9vsM3yKMveSHAIgcBJAN/S4wKfB
                                                                                                                                                                                                                                                          MD5:C5AE3A1DAD32C870651C74E367F604CF
                                                                                                                                                                                                                                                          SHA1:9FF81383C43D98441841E182BC783381EF565204
                                                                                                                                                                                                                                                          SHA-256:9AEC39777013B23D63D0509EBB2F01D57A2C1592264DBB19CE2C61C7D7DDD8DE
                                                                                                                                                                                                                                                          SHA-512:3A7217ED885011972262B71DB7F5D7E4C9C6E82B4BEEF0718BCB9452E49FDBDD5ED78564156577AB09150140B862E1944B4B739BCE0C50E63667050C35329503
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Taipei)]} {.. LoadTimeZoneFile Asia/Taipei..}..set TZData(:ROC) $TZData(:Asia/Taipei)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):162
                                                                                                                                                                                                                                                          Entropy (8bit):4.900717350092823
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8ZQckovXHAIgNtvQMHRL/lmFeWFKKQ7:SlSWB9vsM3yJJHAIgbHN/pwKv
                                                                                                                                                                                                                                                          MD5:59E4C80F97FAFC92987B08BFA03B5EE5
                                                                                                                                                                                                                                                          SHA1:4F86FCE17A51C3789DEB887BE01A1A0E6EA3D2DE
                                                                                                                                                                                                                                                          SHA-256:63153B40225270ADB7CD248788CA9F18C6DEBAF222B3165BBAB633337592DF44
                                                                                                                                                                                                                                                          SHA-512:9FCC0F747096775D0FB8DD252A73E6F47C16BF2D7DB0C3FBDFD206EE57393276FB40F65C1441296AE2AC115CFEE11098474DF3FEF8EE1FABE139427A8991F052
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Seoul)]} {.. LoadTimeZoneFile Asia/Seoul..}..set TZData(:ROK) $TZData(:Asia/Seoul)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):180
                                                                                                                                                                                                                                                          Entropy (8bit):4.85623787837429
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq801c3vXHAIgNtK1tyHRL/kZ8O5h4WFKf1z:SlSWB9vsM3yUgHAIgWv6N/kth4wKf9
                                                                                                                                                                                                                                                          MD5:5EABBAAF3B29B5DFF9E54136F7ABC654
                                                                                                                                                                                                                                                          SHA1:44615F03264012D97512F9AB386413DD72BE1090
                                                                                                                                                                                                                                                          SHA-256:B9443FB17F0128DDB9F2DF657DC5D2DF176F64C61B0D02B272E5DFB108537678
                                                                                                                                                                                                                                                          SHA-512:B930D637A1E69E0847ADDEAB013B2C25BC27EBB9CDF20B9CDDFDAC111E9F26BB5EBC83194E845ACC3E1B9A08C386C94FCC4FDE32292EB558E3F7463832BB38B9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Singapore)]} {.. LoadTimeZoneFile Asia/Singapore..}..set TZData(:Singapore) $TZData(:Asia/Singapore)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):201
                                                                                                                                                                                                                                                          Entropy (8bit):4.996391010176349
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSNJB9vsM3y7p5oeSHAIgppON/kjx+90ppv:JByMYbpwt8+90b
                                                                                                                                                                                                                                                          MD5:1AC81E2C60D528A6C5BF2E6867146813
                                                                                                                                                                                                                                                          SHA1:73D2D24FE6D56CA34ABF11B9A95DC22F809C5158
                                                                                                                                                                                                                                                          SHA-256:978C4E5256057CE7374AD7929605090FC749B55558495BD0112FB0BB743FA9C2
                                                                                                                                                                                                                                                          SHA-512:DB2673FB54C1308BBEB298A186F9130FB9090CE33B958C82D62B9BD88EE39BAB9A1BE40645547BA4167FD475892A323CF8EBA16C97F6FDF5693F1BF7A313FE9A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:SystemV/AST4) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):192
                                                                                                                                                                                                                                                          Entropy (8bit):4.9470542553730255
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqx02NEO/vXHAIg202NEqA6RL/kRDwh4IAcGE2NEOyn:SlSNJB9vsM3y7UEOXHAIgpUEqA6N/k+H
                                                                                                                                                                                                                                                          MD5:2AB4B896957F26B114A990F69989F3FB
                                                                                                                                                                                                                                                          SHA1:8048C99F5EE02C021F311709B30EB28D650D884D
                                                                                                                                                                                                                                                          SHA-256:0114C111F5BCD838A28F2E16E01ECB79D8AFC8CBF639A672889ED0D692FC6CDC
                                                                                                                                                                                                                                                          SHA-512:353744359CD94B1E8184A8B83F762459C69D3AEEA43DA638C1F4CC34E01E9D86C2EBCF7F7BFD059CB23B64051510D1C4556A49D180F8A92DE8449139194DCDC9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Halifax)]} {.. LoadTimeZoneFile America/Halifax..}..set TZData(:SystemV/AST4ADT) $TZData(:America/Halifax)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):186
                                                                                                                                                                                                                                                          Entropy (8bit):4.957831162100758
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqx0sAzE5Y5XHAIg20sAzEo5RL/kR/eIAcGEsAzEpv:SlSNJB9vsM3y7hzi2HAIgphznN/kc90q
                                                                                                                                                                                                                                                          MD5:3EC0B09EAB848821D48849673B24401C
                                                                                                                                                                                                                                                          SHA1:41599CBA78E124A7DA9744D2B4EA8CDC10008E0B
                                                                                                                                                                                                                                                          SHA-256:30428B85B37898AD98B65BE5B6A8BD599331D9A1B49605FC6521464228E32F8F
                                                                                                                                                                                                                                                          SHA-512:9A3303B3338C01B281A40BB48B93C446ADB92BBDC45371667F09EDA92F9EE2AEC60CE8E98CE15C0112B823799C76AEF14895B15DC997DA506494D75BBE58D662
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Regina)]} {.. LoadTimeZoneFile America/Regina..}..set TZData(:SystemV/CST6) $TZData(:America/Regina)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):192
                                                                                                                                                                                                                                                          Entropy (8bit):4.975428048518589
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqx096yXHAIg20961yHRL/kRwx/h4IAcGE967:SlSNJB9vsM3y796SHAIgp9616N/kyxpQ
                                                                                                                                                                                                                                                          MD5:D85CCC5EFAA1ED549D02F09A38A53C68
                                                                                                                                                                                                                                                          SHA1:642ED571E4C6F60A953D42DA4F756F2262E4E709
                                                                                                                                                                                                                                                          SHA-256:44BEF7D4660A9A873EB762E3FDC651D31D97893545DE643FA1B2D05991C090A1
                                                                                                                                                                                                                                                          SHA-512:3CC6A14A17EA4833958A7D444073D6C2709FD61BF54387E5C362151E9143F795B2432B621080DD53E0FC9BDD7C58F406E046E3D0A2BBA4132D99E7C705E6D645
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Chicago)]} {.. LoadTimeZoneFile America/Chicago..}..set TZData(:SystemV/CST6CDT) $TZData(:America/Chicago)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):204
                                                                                                                                                                                                                                                          Entropy (8bit):4.928128138328689
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSNJB9vsM3y73G7JHAIgp3GZRN/kkp4903G8:JByMY3G7Kp3GntVp4903G8
                                                                                                                                                                                                                                                          MD5:506D15E2F37F501F5A592154142A5296
                                                                                                                                                                                                                                                          SHA1:5ACA12E0BA0FFF9734ED978A9C60AAA9D1E05A59
                                                                                                                                                                                                                                                          SHA-256:798F92E5DDA65818C887750016D19E6EE9445ADFE0FCB7ACB11281293A09C2C7
                                                                                                                                                                                                                                                          SHA-512:2EE08D39461CAD3492BE88B421BA463B4CEB8497F036518794BCF605F477057FEA218A9DFBB6335A28A5120750EA06AED9D2EA84CD0007D34CDE562DCD79CC0C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indianapolis)]} {.. LoadTimeZoneFile America/Indianapolis..}..set TZData(:SystemV/EST5) $TZData(:America/Indianapolis)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):195
                                                                                                                                                                                                                                                          Entropy (8bit):5.113680059406992
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSNJB9vsM3y71RHAIgp1aAN/krp4901Yn:JByMY4pltw+90q
                                                                                                                                                                                                                                                          MD5:AAD8EF3067E97785D4052B80F5C4ACE1
                                                                                                                                                                                                                                                          SHA1:3EF0A06FCC41119F4A60A32CED0E5A1E0E8B4300
                                                                                                                                                                                                                                                          SHA-256:D159140114A13C69F073CFE9AD0B67D713E8811CBFF773A3D1681FC38EA0E699
                                                                                                                                                                                                                                                          SHA-512:A8774ADF6818D85476A6C147A45E55B338F413CD9B61BF9FDB0CB7A335C0CE8F8C6D1970783FEFECC2CE18388DF91304CB295BD4DFD29FB538D74F6A414A441D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/New_York)]} {.. LoadTimeZoneFile America/New_York..}..set TZData(:SystemV/EST5EDT) $TZData(:America/New_York)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):193
                                                                                                                                                                                                                                                          Entropy (8bit):4.9733028894475195
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSNJB9vsM3yc6e8SHAIgOb6eKAN/kQmrheo:JByMdniinbtRTo
                                                                                                                                                                                                                                                          MD5:458061B3F3C8F06C61B5726393A26BA2
                                                                                                                                                                                                                                                          SHA1:E894F5615654D1110C9964B8F6A54C048442D8EB
                                                                                                                                                                                                                                                          SHA-256:BF62C8650BBA258000F62F16B0C7CBB66F4FD63F8CFDAF54273BB88A02A6C8D6
                                                                                                                                                                                                                                                          SHA-512:6A161A7AE44CBF8CE4C704C94456A5B714AAF2A3FAF30731254C9FE056F9DDF207119D516CC6A4C44AE76EC078F5C59F5EC6DD6701FAA3A36F061AF3953B7C7D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Honolulu)]} {.. LoadTimeZoneFile Pacific/Honolulu..}..set TZData(:SystemV/HST10) $TZData(:Pacific/Honolulu)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.999038624718282
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqx0utLaDovXHAIg20utLRYovHRL/kRgFfh4IAcGEuto:SlSNJB9vsM3y7OBHAIgpONYyHN/kch4y
                                                                                                                                                                                                                                                          MD5:B06AB4998A57446FC4D5A5B986BCA0A9
                                                                                                                                                                                                                                                          SHA1:5E4A28466383CBAB2067B9B6D22882CF6D83C3FB
                                                                                                                                                                                                                                                          SHA-256:FEBE49FAE260E5595B6F1B21A0A3458D8A50ACA72F4551BF10C1EDB2758E0304
                                                                                                                                                                                                                                                          SHA-512:9E44174C4E348E1B768039585BA6393FD001B606E111092EEC57C75210A1E87BF3C72728321945D584CA60D4C848D88EB8B2F82CB88F38F90224A43FDCFEA9AA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Phoenix)]} {.. LoadTimeZoneFile America/Phoenix..}..set TZData(:SystemV/MST7) $TZData(:America/Phoenix)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.956231227702093
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqx06RGFfXHAIg206RORL/kRMMFfh4IAcGE6RB:SlSNJB9vsM3y7+SPHAIgp+ON/kD490+B
                                                                                                                                                                                                                                                          MD5:5D3C1ADB8AC4EAC9E9A31734CD6884BD
                                                                                                                                                                                                                                                          SHA1:535B024EA088B9B192BE4206CBDD56BC5B163762
                                                                                                                                                                                                                                                          SHA-256:64556A7B20E425C79375C2A7CCF72B2B5223A7DE4FF4C99A5C039DB3456C63F6
                                                                                                                                                                                                                                                          SHA-512:FB799A42880613752AD6010D7B4E97ACCF7F6AE281D9A37057F6423AEF2607B608DB2AC52176F1653D8B2D086223C9658B101E73125F0FF7D6D9E8CD876EEC53
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Denver)]} {.. LoadTimeZoneFile America/Denver..}..set TZData(:SystemV/MST7MDT) $TZData(:America/Denver)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):192
                                                                                                                                                                                                                                                          Entropy (8bit):4.831981174214766
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqTQGuQTWLM4YkovXHAIgObTuQTWLovFvHRL/kRQB5nv:SlSNJB9vsM3yciQyLM4YJHAIgObiQyLQ
                                                                                                                                                                                                                                                          MD5:B568B46A0207800D9C022BAB1E48709B
                                                                                                                                                                                                                                                          SHA1:71CE3F0E75E440D5BBA219BCBB92AF9C1F5A7466
                                                                                                                                                                                                                                                          SHA-256:0B8227AFC94082C985E8E125DF83E5EFADE7CD9CA399800D7B8E8B2BEAE22C7D
                                                                                                                                                                                                                                                          SHA-512:5067AAD0CD02EBDECA6980F9C7CCC80D076C34D6463C5B6B19B678D76B5E69C1C3639D046F56FE9D6255CBEA49189EDD735F66AD9EE2CB0389BE020E7ED3AD50
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pitcairn)]} {.. LoadTimeZoneFile Pacific/Pitcairn..}..set TZData(:SystemV/PST8) $TZData(:Pacific/Pitcairn)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):204
                                                                                                                                                                                                                                                          Entropy (8bit):5.003766957083974
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSNJB9vsM3y7DvPHAIgp5N/kQ1p490Dy:JByMY8p5th090W
                                                                                                                                                                                                                                                          MD5:7E587175CA0F938C47FA920D787C57BD
                                                                                                                                                                                                                                                          SHA1:C3F7D8576C0AC74D6B70F4363EE2C174FADC70B0
                                                                                                                                                                                                                                                          SHA-256:D51D9549835E9C058F836C8952932CB53C10F7F194CD87452E9B13494D1C54C9
                                                                                                                                                                                                                                                          SHA-512:4460686AAA470F07A6DB1F8957FA4DB600E116273497F46E8A2D3FDECF622122DF753556B78C39FA2ADFDB2AF3C3ABB3C330ADA79B35C6A3CD8C498A0319CEE6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Los_Angeles)]} {.. LoadTimeZoneFile America/Los_Angeles..}..set TZData(:SystemV/PST8PDT) $TZData(:America/Los_Angeles)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.9524733332469095
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqTQG5hB5WXHAIgObT5hByY6RL/kRKlUDH5hBpvn:SlSNJB9vsM3ycT2HAIgOboN/kNv
                                                                                                                                                                                                                                                          MD5:5970A466367825D72D9672293FCD4656
                                                                                                                                                                                                                                                          SHA1:1A736D61A6797295EEC8C094AED432171E98578E
                                                                                                                                                                                                                                                          SHA-256:55710EFDED5B5830B2F3A2A072037C5251E1766F318707ED7CD5EB03037FED43
                                                                                                                                                                                                                                                          SHA-512:1F2A1B2A7D0A3E410652546C174D9EC18C91C9327F11C384A0AA1EB12D7EFE85C4D53CA3C2A6C347C0068A4CE92A3138EB17232B0DEC88D52465C5DEDEEE6827
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Gambier)]} {.. LoadTimeZoneFile Pacific/Gambier..}..set TZData(:SystemV/YST9) $TZData(:Pacific/Gambier)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):198
                                                                                                                                                                                                                                                          Entropy (8bit):4.994125896811442
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSNJB9vsM3y7/9EtDSHAIgp/9Ef6N/kB490/9E9v:JByMY/947p/9XtN90/9s
                                                                                                                                                                                                                                                          MD5:560B18DFB138DAF821CFDAE017B94473
                                                                                                                                                                                                                                                          SHA1:0BB0312C742CC0097DF033656AE3D10723035C30
                                                                                                                                                                                                                                                          SHA-256:DA20018DE301F879E4F026405C69FA0370EB10184FE1C84A4F1504079D5DAFA1
                                                                                                                                                                                                                                                          SHA-512:B1D4EAD5F549E319DAD55EE67DAFD732E755164748C08633AA8F07C280B2CF617380D6F886304142D0E4D50026E63678DACFBE2DC809F780BA4CFF35A90DE906
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Anchorage)]} {.. LoadTimeZoneFile America/Anchorage..}..set TZData(:SystemV/YST9YDT) $TZData(:America/Anchorage)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):180
                                                                                                                                                                                                                                                          Entropy (8bit):4.9295990493611495
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV0XaDovXHAIgoq3XRFvHRL/jCl1yQaqXKv:SlSWB9vsM3ymQa2HAIgoQ/HN/SymKv
                                                                                                                                                                                                                                                          MD5:1FABF2DFD4BFD0184AE22ED76F7569E5
                                                                                                                                                                                                                                                          SHA1:5859266B26357B4FCADD7EC65847667631E303EB
                                                                                                                                                                                                                                                          SHA-256:8471A5575B9D9E47412D851A18A26C4405480540AABC8DAED5F81BE0C714C07C
                                                                                                                                                                                                                                                          SHA-512:1DCBECEF6D1F923E6C9CEA70CB10F1FF4E453265966AA88FBC8739E93EF40F8A16AAD85AF4ECC5CC1E52F22F49E5D3F4EE01A97DE2302FC4FBC063FE814F3851
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Istanbul)]} {.. LoadTimeZoneFile Europe/Istanbul..}..set TZData(:Turkey) $TZData(:Europe/Istanbul)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):153
                                                                                                                                                                                                                                                          Entropy (8bit):4.844017562912325
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/iGMFfh8RFB:SlSWB9vsM3yzTHAIgm6N/iP8RX
                                                                                                                                                                                                                                                          MD5:DA060D2F397C978E0842631B4EC73376
                                                                                                                                                                                                                                                          SHA1:649BC85430B04662BE079C0AAD43DF5D5D499D28
                                                                                                                                                                                                                                                          SHA-256:356A9BB6F831971C295CF4DCE0F0CDC9EDF94FD686CA3D3195E5F031A0B67CBA
                                                                                                                                                                                                                                                          SHA-512:3359BFC6F0837D2DA9D72DA8053773CE0C1A1B1A47C33163BF38965E2104F57BC147F9EEC228A3591B75BF1BA93285AB83E8427E8E2E697AB18501DC017B6E6A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:UCT) $TZData(:Etc/UTC)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):189
                                                                                                                                                                                                                                                          Entropy (8bit):4.911775112130145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0/VXEtDovXHAIg20/VXEfovRL/iOGl0IAcGE/VXEN:SlSWB9vsM3y7/9EtDSHAIgp/9Ef6N/i4
                                                                                                                                                                                                                                                          MD5:4379C0BF618649AA07CC4BDAC75F62EF
                                                                                                                                                                                                                                                          SHA1:7813B54BF2BD0C40A39CA9A29CC50C6D034880A3
                                                                                                                                                                                                                                                          SHA-256:CED56F09D68BE00555219594C7B2F3E7EFE8323201FB3E2AA0E1FA9A6467D5AF
                                                                                                                                                                                                                                                          SHA-512:AC822061F5C9743120A66E11C02B199253A40460A87F78DC154B0BDD91E410EDDA581E889F5D2A74670939034F39A7F6C7E814E038A1371DAB71EF79A8911AE7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Anchorage)]} {.. LoadTimeZoneFile America/Anchorage..}..set TZData(:US/Alaska) $TZData(:America/Anchorage)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):176
                                                                                                                                                                                                                                                          Entropy (8bit):4.8886795125313585
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0/yO5WXHAIg20/yOoNvWARL/iObMEIB/4IAcGE/y2:SlSWB9vsM3y7/yrHAIgp/yH0AN/itE8h
                                                                                                                                                                                                                                                          MD5:AB14CF1840CBDA2B326660DBD51273B4
                                                                                                                                                                                                                                                          SHA1:78144B3A2C75568307E4E86AE3B01EA7F541B011
                                                                                                                                                                                                                                                          SHA-256:A4F1398CF84D0AE09BF19288770756622D1710CCBFBFE79E0D3239497731287D
                                                                                                                                                                                                                                                          SHA-512:557A3ED9D1401E76291DC41524A1FD04AFF0829CEF66E103CEF9D10CD751F04FDEB6B7C0490302C71297F53AA8DC42930649AD274215D5DF068BCDE837E73756
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Adak)]} {.. LoadTimeZoneFile America/Adak..}..set TZData(:US/Aleutian) $TZData(:America/Adak)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.9334626069754455
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0utLaDovXHAIg20utLRYovHRL/iQMfQfBx+IAcGEB:SlSWB9vsM3y7OBHAIgpONYyHN/iZfQfl
                                                                                                                                                                                                                                                          MD5:30ED80335BE37C7CBA672C33FDE23490
                                                                                                                                                                                                                                                          SHA1:B627E86F023FE02A5590FE8D55FF41946BE6D24B
                                                                                                                                                                                                                                                          SHA-256:9503403F231BA33415A5F2F0FDD3771CE7FF78534CE83C16A8DB5BC333B4AD8A
                                                                                                                                                                                                                                                          SHA-512:C1352612EC0B4FF2F6F279CDB6008D7E9DA7F94F0009EFD959AD3092393150ECA83A09E72C724E1A4BFC3A057B9218D54A87FFA1102E2D9BF058B78AC0A0B1AB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Phoenix)]} {.. LoadTimeZoneFile America/Phoenix..}..set TZData(:US/Arizona) $TZData(:America/Phoenix)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):184
                                                                                                                                                                                                                                                          Entropy (8bit):4.90255068822036
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx096yXHAIg20961yHRL/ibXgox/h4IAcGE967:SlSWB9vsM3y796SHAIgp9616N/iB490+
                                                                                                                                                                                                                                                          MD5:7770A6B85B2FE73BCCE9D803E0200F23
                                                                                                                                                                                                                                                          SHA1:784AD1082FF1569961C2AC44F6D6F7605FBBE766
                                                                                                                                                                                                                                                          SHA-256:B6AC9FAE0AB69D58ECFD6B9A84F3C6D3E1A594E40CEEC94E2A0A7855781E173A
                                                                                                                                                                                                                                                          SHA-512:EEE79D37D77E6B80B91E8F30CE48B107371F6A58F0C91785E3C74EF210AE1011D0EB913113F1873BE6099B0BE1260410F0C74650446CB377F8FDB5505A44F266
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Chicago)]} {.. LoadTimeZoneFile America/Chicago..}..set TZData(:US/Central) $TZData(:America/Chicago)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):228
                                                                                                                                                                                                                                                          Entropy (8bit):4.7645631776966715
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y73GK7JHAIgp3GKZRN/i3E0903GK8:MByMY3GK7Kp3GKnti3t903GK8
                                                                                                                                                                                                                                                          MD5:96828B6BA17CA96723794F4B3744B494
                                                                                                                                                                                                                                                          SHA1:C3A824A925AEFE2A13A0E65548078D9842C2C7D7
                                                                                                                                                                                                                                                          SHA-256:5D86F8D36598516FB2342A18A87DB2701BABD265B0671CC9321C48DB22C7ECA5
                                                                                                                                                                                                                                                          SHA-512:2A27A455787DEAC3EC78A2784FB989DAB178E9D6DD7721CD3F5D3337231A3C651994B964D6CE040B7858E0127D7F70C0C48CB0D553D5B725B649C828288224B5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Indianapolis)]} {.. LoadTimeZoneFile America/Indiana/Indianapolis..}..set TZData(:US/East-Indiana) $TZData(:America/Indiana/Indianapolis)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):187
                                                                                                                                                                                                                                                          Entropy (8bit):5.0345860115708785
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0wAy0vfXHAIg20wAyGWARL/i37oxp4IAcGEwAy0yn:SlSWB9vsM3y71RHAIgp1aAN/i37oxp4P
                                                                                                                                                                                                                                                          MD5:375DB249106C5D351CA0E84848835EDB
                                                                                                                                                                                                                                                          SHA1:ECC5C0C9DA68773B94C9013F4F1A8800D511CC4C
                                                                                                                                                                                                                                                          SHA-256:2FFCAD8CBEF5ECDC74DB3EE773E4B18ABC8EFA9C09C4EA8F3A45A08BADAF91A9
                                                                                                                                                                                                                                                          SHA-512:21550743BF4E1A79754F76AB201F0EB6BA6B265F43855901640054316A4A32A5D01D266B2441E4A6415720715A2ABD367D82E3D40949A7A66BE9F8366E47A8DD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/New_York)]} {.. LoadTimeZoneFile America/New_York..}..set TZData(:US/Eastern) $TZData(:America/New_York)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):186
                                                                                                                                                                                                                                                          Entropy (8bit):4.88075715646936
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG2fWGYFeyXHAIgObT2fWKARL/ioMN75nUDH2fWWv:SlSWB9vsM3yc6e8SHAIgOb6eKAN/ioER
                                                                                                                                                                                                                                                          MD5:C0475756CFEC302F737967468804846E
                                                                                                                                                                                                                                                          SHA1:85C13CA0A908C69B8BBB6040FC502AFF96B8F8C7
                                                                                                                                                                                                                                                          SHA-256:529BB43EFDA6C1584FEAEA789B590CEF1397E33457AB3845F3101B1FC126E0FB
                                                                                                                                                                                                                                                          SHA-512:D3FF374443344E8438D50803872E8A8EA077B2299B38C1BD155386B4D2C6008BBD0C0B0B26DE9680812D4AFC9A187B644BDCCB04C23880337228BCEC06D5D61B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Honolulu)]} {.. LoadTimeZoneFile Pacific/Honolulu..}..set TZData(:US/Hawaii) $TZData(:Pacific/Honolulu)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):206
                                                                                                                                                                                                                                                          Entropy (8bit):4.87340978435866
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:SlSWB9vsM3y73GKaHAIgp3GKIN/iGIfh4903GKT:MByMY3GKDp3GKItiBfh4903GKT
                                                                                                                                                                                                                                                          MD5:00AAFD60A0B1146274981FAB6336AFD9
                                                                                                                                                                                                                                                          SHA1:20AD47ED52874202585C90FE362663F060E064D3
                                                                                                                                                                                                                                                          SHA-256:5827B6A6D50CF0FB75D6BA6E36282591AD25E1F0BE636DCFC5D09BDA29A107FD
                                                                                                                                                                                                                                                          SHA-512:61113AB72B7D671D7B429106709E73DB57D5B8A382680BA37A54126C7F54BC2D6B47A2584177CE6B434793546DA7EB9B8B7DF9163816DBFC67C83D9930D6A158
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Knox)]} {.. LoadTimeZoneFile America/Indiana/Knox..}..set TZData(:US/Indiana-Starke) $TZData(:America/Indiana/Knox)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):185
                                                                                                                                                                                                                                                          Entropy (8bit):4.83459089067994
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx06FQGFfXHAIg206FQJARL/iHaMCELMr4IAcGE6FQB:SlSWB9vsM3y74PFPHAIgp4KAN/iHaMHs
                                                                                                                                                                                                                                                          MD5:D955A5A943B203DC4B87A91ED196B82A
                                                                                                                                                                                                                                                          SHA1:C7ACC48AB2033C372C60C741F68B12FFAEA147DE
                                                                                                                                                                                                                                                          SHA-256:B4E4269C4FEBFEFF26750B297A590226C0A6872519A6BFDE36F6DC3F6F756349
                                                                                                                                                                                                                                                          SHA-512:445DC9A50487A4BA0A7F79078441696DCAA31F9988E5B515B5A827AC9275776B22DE303040900C1726EB99CABA8AD09E57AA674F798EA3FDEBC580E4B87D9439
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Detroit)]} {.. LoadTimeZoneFile America/Detroit..}..set TZData(:US/Michigan) $TZData(:America/Detroit)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):182
                                                                                                                                                                                                                                                          Entropy (8bit):4.892777905787396
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx06RGFfXHAIg206RORL/iBOlLo/4IAcGE6RB:SlSWB9vsM3y7+SPHAIgp+ON/iBY8/49Z
                                                                                                                                                                                                                                                          MD5:E53EDD55E6448C624DD03A8A100EF5AF
                                                                                                                                                                                                                                                          SHA1:1D266553CAFA23A3375CFAF7AFE6636553CC7B70
                                                                                                                                                                                                                                                          SHA-256:3763BF520D3C97148C34DCFBDF70DEC2636D4E38241555900C058EFEE3BD1256
                                                                                                                                                                                                                                                          SHA-512:B7FCF01DBB4231F30FEFA77C339B2CD7D984D6E6182F3BD15D6B64AC9525994E7CBF90C3F1F520FD22B54E19831B3CBAE1C22F04F60244C0C60A1809942422A4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Denver)]} {.. LoadTimeZoneFile America/Denver..}..set TZData(:US/Mountain) $TZData(:America/Denver)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):196
                                                                                                                                                                                                                                                          Entropy (8bit):4.932311644026309
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0ydJg4o3vXHAIg20ydJPyHRL/iP+e2IAcGEydJgov:SlSWB9vsM3y7DvPHAIgp5N/ip290Dy
                                                                                                                                                                                                                                                          MD5:37AF94FAB52D80AF32C766644892E36D
                                                                                                                                                                                                                                                          SHA1:03CE96A3B3EBFC16C9ED192DD2127FB265A7ED49
                                                                                                                                                                                                                                                          SHA-256:54E5F126D4E7CC13555841A61FF66C0350621C089F475638A393930B3FB4918C
                                                                                                                                                                                                                                                          SHA-512:405A7F414FA0864111E5E9F06FCA675BF4EF11FE0F82F5438416273BEF820A030A50E4D43E4E522ED79C08C0C243E9DD3692971DC912C9ADFB1BEABEB935CDDC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Los_Angeles)]} {.. LoadTimeZoneFile America/Los_Angeles..}..set TZData(:US/Pacific) $TZData(:America/Los_Angeles)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):188
                                                                                                                                                                                                                                                          Entropy (8bit):4.838968615416201
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGurKeTnXHAIgObTurKefVHRL/i6A5nUDHurKeTyn:SlSWB9vsM3yciemHAIgObiecN/idXevn
                                                                                                                                                                                                                                                          MD5:509CF35F5F7C9567FD19CC5C137DC070
                                                                                                                                                                                                                                                          SHA1:AA5F27D36BC617A6A4107E3CA0CB0C10A71A1D9E
                                                                                                                                                                                                                                                          SHA-256:E51FC51C65FFEAB514D7636271157EE8941BDACF602CBC380F5D60B5FA674E87
                                                                                                                                                                                                                                                          SHA-512:E23633A16F11015F3FE2F4E675B5A60B4FDC61F8CF152FDB9BA7ED4C213B8897117721A78C5470296DAFB0FD4F0DDC019DD0DB8C28C1F1B2BE0D3A289F53D5B3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pago_Pago)]} {.. LoadTimeZoneFile Pacific/Pago_Pago..}..set TZData(:US/Samoa) $TZData(:Pacific/Pago_Pago)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):153
                                                                                                                                                                                                                                                          Entropy (8bit):4.844017562912325
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/iLB5h8RFB:SlSWB9vsM3yzTHAIgm6N/iLfh8RX
                                                                                                                                                                                                                                                          MD5:3402C8784654C24F7E956731866B833F
                                                                                                                                                                                                                                                          SHA1:C34F3CCA074A50E6564B8C78683C8763B37A3002
                                                                                                                                                                                                                                                          SHA-256:DEE28FF84E3FC495ED3547D5E5E9FAFDACC36A67329E747D434248ED45BF1755
                                                                                                                                                                                                                                                          SHA-512:FBA2840B0FA0F084EE9840BCF56E497F8A7ABF509FA10FA66FB26BA3D80079C4F9A363577A453CD68557080EAF9DD7F1F7B5AF957B64BDA2A897B1E08C85DD19
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:UTC) $TZData(:Etc/UTC)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):159
                                                                                                                                                                                                                                                          Entropy (8bit):4.879221007428352
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/iL7DJMFfh8RFB:SlSWB9vsM3yzTHAIgm6N/iL7VMr8RX
                                                                                                                                                                                                                                                          MD5:5F24A249884C241D1E03D758C2641675
                                                                                                                                                                                                                                                          SHA1:63AAC15A68659006F8A14FEC3F2A66B55A8AC398
                                                                                                                                                                                                                                                          SHA-256:B7B0B82F471D64704E1D6F84646E6B7B2BD9CAB793FAD00F9C9B0595143C0AB7
                                                                                                                                                                                                                                                          SHA-512:A7AB5E26A2C23BA296942D7C524C6EE6708A9A38CDD88022EA92E2180BC3CCFE930758FC20A24A0D271AD70733EB924B0E530FBF83CC0FC49EAD411B28503CC0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Universal) $TZData(:Etc/UTC)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):172
                                                                                                                                                                                                                                                          Entropy (8bit):4.999171213761279
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVwTwWXHAIgoqzTbNOARL/gIuyQauTgvn:SlSWB9vsM3ymSHAIgoXAN/gXy5n
                                                                                                                                                                                                                                                          MD5:5444E85070CA2E7A52D38D6D53216B88
                                                                                                                                                                                                                                                          SHA1:0F9A4FB1156312EBD0B9C81DA2164E89D21878E1
                                                                                                                                                                                                                                                          SHA-256:F7DA75B585F45AB501B2889E272FF47B1C4A1D668E40AED7463EB0E8054028C2
                                                                                                                                                                                                                                                          SHA-512:BBC94F98C84641392D3A4B67C152E92EDB3011DA329319ADB2485DBEAFD44DED328D80FBCA89E58687E1F0EB6BED8580BBB0075CA42284B6206A8641D76F2DE5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Moscow)]} {.. LoadTimeZoneFile Europe/Moscow..}..set TZData(:W-SU) $TZData(:Europe/Moscow)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6945
                                                                                                                                                                                                                                                          Entropy (8bit):3.7806395604065135
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:v6PgDGfXCiZoFtFPIaFF1w0urfva946ZGsE3f2Sf+aCNmSv+kznl4klEp8OT:rQbkIaFF1w0us4qE3+sSGjT
                                                                                                                                                                                                                                                          MD5:1EC38B05B53ECF2DD3A90164C4693934
                                                                                                                                                                                                                                                          SHA1:00900F0ADDB7526C63C67CA1662C038E95A79245
                                                                                                                                                                                                                                                          SHA-256:7E6E2369C19DD19A41BE27BB8AD8DF5BE8B0096ED045C8B2C2D2F0916D494079
                                                                                                                                                                                                                                                          SHA-512:47A8DAAB1B891FF09A94AF01B6673213392F70C6C1EE53D95A59D6E238FD06B0E80FA21C7279A9ADA891F5CA5B86E4D6B696EE8CFE14BFEF0ACCC9759AF1419A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:WET) {.. {-9223372036854775808 0 0 WET}.. {228877200 3600 1 WEST}.. {243997200 0 0 WET}.. {260326800 3600 1 WEST}.. {276051600 0 0 WET}.. {291776400 3600 1 WEST}.. {307501200 0 0 WET}.. {323830800 3600 1 WEST}.. {338950800 0 0 WET}.. {354675600 3600 1 WEST}.. {370400400 0 0 WET}.. {386125200 3600 1 WEST}.. {401850000 0 0 WET}.. {417574800 3600 1 WEST}.. {433299600 0 0 WET}.. {449024400 3600 1 WEST}.. {465354000 0 0 WET}.. {481078800 3600 1 WEST}.. {496803600 0 0 WET}.. {512528400 3600 1 WEST}.. {528253200 0 0 WET}.. {543978000 3600 1 WEST}.. {559702800 0 0 WET}.. {575427600 3600 1 WEST}.. {591152400 0 0 WET}.. {606877200 3600 1 WEST}.. {622602000 0 0 WET}.. {638326800 3600 1 WEST}.. {654656400 0 0 WET}.. {670381200 3600 1 WEST}.. {686106000 0 0 WET}.. {701830800 3600 1 WEST}.. {717555600 0 0 WET}.. {733280400 3600 1 WEST}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):154
                                                                                                                                                                                                                                                          Entropy (8bit):4.8800842076244715
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/taFBURFB:SlSWB9vsM3yzTHAIgm6N/YFaRX
                                                                                                                                                                                                                                                          MD5:DDB6F69CA4F0EF6A708481F53F95EAB9
                                                                                                                                                                                                                                                          SHA1:A63E900A9257E9D73B4BB4BACBA8133C3D1DC41B
                                                                                                                                                                                                                                                          SHA-256:A06E8CCCF97CC8FB545DFDB4C89B5E5C8EDF0360547BDC1823B4AC47B1556C31
                                                                                                                                                                                                                                                          SHA-512:C8EA1039BE001F5EF52662B28DBF46D02E4848F08F05923850DEA1994732037B4C8D6030B742D97FA4276AF5FEE3F17C47C7DDA4F44DD23244F9976A076D5CC4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Zulu) $TZData(:Etc/UTC)..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5051
                                                                                                                                                                                                                                                          Entropy (8bit):4.840016819053602
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:HgT4Wi5uhdFQpmuldFQofsGP3R1hF9Dl19arB0E9Dl1YoaEhHe2Gu/q1ZFyJRpqz:8K5ULoxvR197ABr971h5GIqrmbqIc+bq
                                                                                                                                                                                                                                                          MD5:BB07BBA7F99F6BB56135429BED589136
                                                                                                                                                                                                                                                          SHA1:47593D5EFFC8618B07C2C3C838C8752072ACB318
                                                                                                                                                                                                                                                          SHA-256:128A314521EA5671569E265968057DA0C5A420F126AD02C4A2DB7EFC736620E9
                                                                                                                                                                                                                                                          SHA-512:ADDD960D09119F06A454A7510BF12DEA67BB97AF931887276B8683338CC794B36BE1B7DEF3A02E016C7E009F6F6E96C0DCECB068839CFDE5B2B3EFDEB1C5A073
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# word.tcl --..#..# This file defines various procedures for computing word boundaries in..# strings. This file is primarily needed so Tk text and entry widgets behave..# properly for different platforms...#..# Copyright (c) 1996 Sun Microsystems, Inc...# Copyright (c) 1998 Scriptics Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....# The following variables are used to determine which characters are..# interpreted as white space.....if {$::tcl_platform(platform) eq "windows"} {.. # Windows style - any but a Unicode space char.. if {![info exists ::tcl_wordchars]} {...set ::tcl_wordchars {\S}.. }.. if {![info exists ::tcl_nonwordchars]} {...set ::tcl_nonwordchars {\s}.. }..} else {.. # Motif style - any Unicode word char (number, letter, or underscore).. if {![info exists ::tcl_wordchars]} {...set ::tcl_wordchars {\w}.. }.. if {![info exists ::tcl_nonwordchar
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8806
                                                                                                                                                                                                                                                          Entropy (8bit):4.863085192885279
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:RpwYLapGk1BlM4UBIHpJFVUXUziMJ5Kxyk55qxUr7Vdk5vNR:RuYfvMdOXyj+01f
                                                                                                                                                                                                                                                          MD5:C5E9A2E32AE83A79DF422D1145B692DF
                                                                                                                                                                                                                                                          SHA1:08350F930FB97A95970122920C91FB9CED8329E9
                                                                                                                                                                                                                                                          SHA-256:8822365EE279BEBF7A36CFDEDBA1114762F894781F4635170CC5D85FF5B17923
                                                                                                                                                                                                                                                          SHA-512:71420E15A3D63329560074F6FFAD42CB464401284BC29D0DC8E34D83F8F77079F26BB4C5703E656A48E6931C3DBF6B873756FB212D0860483E0301B29EDE1212
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# bgerror.tcl --..#..#.Implementation of the bgerror procedure. It posts a dialog box with..#.the error message and gives the user a chance to see a more detailed..#.stack trace, and possible do something more interesting with that..#.trace (like save it to a log). This is adapted from work done by..#.Donal K. Fellows...#..# Copyright (c) 1998-2000 by Ajuba Solutions...# Copyright (c) 2007 by ActiveState Software Inc...# Copyright (c) 2007 Daniel A. Steffen <das@users.sourceforge.net>..# Copyright (c) 2009 Pat Thoyts <patthoyts@users.sourceforge.net>....namespace eval ::tk::dialog::error {.. namespace import -force ::tk::msgcat::*.. namespace export bgerror.. option add *ErrorDialog.function.text [mc "Save To Log"] \...widgetDefault.. option add *ErrorDialog.function.command [namespace code SaveToLog].. option add *ErrorDialog*Label.font TkCaptionFont widgetDefault.. if {[tk windowingsystem] eq "aqua"} {...option add *ErrorDialog*background systemAlertBackgroundActi
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):21612
                                                                                                                                                                                                                                                          Entropy (8bit):4.947590677310969
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:Tv7cBCAsj9oqlFFSsB3VfRt+lMpWaNwJgzCHarc6gAsj9oqlFFSsB3VlRtYlMpBz:TvweHBBTfIZxHBnZWqbJPBFIaVlCj26+
                                                                                                                                                                                                                                                          MD5:AEB53F7F1506CDFDFE557F54A76060CE
                                                                                                                                                                                                                                                          SHA1:EBB3666EE444B91A0D335DA19C8333F73B71933B
                                                                                                                                                                                                                                                          SHA-256:1F5DD8D81B26F16E772E92FD2A22ACCB785004D0ED3447E54F87005D9C6A07A5
                                                                                                                                                                                                                                                          SHA-512:ACDAD4DF988DF6B2290FC9622E8EACCC31787FECDC98DCCA38519CB762339D4D3FB344AE504B8C7918D6F414F4AD05D15E828DF7F7F68F363BEC54B11C9B7C43
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# button.tcl --..#..# This file defines the default bindings for Tk label, button,..# checkbutton, and radiobutton widgets and provides procedures..# that help in implementing those bindings...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1996 Sun Microsystems, Inc...# Copyright (c) 2002 ActiveState Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# The code below creates the default class bindings for buttons...#-------------------------------------------------------------------------....if {[tk windowingsystem] eq "aqua"} {.... bind Radiobutton <Enter> {...tk::ButtonEnter %W.. }.. bind Radiobutton <1> {...tk::ButtonDown %W.. }.. bind Radiobutton <ButtonRelease-1> {...tk::ButtonUp %W.. }.. bind Checkbutton <Enter> {...tk::ButtonEnter %W
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Nim source code, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10009
                                                                                                                                                                                                                                                          Entropy (8bit):4.804060725528893
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:HKOdkMpU9YUp8UIhMYYicln9Die0luVZS3pIp5Y3sF1P8Bg8p6trIOzvKsOiCLt+:HyMm9J8wPx70lu+4C8Fygq6tohef+0Uk
                                                                                                                                                                                                                                                          MD5:95975F4BB026E7302CBE9A4F48BC8EA4
                                                                                                                                                                                                                                                          SHA1:AD775025B2B2CB8192D851CEFF66B4F3141BDBB4
                                                                                                                                                                                                                                                          SHA-256:0EB33BC583823E5F10172C04B73B07EE36A17F1A5E2662548F2F3A13C7517FE7
                                                                                                                                                                                                                                                          SHA-512:0A6F350D7840354D6939EADC53979179A9E1DA256183CC0BD38777694A0B830DEF162F2F5FE592BD722C354BEFFF2546ED60E05939C71ACFD8D8F7C09B50027E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# choosedir.tcl --..#..#.Choose directory dialog implementation for Unix/Mac...#..# Copyright (c) 1998-2000 by Scriptics Corporation...# All rights reserved.....# Make sure the tk::dialog namespace, in which all dialogs should live, exists..namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::file {}....# Make the chooseDir namespace inside the dialog namespace..namespace eval ::tk::dialog::file::chooseDir {.. namespace import -force ::tk::msgcat::*..}....# ::tk::dialog::file::chooseDir:: --..#..#.Implements the TK directory selection dialog...#..# Arguments:..#.args..Options parsed by the procedure...#..proc ::tk::dialog::file::chooseDir:: {args} {.. variable ::tk::Priv.. set dataName __tk_choosedir.. upvar ::tk::dialog::file::$dataName data.. Config $dataName $args.... if {$data(-parent) eq "."} {.. set w .$dataName.. } else {.. set w $data(-parent).$dataName.. }.... # (re)create the dialog box if necessary.. #.. if {![winfo exis
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):22039
                                                                                                                                                                                                                                                          Entropy (8bit):5.031583640145799
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:lJGidpe3JQDUd6hgp6EQstzQf+a9DPbC43/H//cO802UeeVnZmM6BA0kyVJv9Qpu:Gep6JCwQDPb7PaRCzTdMAe
                                                                                                                                                                                                                                                          MD5:084E0D1FF7730CD92FAA97D18C2F2F09
                                                                                                                                                                                                                                                          SHA1:86EC3B4E6ECF4E9A00387EE69B1C524E71EBE059
                                                                                                                                                                                                                                                          SHA-256:D8D500875E78B21FC1F5F4196218715116474EC834B6E52022A18F885D4645B2
                                                                                                                                                                                                                                                          SHA-512:94C364FA1B8D00775DA3F7459CBEF63504C306CC2908F0FF84E2553986B3D5DA617B7CDC49D3000E4E7638E57C3D7D74C312214FED7DC2B80191FBB0FE318EB4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# clrpick.tcl --..#..#.Color selection dialog for platforms that do not support a..#.standard color selection dialog...#..# Copyright (c) 1996 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#..# ToDo:..#..#.(1): Find out how many free colors are left in the colormap and..#. don't allocate too many colors...#.(2): Implement HSV color selection...#....# Make sure namespaces exist..namespace eval ::tk {}..namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::color {.. namespace import ::tk::msgcat::*..}....# ::tk::dialog::color:: --..#..#.Create a color dialog and let the user choose a color. This function..#.should not be called directly. It is called by the tk_chooseColor..#.function when a native color selector widget does not exist..#..proc ::tk::dialog::color:: {args} {.. variable ::tk::Priv.. set dataName __tk__color.. upvar ::tk::dialog::color::$da
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8690
                                                                                                                                                                                                                                                          Entropy (8bit):5.098389551322902
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:u4R7+/gFw/MEN55fO7eyjt4bjC+gR8e3vwLln/+LVtUw0tXK4jA:u4l+/gFeMI55Xyjt4bjC+gOe3Ih/+LV1
                                                                                                                                                                                                                                                          MD5:ABF277E4F62423F4345B6AD65640B8C2
                                                                                                                                                                                                                                                          SHA1:E66A4E37D51C7827C9ACA449A42E0966AACBC8C8
                                                                                                                                                                                                                                                          SHA-256:C7DA292CCF5F413E599C3491C331FFD58CF273F8477FACB097E6F36CF1F32A08
                                                                                                                                                                                                                                                          SHA-512:AA9F75D7C5C915B5FCD2F454856D080D186AB9BA149DC139FEAF7F4AC3DC51E6769E138E3B1BE45B3FEC3AE744189DE44DB2B748F0628FF13E4E733B9CD68BD5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# comdlg.tcl --..#..#.Some functions needed for the common dialog boxes. Probably need to go..#.in a different file...#..# Copyright (c) 1996 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# tclParseConfigSpec --..#..#.Parses a list of "-option value" pairs. If all options and..#.values are legal, the values are stored in..#.$data($option). Otherwise an error message is returned. When..#.an error happens, the data() array may have been partially..#.modified, but all the modified members of the data(0 array are..#.guaranteed to have valid values. This is different than..#.Tk_ConfigureWidget() which does not modify the value of a..#.widget record if any error occurs...#..# Arguments:..#..# w = widget record to modify. Must be the pathname of a widget...#..# specs = {..# {-commandlineswitch resourceName ResourceClass defaultValue verifier}..# {....}..# }..#..# flags
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):33348
                                                                                                                                                                                                                                                          Entropy (8bit):4.996041902501109
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:jMpwGU6OGEJemVueuR3fitsHI76Su6qKNjGCy1HyOnmTTRV+po2mBh6S5mDjbHqC:jMpdUDGEJpC6+oVeKNPjnD2jVfV/
                                                                                                                                                                                                                                                          MD5:410FE75A44BF8E1E0D2FEF923EB0D181
                                                                                                                                                                                                                                                          SHA1:95B73F3C861F5E7F2AD2B48048016E81B2EA6AD6
                                                                                                                                                                                                                                                          SHA-256:4B1527F6572DB1ED6DE66C194F687419FD78C381928E7B1F523C6A06CD755E9E
                                                                                                                                                                                                                                                          SHA-512:267925AEF36E69D803C7A23A6CAB7C81925AC9B6379D61B796A3BB933AB624F57F5B65BA34ECFCC0C6995DC2CB8662A31F3A9ADF760924199D14071BD60321C5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# console.tcl --..#..# This code constructs the console window for an application. It..# can be used by non-unix systems that do not have built-in support..# for shells...#..# Copyright (c) 1995-1997 Sun Microsystems, Inc...# Copyright (c) 1998-2000 Ajuba Solutions...# Copyright (c) 2007-2008 Daniel A. Steffen <das@users.sourceforge.net>..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# TODO: history - remember partially written command....namespace eval ::tk::console {.. variable blinkTime 500 ; # msecs to blink braced range for.. variable blinkRange 1 ; # enable blinking of the entire braced range.. variable magicKeys 1 ; # enable brace matching and proc/var recognition.. variable maxLines 600 ; # maximum # of lines buffered in console.. variable showMatches 1 ; # show multiple expand matches.. variable useFontchooser [llength [info command ::tk::fontchooser]
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5988
                                                                                                                                                                                                                                                          Entropy (8bit):4.829498876074983
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:qFR55woFFEciKwKClFEOTIhDHWyzaoj9zza7v0J7:qL55jiKwKCzTIhDbzaojhSG7
                                                                                                                                                                                                                                                          MD5:B2B3AA971D42FDBF92F13B45111EE1D3
                                                                                                                                                                                                                                                          SHA1:A74F2C2707463D6E209D0E0C96D75083AC6920A5
                                                                                                                                                                                                                                                          SHA-256:1C977052C1D8293CC5FE4198A538BECA9BC821AF85E76E4EEFBFB75B33CE8BED
                                                                                                                                                                                                                                                          SHA-512:146F658DA3E6E9176FA51C9836D7C1DCFC14E148A26B224155F6493C195A7FB20C2DC4EE21994E5A193B8DA8561C75374E830304F94F0C844E52AD829F6810D5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# dialog.tcl --..#..# This file defines the procedure tk_dialog, which creates a dialog..# box containing a bitmap, a message, and one or more buttons...#..# Copyright (c) 1992-1993 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#..# ::tk_dialog:..#..# This procedure displays a dialog box, waits for a button in the dialog..# to be invoked, then returns the index of the selected button. If the..# dialog somehow gets destroyed, -1 is returned...#..# Arguments:..# w -..Window to use for dialog top-level...# title -.Title to display in dialog's decorative frame...# text -.Message to display in dialog...# bitmap -.Bitmap to display in dialog (empty string means none)...# default -.Index of button that is to display the default ring..#..(-1 means none)...# args -.One or more strings to display in buttons
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):18942
                                                                                                                                                                                                                                                          Entropy (8bit):4.977853953260254
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:mDfyPIlBk3yrt8qLjtpa+qh+rA4rsWRWrrMUtCPnsKAN3Pp64ZnCD:mDfyPIlBk3yJ8mtpaplcpwo
                                                                                                                                                                                                                                                          MD5:CE819200E8CD36E4458B4CF47CFE9107
                                                                                                                                                                                                                                                          SHA1:D04357D9E236F83BB0D2F5DB97E9EE228C34EC80
                                                                                                                                                                                                                                                          SHA-256:6AC78F764434F932D37E8183AA6DB5D04EB1848B774C92F7ABC243ECB7D4A59B
                                                                                                                                                                                                                                                          SHA-512:6576612C380AB04FA75724C72108A2F386D7F75C9DB7A082445778F675E268D0594280A7644AA9FF3AC3D29026327B84A0990EE0C7A9F94BBAC3AE63CF91E1DE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# entry.tcl --..#..# This file defines the default bindings for Tk entry widgets and provides..# procedures that help in implementing those bindings...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of tk::Priv that are used in this file:..#..# afterId -..If non-null, it means that auto-scanning is underway..#...and it gives the "after" id for the next auto-scan..#...command to be executed...# mouseMoved -..Non-zero means the mouse has moved a significant..#...amount since the button went down (so, for example,..#...start dragging out a selection)...# pressX -..X-coordinate at which the mouse button was pressed...# selectMode -..The style of selection currently underway:..#...char, word
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5035
                                                                                                                                                                                                                                                          Entropy (8bit):4.819523401259934
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:J3MRZZ7HWb/6OgRKjtS6Mn9GRZZ7HWb2Y6aO6R5nh76SMoB2kd82KtTpsi2D0DSn:CRZdPul1RZdFaRf0XoB2gZKZpsi2pn
                                                                                                                                                                                                                                                          MD5:63B219BE9AFF1DE7DE2BAF0E941CAE38
                                                                                                                                                                                                                                                          SHA1:A2FEBB31380E12FF01E6F641FE8B4F815941462F
                                                                                                                                                                                                                                                          SHA-256:8872F236D7E824AEC0ACD4BACC00FDD7EC9BC5534814ECF2160610C10647B7C5
                                                                                                                                                                                                                                                          SHA-512:057700F8FDE4B7C3D7AB7CEFD6C531060BF2B1B3B727CAD6A37ECD42EBC557765D94B83ADD438BD5AFA1F6F919D80AE755A8D98918981167B871F31AD42FDF5E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# focus.tcl --..#..# This file defines several procedures for managing the input..# focus...#..# Copyright (c) 1994-1995 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk_focusNext --..# This procedure returns the name of the next window after "w" in..# "focus order" (the window that should receive the focus next if..# Tab is typed in w). "Next" is defined by a pre-order search..# of a top-level and its non-top-level descendants, with the stacking..# order determining the order of siblings. The "-takefocus" options..# on windows determine whether or not they should be skipped...#..# Arguments:..# w -..Name of a window.....proc ::tk_focusNext w {.. set cur $w.. while {1} {.....# Descend to just before the first child of the current widget......set parent $cur...set children [winfo children $cur]...set i -1.....# Look for the next sibling that isn't a top-leve
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):18292
                                                                                                                                                                                                                                                          Entropy (8bit):4.724158138062491
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:NoRqdguMCeor/4VxgU80QNxWHKVozN5EaKdhsbyM:NoRqdguMCeor/4VxgUnQN0KSDEk
                                                                                                                                                                                                                                                          MD5:48B77259261D1B0BE6BA1253D55F93E3
                                                                                                                                                                                                                                                          SHA1:345BB0F09DF3DA9D87EDBF68E860A10C8819146D
                                                                                                                                                                                                                                                          SHA-256:901F70BB14A197495575D3BD2BF11E8654F9490E7E16D8DCA8057C5393FF2093
                                                                                                                                                                                                                                                          SHA-512:FAFF122ACF9510F51AE8C7731C9BDE817E58ECD914A6C17C944195E507071BCB0CE0BE70D86FB65C35B308B9615DE3AE352DE352FE175EAB46F3932FFDB8BBE0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# fontchooser.tcl -..#..#.A themeable Tk font selection dialog. See TIP #324...#..# Copyright (C) 2008 Keith Vetter..# Copyright (C) 2008 Pat Thoyts <patthoyts@users.sourceforge.net>..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....namespace eval ::tk::fontchooser {.. variable S.... set S(W) .__tk__fontchooser.. set S(fonts) [lsort -dictionary -unique [font families]].. set S(styles) [list \.. [::msgcat::mc Regular] \.. [::msgcat::mc Italic] \.. [::msgcat::mc Bold] \.. [::msgcat::mc {Bold Italic}] \.. ].. set S(sizes) {8 9 10 11 12 14 16 18 20 22 24 26 28 36 48 72}.. set S(strike) 0.. set S(under) 0.. set S(first) 1.. set S(-parent) ... set S(-title) {}.. set S(-command) "".. set S(-font) TkDefaultFont.. set S(bad) [list ]..}....proc ::tk::fontchooser::Canonical {} {.. variable S.... foreach style $S(styles
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):17456
                                                                                                                                                                                                                                                          Entropy (8bit):4.9606603722465135
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:FNP8nO9Wo8k5NfQH8EsOy8WMdtafNCvHshPOw7jW:FNf8uNfQH89Z8WMdA1vDW
                                                                                                                                                                                                                                                          MD5:F538719BB6B5B6CBE451A13DF9009B7D
                                                                                                                                                                                                                                                          SHA1:CBA1CFFCA6E78EB4B1701ABB4C73020D82163685
                                                                                                                                                                                                                                                          SHA-256:541647A1D4D91FFB8EE93D53B0017E5C3D3FA943373BB8490761D25B7A2CA330
                                                                                                                                                                                                                                                          SHA-512:AA5EBCB5364B2FE131317C471AE51F3F709CD1ED49AC843127739C211B9AFA690F011E89E397028A3BCC97EE04BAB91FB936D9A40C9246F125F9E8AC69795D1C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# iconlist.tcl..#..#.Implements the icon-list megawidget used in the "Tk" standard file..#.selection dialog boxes...#..# Copyright (c) 1994-1998 Sun Microsystems, Inc...# Copyright (c) 2009 Donal K. Fellows..#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES...#..# API Summary:..#.tk::IconList <path> ?<option> <value>? .....#.<path> add <imageName> <itemList>..#.<path> cget <option>..#.<path> configure ?<option>? ?<value>? .....#.<path> deleteall..#.<path> destroy..#.<path> get <itemIndex>..#.<path> index <index>..#.<path> invoke..#.<path> see <index>..#.<path> selection anchor ?<int>?..#.<path> selection clear <first> ?<last>?..#.<path> selection get..#.<path> selection includes <item>..#.<path> selection set <first> ?<last>?.....package require Tk....::tk::Megawidget create ::tk::IconList ::tk::FocusableWidget {.. variable w canvas sbar accel accelCB fill font index \...itemList itemsPerColumn list
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11037
                                                                                                                                                                                                                                                          Entropy (8bit):6.048349526382653
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:0nEPytJLl1S47T3YqN5/vkJpnhXqBB4aw2rqZiygTtYTpOq/pc75Mk:xqLz7F5KTqBBLuZ1gTSsqhk
                                                                                                                                                                                                                                                          MD5:995A0A8F7D0861C268AEAD5FC95A42EA
                                                                                                                                                                                                                                                          SHA1:21E121CF85E1C4984454237A646E58EC3C725A72
                                                                                                                                                                                                                                                          SHA-256:1264940E62B9A37967925418E9D0DC0BEFD369E8C181B9BAB3D1607E3CC14B85
                                                                                                                                                                                                                                                          SHA-512:DB7F5E0BC7D5C5F750E396E645F50A3E0CDE61C9E687ADD0A40D0C1AA304DDFBCEEB9F33AD201560C6E2B051F2EDED07B41C43D00F14EE435CDEEE73B56B93C7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# icons.tcl --..#..#.A set of stock icons for use in Tk dialogs. The icons used here..#.were provided by the Tango Desktop project which provides a..#.unified set of high quality icons licensed under the..#.Creative Commons Attribution Share-Alike license..#.(https://creativecommons.org/licenses/by-sa/3.0/)..#..#.See http://tango.freedesktop.org/Tango_Desktop_Project..#..# Copyright (c) 2009 Pat Thoyts <patthoyts@users.sourceforge.net>....namespace eval ::tk::icons {}....image create photo ::tk::icons::warning -data {.. iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAABHNCSVQICAgIfAhkiAAABSZJREFU.. WIXll1toVEcYgL+Zc87u2Yu7MYmrWRuTJuvdiMuqiJd4yYKXgMQKVkSjFR80kFIVJfWCWlvpg4h9.. 8sXGWGof8iKNICYSo6JgkCBEJRG8ImYThNrNxmaTeM7pQ5IlJkabi0/9YZhhZv7///4z/8zPgf+7.. KCNRLgdlJijXwRyuDTlcxV9hbzv8nQmxMjg+XDtiOEplkG9PSfkztGmTgmFQd+FCVzwa3fYN/PHZ.. AcpBaReicW5xcbb64IEQqko8Lc26d/58cxS+/BY6hmJvyEfQBoUpwWCmW1FErKaGWHU13uRk4QkE.. UtxQNFR7QwIoB4eiKD9PWbVKbb10CZmaCqmpxCormRYO26QQx85B0mcD+AeK0
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):329
                                                                                                                                                                                                                                                          Entropy (8bit):4.3973643486226655
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:nVxpJFBmHdeA1xNZgk0dIf3Ju4dFi6/XWrWhr3W7FxmVFraazmVAJFKyVQR7icr8:nj5Bqf1fZgp6A4FDG6dm7FUGAJVVMRmn
                                                                                                                                                                                                                                                          MD5:921245A21F7E783997DC7B859AF1B65B
                                                                                                                                                                                                                                                          SHA1:2EFE3C8F70CF18621006890BF21CC097770D140D
                                                                                                                                                                                                                                                          SHA-256:C6DB098EBD8A622164D37D4AB0A8C205DB1A83AC3065D5CDE3CB5FB61925D283
                                                                                                                                                                                                                                                          SHA-512:CAD823FF3D13A64C00825961E75B5133690556FB1F622834F8B1DF316A9E75BABB63B9F5148DAE7B1391123B4C8D55B4B8B2EB6F8E6E1DA9DE02A5BD7AC0FD6F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:README - images directory....This directory includes images for the Tcl Logo and the Tcl Powered..Logo. Please feel free to use the Tcl Powered Logo on any of your..products that employ the use of Tcl or Tk. The Tcl logo may also be..used to promote Tcl in your product documentation, web site or other..places you so desire...
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PostScript document text conforming DSC level 3.0, type EPS
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):34991
                                                                                                                                                                                                                                                          Entropy (8bit):5.248845410801251
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:0YrY6a0v4uIqYMEKjodQKOfRXMLcSqDGpfTKFVm3AsanMEDzzBHWzaw7XUbTJjoB:0YrY6aeIqYMEKjouzfRXMLcSqDGpfTKo
                                                                                                                                                                                                                                                          MD5:23C4EDED40DEC065F99E6653AEE1BB31
                                                                                                                                                                                                                                                          SHA1:3175E261BE198731DEDB07264CCB84C8DEDF7967
                                                                                                                                                                                                                                                          SHA-256:76207D8DFDE189A29DC0E76ADB7EAAA606B96BC6C1C831F34D1C85B1C5B51DD3
                                                                                                                                                                                                                                                          SHA-512:BA139A64BE72BB681040924C4294E2726BA5AB243E805E60A854D2D23E154705E2431D1AB2DE732BFA393747FD30D8A5C913895CBE1463DBF50CC23CAE5B0454
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:%!PS-Adobe-3.0 EPSF-3.0..%%Creator: Adobe Illustrator(TM) 5.5..%%For: (Bud Northern) (Mark Anderson Design)..%%Title: (TCL/TK LOGO.ILLUS)..%%CreationDate: (8/1/96) (4:58 PM)..%%BoundingBox: 251 331 371 512..%%HiResBoundingBox: 251.3386 331.5616 370.5213 511.775..%%DocumentProcessColors: Cyan Magenta Yellow..%%DocumentSuppliedResources: procset Adobe_level2_AI5 1.0 0..%%+ procset Adobe_IllustratorA_AI5 1.0 0..%AI5_FileFormat 1.2..%AI3_ColorUsage: Color..%%DocumentCustomColors: (TCL RED)..%%CMYKCustomColor: 0 0.45 1 0 (Orange)..%%+ 0 0.25 1 0 (Orange Yellow)..%%+ 0 0.79 0.91 0 (TCL RED)..%AI3_TemplateBox: 306 396 306 396..%AI3_TileBox: 12 12 600 780..%AI3_DocumentPreview: Macintosh_ColorPic..%AI5_ArtSize: 612 792..%AI5_RulerUnits: 0..%AI5_ArtFlags: 1 0 0 1 0 0 1 1 0..%AI5_TargetResolution: 800..%AI5_NumLayers: 1..%AI5_OpenToView: 90 576 2 938 673 18 1 1 2 40..%AI5_OpenViewLayers: 7..%%EndComments..%%BeginProlog..%%BeginResource: procset Adobe_level2_AI5 1.0 0..%%Title: (Adobe Illustrator
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 68 x 100
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2341
                                                                                                                                                                                                                                                          Entropy (8bit):6.9734417899888665
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:qF/mIXn3l7+ejbL/4nZEsKPKer1OPQqVRqJbPpRRKOv/UVO47f:81nHL4T0KorxvRKkc847f
                                                                                                                                                                                                                                                          MD5:FF04B357B7AB0A8B573C10C6DA945D6A
                                                                                                                                                                                                                                                          SHA1:BCB73D8AF2628463A1B955581999C77F09F805B8
                                                                                                                                                                                                                                                          SHA-256:72F6B34D3C8F424FF0A290A793FCFBF34FD5630A916CD02E0A5DDA0144B5957F
                                                                                                                                                                                                                                                          SHA-512:10DFE631C5FC24CF239D817EEFA14329946E26ED6BCFC1B517E2F9AF81807977428BA2539AAA653A89A372257D494E8136FD6ABBC4F727E6B199400DE05ACCD5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:GIF89aD.d...............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3.............f..3..........f.3...f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3.............f..3............f..3.............f..3....f..f.f..ff.f3.f..3..3.3..3f.33.3...........f..3...f..f..f..f.ff.3f..f..f..f.f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3.3.f3.33..3..3..3..3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...............w..U..D..".....................w..U..D..".....................w..U..D..".................wwwUUUDDD"""......,....D.d........H......*\...z..Ht@Q...92.p...z.$.@@.E..u.Y.2..0c..q.cB.,[..... ..1..qbM.2~*].....s...S.@.L.j..#..\......h..........].D(..m......@.Z....oO...3=.c...G".(..pL...q]..%....[...#...+...X.h....^.....
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 43 x 64
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1670
                                                                                                                                                                                                                                                          Entropy (8bit):6.326462043862671
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:PF/mIXn3l7+ejbL/4xsgq4sNC6JYp6s/pmp76F:/1nHL404raM/op2
                                                                                                                                                                                                                                                          MD5:B226CC3DA70AAB2EBB8DFFD0C953933D
                                                                                                                                                                                                                                                          SHA1:EA52219A37A140FD98AEA66EA54685DD8158D9B1
                                                                                                                                                                                                                                                          SHA-256:138C240382304F350383B02ED56C69103A9431C0544EB1EC5DCD7DEC7A555DD9
                                                                                                                                                                                                                                                          SHA-512:3D043F41B887D54CCADBF9E40E48D7FFF99B02B6FAF6B1DD0C6C6FEF0F8A17630252D371DE3C60D3EFBA80A974A0670AF3747E634C59BDFBC78544D878D498D4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:GIF89a+.@...............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3.............f..3..........f.3...f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3.............f..3............f..3.............f..3....f..f.f..ff.f3.f..3..3.3..3f.33.3...........f..3...f..f..f..f.ff.3f..f..f..f.f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3.3.f3.33..3..3..3..3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...............w..U..D..".....................w..U..D..".....................w..U..D..".................wwwUUUDDD"""......,....+.@........H. .z..(tp......@...92....#. A.......C.\.%...)Z..1a.8s..W/..@....3..C...y$.GW.....5.FU..j..;.F(Pc+W.-..X.D-[.*g....F..`.:mkT...Lw...A/.....u.7p..a..9P.....q2..Xg..G....3}AKv.\.d..yL.>..1.#
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 354 x 520
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11000
                                                                                                                                                                                                                                                          Entropy (8bit):7.88559092427108
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:d+nY6zludc/We/yXy9JHBUoIMSapQdrGlapzmyNMK1vbXkgMmgFW/KxIq3NhZe:YnY6p4c/OCHyowaGUaCcMK1vbXNwFW/l
                                                                                                                                                                                                                                                          MD5:45D9B00C4CF82CC53723B00D876B5E7E
                                                                                                                                                                                                                                                          SHA1:DDD10E798AF209EFCE022E97448E5EE11CEB5621
                                                                                                                                                                                                                                                          SHA-256:0F404764D07A6AE2EF9E1E0E8EAAC278B7D488D61CF1C084146F2F33B485F2ED
                                                                                                                                                                                                                                                          SHA-512:6E89DACF2077E1307DA05C16EF8FDE26E92566086346085BE10A7FD88658B9CDC87A3EC4D17504AF57D5967861B1652FA476B2DDD4D9C6BCFED9C60BB2B03B6F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:GIF89ab.................f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3.............f..3..........f.3...f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3.............f..3............f..3.............f..3....f..f.f..ff.f3.f..3..3.3..3f.33.3...........f..3...f..f..f..f.ff.3f..f..f..f.f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3.3.f3.33..3..3..3..3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...............w..U..D..".....................w..U..D..".....................w..U..D..".................wwwUUUDDD"""......,....b..........H......*\....#J.H....3j.... '.;p....(.8X..^.0c.I...z8O.\.....:....$..Fu<8`...P.>%I.gO.C.h-..+.`....@..h....dJ.?...K...H.,U.._.#...g..[.*^.x.....J.L.!.'........=+eZ..i..ynF.8...].y|..m.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:GIF image data, version 87a, 120 x 181
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3889
                                                                                                                                                                                                                                                          Entropy (8bit):7.425138719078912
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:9qqbIh+cE4C8ric/jxK5mxsFBu3/0GIJ6Qap1Y5uMiR8pw5rB/SgijDb+TOh:hy+mnZ7xK5IsTwDQmkdiiG5rB/BE+6h
                                                                                                                                                                                                                                                          MD5:BD12B645A9B0036A9C24298CD7A81E5A
                                                                                                                                                                                                                                                          SHA1:13488E4F28676F1E0CE383F80D13510F07198B99
                                                                                                                                                                                                                                                          SHA-256:4D0BD3228AB4CC3E5159F4337BE969EC7B7334E265C99B7633E3DAF3C3FCFB62
                                                                                                                                                                                                                                                          SHA-512:F62C996857CA6AD28C9C938E0F12106E0DF5A20D1B4B0B0D17F6294A112359BA82268961F2A054BD040B5FE4057F712206D02F2E668675BBCF6DA59A4DA0A1BB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:GIF87ax............................................................................z.....{..o.....m..b...`{.X....vy...hk.Um.N...I`.D..Z^.LP.?R.;!....?C.5C.3#.l..,6.*&.15...`..#(.If.y.....l...._..#/...Hm.>_.y..4R.k..#6..._......w..*K.^.."<.....G{.w..3_."C.Q..F....v..!K...v.2m.)_.[..!R.u.1t.g..)f. X.O..E..1z.g. _.Z..D..:..0..Z.. f.D..0..'z..m.N..C../.z.svC.q/.m.ze7.\..P..I..1%.,...............................................................................................................................................................................................................................................................................................................................................................................................,....x..........H.......D..!...7.PAQ...._l8.... C.<.a...*.x....0q.. ..M.%.<.HBe.@.....Q..7..XC..P..<z3..X...P.jA.%'@.J.lV.......R.,..+....t....7h.....(..a...+^.'..7..L.....V...s..$....a.....8`.9..}K......
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PostScript document text conforming DSC level 3.0, type EPS
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):29706
                                                                                                                                                                                                                                                          Entropy (8bit):5.33387357427899
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:0warY6a0v4uIqYMEKjodQKOfRtMLcSqDGpf88KFVmlhEtOI/eE7U0a1:03rY6aeIqYMEKjouzfRtMLcSqDGpfbKc
                                                                                                                                                                                                                                                          MD5:4AE11820D4D592D02CDE458E6F8CE518
                                                                                                                                                                                                                                                          SHA1:A2E8D3D6191B336D43E48A65C3AE6485B07D93C6
                                                                                                                                                                                                                                                          SHA-256:87FD9E46DBB5F2BF1529AFB411182C9FB9C58E23D830C66A233AF0C256BB8EFF
                                                                                                                                                                                                                                                          SHA-512:E0AD4ED570D414BF00931B0F5BBB61FEF981ABDB22ECC42F8E9841905D38874CDFE38F22EDB17ACD0F7539B2932F9C4A865FA73A49BB1458CE05EE10A78BE357
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:%!PS-Adobe-3.0 EPSF-3.0..%%Creator: Adobe Illustrator(TM) 5.5..%%For: (Bud Northern) (Mark Anderson Design)..%%Title: (TCL PWRD LOGO.ILLUS)..%%CreationDate: (8/1/96) (4:59 PM)..%%BoundingBox: 242 302 377 513..%%HiResBoundingBox: 242.0523 302.5199 376.3322 512.5323..%%DocumentProcessColors: Cyan Magenta Yellow..%%DocumentSuppliedResources: procset Adobe_level2_AI5 1.0 0..%%+ procset Adobe_IllustratorA_AI5 1.0 0..%AI5_FileFormat 1.2..%AI3_ColorUsage: Color..%%CMYKCustomColor: 0 0.45 1 0 (Orange)..%%+ 0 0.25 1 0 (Orange Yellow)..%%+ 0 0.79 0.91 0 (PANTONE Warm Red CV)..%%+ 0 0.79 0.91 0 (TCL RED)..%AI3_TemplateBox: 306 396 306 396..%AI3_TileBox: 12 12 600 780..%AI3_DocumentPreview: Macintosh_ColorPic..%AI5_ArtSize: 612 792..%AI5_RulerUnits: 0..%AI5_ArtFlags: 1 0 0 1 0 0 1 1 0..%AI5_TargetResolution: 800..%AI5_NumLayers: 1..%AI5_OpenToView: 102 564 2 938 673 18 1 1 2 40..%AI5_OpenViewLayers: 7..%%EndComments..%%BeginProlog..%%BeginResource: procset Adobe_level2_AI5 1.0 0..%%Title: (Adobe I
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 64 x 100
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1615
                                                                                                                                                                                                                                                          Entropy (8bit):7.461273815456419
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:aE45BzojC3r1WAQ+HT2gAdKhPFZ/ObchgB8:V5Gb1WN+yfcObmgW
                                                                                                                                                                                                                                                          MD5:DBFAE61191B9FADD4041F4637963D84F
                                                                                                                                                                                                                                                          SHA1:BD971E71AE805C2C2E51DD544D006E92363B6C0C
                                                                                                                                                                                                                                                          SHA-256:BCC0E6458249433E8CBA6C58122B7C0EFA9557CBC8FB5F9392EED5D2579FC70B
                                                                                                                                                                                                                                                          SHA-512:ACEAD81CC1102284ED7D9187398304F21B8287019EB98B0C4EC7398DD8B5BA8E7D19CAA891AA9E7C22017B73D734110096C8A7B41A070191223B5543C39E87AF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:GIF89a@.d.............................f.................f...ff.f3.f..33.3.........f..ff.f3.33.3.f..f..ff.ff.ffff3ff333f.3f.33.33f.3...................................................................!.. -dl-.!.......,....@.d....@.pH,..E.... ..(...H$..v..j....K....q..5L......^).3.Y7..r..u.v|g..om...\iHl..p...`G..\~....fn[q...P.g.Z.l....y...\.l......f.Z.g...%%....e...e...)....O.f..e. ....O..qf..%..(.H.u..]..&....#4.......@.).....u!.M..2. ..PJ..#..T..a.....P.Gi... <Hb....x..z.3.X.O..f.........].Bt..lB.Q.r...9pP....&...L. ..,`[.....E6.Q.....?.#L......|g........N....[.._........."4......b....G6.........m.zI].....I.@.......I.9...glew...2.B..c>./..2....x.....<...{...7;.....y.I.....4G.Qj0..7..%.W.V...?!..[...X..=..k.h..[Q<.....0.B....(P.x.,.......8O*Z.8P!.$....u.c..Ea!..eC....CB.. .H..E..#..C..E...z..&.Nu........c.0..#.T.M.U........l.p @..s.|..pf!..&.......8.#.8.....*..J>. .t..h6(........#..0.A...*!..)...x..u.Z....*%..H.....*.......`......|.....1.......&.....T*...f.l...
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 97 x 150
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2489
                                                                                                                                                                                                                                                          Entropy (8bit):7.708754027741608
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:/Ev7JJ+3uvz/Hwbcp7igaIwjBui7qFxIIOdJXcI+Ks:M9oWz/7pZAV7qPIImJXtXs
                                                                                                                                                                                                                                                          MD5:711F4E22670FC5798E4F84250C0D0EAA
                                                                                                                                                                                                                                                          SHA1:1A1582650E218B0BE6FFDEFFD64D27F4B9A9870F
                                                                                                                                                                                                                                                          SHA-256:5FC25C30AEE76477F1C4E922931CC806823DF059525583FF5705705D9E913C1C
                                                                                                                                                                                                                                                          SHA-512:220C36010208A87D0F674DA06D6F5B4D6101D196544ABCB4EE32378C46C781589DB1CE7C7DFE6471A8D8E388EE6A279DB237B18AF1EB9130FF9D0222578F1589
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:GIF89aa...............................f.................f...ff.f3.f..33.3............f..ff.f3.33.3.f..ff.ff.ffff3ff333f.3f.33.33f.3...................................................................!.. -dl-.!.......,....a......@.pH,...r.l:..TB.T..V..z..H.j..h...&.......t"....F...d..gN~Y...g....}..r....g.....o...g.......Y.w..W......N....Z....W....f...tL.~.f....New............W.M.r.........O.q........W-./i.*...`..z..F9.../9..-.......$6..G..S...........zB.,nw.64...e4.......HOt......f.....)..OX..C.eU.(.Qh.....T..<Q.Y.P.L.YxT....2........ji..3.^)zz..O.a..6 ...TZ........^...7.....>|P.....w$...k.ZF.\R.u....F.]Z.--(v+)[Y....=.!.W..+.]..]._.....&..../Ap...j...!..b.:...{.^.=.`...U.....@Hf..\?.(..Lq@.........0..L...a...&.!.....]#..]G \..q...A.H.X[...(.W......,...1a..B...W(.t.8.AdG.)..(P=...Uu.u..A.KM\...'r.R./.W..d2a.0..G...?...B......#H........1Q.0...R....%+...0.I..{.<......QV.tz'.yn.E.p..0i.I.g......L....%....K...A.l.ph.Q.1e...Z....g..2e...smU&d;.J..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 113 x 175
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2981
                                                                                                                                                                                                                                                          Entropy (8bit):7.758793907956808
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:AmEwM8ioQoHJQBTThKVI7G78NLL120GFBBFXJRxlu+BmO/5lNqm7Eq:B57QoHJQt4II8BZ+jxluZO/5lNqm7Eq
                                                                                                                                                                                                                                                          MD5:DA5FB10F4215E9A1F4B162257972F9F3
                                                                                                                                                                                                                                                          SHA1:8DB7FB453B79B8F2B4E67AC30A4BA5B5BDDEBD3B
                                                                                                                                                                                                                                                          SHA-256:62866E95501C436B329A15432355743C6EFD64A37CFB65BCECE465AB63ECF240
                                                                                                                                                                                                                                                          SHA-512:990CF306F04A536E4F92257A07DA2D120877C00573BD0F7B17466D74E797D827F6C127E2BEAADB734A529254595918C3A5F54FDBD859BC325A162C8CD8F6F5BE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:GIF89aq...............................f.................f...ff.f3.f..33.3............f..ff.f3.3f.33.3.f..ff.ff.ffff3ff333f.3f.33.33f.3................................................................!.. -dl-.!.......,....q......@.pH,...r.l:....A}H...v..R......D.VF..,%M....^.....fyzU.P..f...i.....t..Uqe..N..Z..i......~....g......u.....g......\...h.....P...h.....Q..g....Z..h......]......\...M...[..s...c2.+R.$. ......#.....)v..4....MO.b.....9......[.M.........h'..<-..=.....HQD....D?.~......W7. ..V.W0..l....*0p}..KP?c.\@KW.S(..M..B.....-q...S2...*.,..P.{....F..._MAn ....i.Y3............zh.y.j@...a876...ui.i..;K.........p...`.,}w....tv.m...Y..........;.;.e).e&.......-.NC.*4..(........*..F........[,w....f......E....h..a3.T.^.........)...C.N8.h\T...+&.z....g]H..B..#.t6..Z.....j.-..N......TI....A........M?..Q&V'...Mb.f.x...h.$r.U .9..Ci. ].4.Zb..@...X....%..<..b)V!........Y)x......T.....h.p.d..h..(........]@.**J.M.U.Jf...Y.:....F..g:..d..6q.-..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 130 x 200
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3491
                                                                                                                                                                                                                                                          Entropy (8bit):7.790611381196208
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:ROGuxkQ9mcV7RXcECEtqCa+6GK8WseNXhewFIp9ZmL4u:ROGwpVOEbqCrWsUhtIk4u
                                                                                                                                                                                                                                                          MD5:A5E4284D75C457F7A33587E7CE0D1D99
                                                                                                                                                                                                                                                          SHA1:FA98A0FD8910DF2EFB14EDAEC038B4E391FEAB3C
                                                                                                                                                                                                                                                          SHA-256:BAD9116386343F4A4C394BDB87146E49F674F687D52BB847BD9E8198FDA382CC
                                                                                                                                                                                                                                                          SHA-512:4448664925D1C1D9269567905D044BBA48163745646344E08203FCEF5BA1524BA7E03A8903A53DAF7D73FE0D9D820CC9063D4DA2AA1E08EFBF58524B1D69D359
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:GIF89a................................f.................f...ff.f3.f..33.3............f..ff.3f.33.3.f..ff.ff.ffff3ff333f.3f.33.33f.3...................................................................!.. -dl-.!.......,...........@.pH,...r.l:..T..F$XIe..V$.x..V.Z.z..F.pxd~..........{....o....l..{.b...hi[}P.k...y.....y.f.._R.\...............m.....y.....x......^.Q...j.....\S.....^.......l......]...[.......).....{....7...`..<...`..">..i.?/..@............>..Z.z@....0B..r...j.V.I.@..;%R...*...J.p.A.t.*..$A*...>`.....@g5BP.A..p.x.............q..8...... ...(.Q..#..@...F..YSK..M..#o.....D.m..-.....k}...BT..V......'.....`.d..~;..9+..6...<b.eZ..y^0]0..I...=.6.....}.0<.Z...M...Y1*35.e.....b...U0F~.-.HT......l2.s.q`-....y...e....dPZ....~.zT.M.... "r.E/k. ...*..Lj@'........Pcd&.(..mxF_w.."K..x!..--Y`..A.....Be.jH.A..\..j.....du#.....]^...>......].i.FMO..].9n1",Y...F...EW.9.....0TY.T...Cv!i`%...Hz@.]..U.!Y...#Dv&pi.z(.mn.A....@Q.0.%...&.4.v.cw(.`cd'|..M9..."...,*.......
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 48 x 75
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1171
                                                                                                                                                                                                                                                          Entropy (8bit):7.289201491091023
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:DOfHIzP8hqiF+oyPOmp3XHhPBlMVvG0ffWLpfc:DGoPM+o0OmZXHhOv5WRc
                                                                                                                                                                                                                                                          MD5:7013CFC23ED23BFF3BDA4952266FA7F4
                                                                                                                                                                                                                                                          SHA1:E5B1DED49095332236439538ECD9DD0B1FD4934B
                                                                                                                                                                                                                                                          SHA-256:462A8FF8FD051A8100E8C6C086F497E4056ACE5B20B44791F4AAB964B010A448
                                                                                                                                                                                                                                                          SHA-512:A887A5EC33B82E4DE412564E86632D9A984E8498F02D8FE081CC4AC091A68DF6CC1A82F4BF99906CFB6EA9D0EF47ADAC2D1B0778DCB997FB24E62FC7A6D77D41
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:GIF89a0.K.............................f.................f...ff.f3.f..33.3.........f..ff.f3.3f.33.3.f..ff.ff.f3ff333f.3f.33.33f.3......................................................................!.. -dl-.!.......,....0.K....@.pH,...GD.<:..%SR.Z......<.V.$l.....z......:.. .|v[D..f...z.W.G.Vr...NgsU.yl..qU..`.......`fe`.......Fg....(.&...g.Y.. .."..q.V.$.'.Ez.W....y...Y.U...(#Xrf.........Xux.U..........(U.4...X....G.B..t..1S...R..Y. ...l ..".>.h......,%K....A.....<s....#..8.iK.....a.y$h..DQh.PE)....6.....MyL.qzF..... ."..Y0..a......2..*t..Ma..b...M..R.....\..st..=....Q......,>s`....Qt.,..B.R.....!.$..%.....(...s...B.T...`,".h(. D....8..dC..\Q.p.......x.#A.....:..du..(D.XV......7....S.#n8a....2`...f.:G,...==(......`!..$...t....b..../N|...f..J.x... P&.|.d._!N...].1w.3D.0!....@o&H...N.B.J....pz8..w.i....=r.............@5.-!.......H."..[.j.AB<..p....h...V.D..6.h...ab1F.g...I !.V~.H..V.........:.G..|c...,.....TD5..c[.W.....LC.....FJ..71[..lH.M.....8.:$......
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 100 x 100
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5473
                                                                                                                                                                                                                                                          Entropy (8bit):7.754239979431754
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:+EqG96vSGfyJZ26G6U1LI7nTD2enhjc+2VBnOqcUERVIim:+46KcyJI6G6uU7/LhjlkhQR7m
                                                                                                                                                                                                                                                          MD5:048AFE69735F6974D2CA7384B879820C
                                                                                                                                                                                                                                                          SHA1:267A9520C4390221DCE50177E789A4EBD590F484
                                                                                                                                                                                                                                                          SHA-256:E538F8F4934CA6E1CE29416D292171F28E67DA6C72ED9D236BA42F37445EA41E
                                                                                                                                                                                                                                                          SHA-512:201DA67A52DADA3AE7C533DE49D3C08A9465F7AA12317A0AE90A8C9C04AA69A85EC00AF2D0069023CD255DDA8768977C03C73516E4848376250E8D0D53D232CB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:GIF89ad.d...................RJJ...B99.......RBB..B11ZBB!....R991!!...)....{{B!!R)).JJ.ss.ZZ.BB.kk.RR.JJ.BB9...JJR!!.ZZ.BB.11.99.{s.sk.kc.cZ.ZR.JB.ZR.JB.JB.RJ.B9.91.B9...{.JB.91.B9.B9.1){)!.)!.9)..ZR.JB{91.cR{1).ZJ.ZJ.RB.J9.B1.B1.9).1!....{B9.{k.scc1).kZZ)!c)!.9).B1.9).9).1!.1!.1!.B).9!.9!.1..).....{.sZ1)R)!.B1.B1.ZBR!..9).ZB.9).R9.R9.1!.J1.J1.B).B).9!.9!.1..1..).....sZ.J9.ZB.cJJ!.{1!.B).9!{)..9!.J).B!.B!.9..R1).kJ)!.B1{9).R9.cB.Z9.Z9.B).Z9.B).R1.9!.R1.J).J).B!.1..9....{.s.J9.{Z.ZB.sR.kJk1!.cB.cB.R1.R).1..B!.J!.B.....R91.J1).c.kJ.J).Z1.B!.B!..9!..{R.sJ.Z9.R1{9!..s.R9.Z...J91Z9){B)...............B91..1)!..............................RJR............B)1......R19........BJ.9B..{..s{......!.......,....d.d.@............0@PHa....*.p...7.8.y...C.s6Z.%Q.#s.`:B.N....4jd.K.0..|y....F@.......1~ ......'Y.B"C&R.V.R.4$k.3...D.......Ef*Y3..M........BDV._.....\..).]..>s..$H\%y0WL...d.......D..'..v..1Kz.Zp$;S
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2307
                                                                                                                                                                                                                                                          Entropy (8bit):5.135743409565932
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:XU/zAcKT6yOCaDBfsHLk32s3J5w83KDyP1BXy3JQz7yuC:XNc+92sg3A8uyDXy3JQnDC
                                                                                                                                                                                                                                                          MD5:F090D9B312C16489289FD39813412164
                                                                                                                                                                                                                                                          SHA1:1BEC6668F6549771DADC67D153B89B8F77DCD4B9
                                                                                                                                                                                                                                                          SHA-256:0D1E4405F6273F091732764ED89B57066BE63CE64869BE6C71EA337DC4F2F9B5
                                                                                                                                                                                                                                                          SHA-512:57B323589C5A8D9CBB224416731D8CE65C4B94146DF15CE30885DF63B1D0B3F709093B65390A911F84F20B7C5DE3C0AF9B4D7D531742BE046EDA6E8C3432EF6E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:This software is copyrighted by the Regents of the University of..California, Sun Microsystems, Inc., Scriptics Corporation, ActiveState..Corporation, Apple Inc. and other parties. The following terms apply to..all files associated with the software unless explicitly disclaimed in..individual files.....The authors hereby grant permission to use, copy, modify, distribute,..and license this software and its documentation for any purpose, provided..that existing copyright notices are retained in all copies and that this..notice is included verbatim in any distributions. No written agreement,..license, or royalty fee is required for any of the authorized uses...Modifications to this software may be copyrighted by their authors..and need not follow the licensing terms described here, provided that..the new terms are clearly indicated on the first page of each file where..they apply.....IN NO EVENT SHALL THE AUTHORS OR DISTRIBUTORS BE LIABLE TO ANY PARTY..FOR DIRECT, INDIRECT, SPECIAL, INCI
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):15255
                                                                                                                                                                                                                                                          Entropy (8bit):4.9510475386072095
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:apDYV5Yupn5OcckwBv3HCpg2J8JvJBfWeZhXkz+WkHGowv:aPPkevB2JuvJ9D3XmSc
                                                                                                                                                                                                                                                          MD5:804E6DCE549B2E541986C0CE9E75E2D1
                                                                                                                                                                                                                                                          SHA1:C44EE09421F127CF7F4070A9508F22709D06D043
                                                                                                                                                                                                                                                          SHA-256:47C75F9F8348BF8F2C086C57B97B73741218100CA38D10B8ABDF2051C95B9801
                                                                                                                                                                                                                                                          SHA-512:029426C4F659848772E6BB1D8182EB03D2B43ADF68FCFCC1EA1C2CC7C883685DEDA3FFFDA7E071912B9BDA616AD7AF2E1CB48CE359700C1A22E1E53E81CAE34B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# listbox.tcl --..#..# This file defines the default bindings for Tk listbox widgets..# and provides procedures that help in implementing those bindings...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994-1995 Sun Microsystems, Inc...# Copyright (c) 1998 by Scriptics Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....#--------------------------------------------------------------------------..# tk::Priv elements used in this file:..#..# afterId -..Token returned by "after" for autoscanning...# listboxPrev -.The last element to be selected or deselected..#...during a selection operation...# listboxSelection -.All of the items that were selected before the..#...current selection operation (such as a mouse..#...drag) started; used to cancel an operation...#--------------------------------------------------------------------------....#--------------
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9862
                                                                                                                                                                                                                                                          Entropy (8bit):4.786615174847384
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:mvEEVwjVwqOpOLbkVAg/vyKEZ25YbKZbwrmQ:mvEEVwJwpALPgnyx25YGZkr3
                                                                                                                                                                                                                                                          MD5:D83ED6AC2912900040530528A0237AB3
                                                                                                                                                                                                                                                          SHA1:2D18E42A8B96C3D71C1C6701010FDF75C1E6D5D8
                                                                                                                                                                                                                                                          SHA-256:848258B946C002E2696CA3815A1589C8120AF5CC41FBC11BBD9A3F5754CC21AF
                                                                                                                                                                                                                                                          SHA-512:00B4CD0D58029FC37820C163A4AE1DEAD22FB5C767BDC118659EACE26D449C362189611DFB3FAB1AC129FABFEC2CE853EA2C10D418FAE5AEB91DDC9330FF782D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# megawidget.tcl..#..#.Basic megawidget support classes. Experimental for any use other than..#.the ::tk::IconList megawdget, which is itself only designed for use in..#.the Unix file dialogs...#..# Copyright (c) 2009-2010 Donal K. Fellows..#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES...#....package require Tk.....::oo::class create ::tk::Megawidget {.. superclass ::oo::class.. method unknown {w args} {...if {[string match .* $w]} {... [self] create $w {*}$args... return $w...}...next $w {*}$args.. }.. unexport new unknown.. self method create {name superclasses body} {...next $name [list \....superclass ::tk::MegawidgetClass {*}$superclasses]\;$body.. }..}....::oo::class create ::tk::MegawidgetClass {.. variable w hull options IdleCallbacks.. constructor args {...# Extract the "widget name" from the object name...set w [namespace tail [self]].....# Configure things...
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):40215
                                                                                                                                                                                                                                                          Entropy (8bit):4.920242375381158
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:NKJsOtO4IzOQj4+Abqqzilh5QU4Vjj9eCcYyq4xYpKgnP:NKJsOtiOQEzilh5Glj9eCcYf4s
                                                                                                                                                                                                                                                          MD5:994CBD4038EEEF9991F7D6086904166F
                                                                                                                                                                                                                                                          SHA1:24C05D55E80DDC36FD207EEB7C0FA262573D67D2
                                                                                                                                                                                                                                                          SHA-256:AE4EE8400174C798337B9C60867CBC94F811B249EBE6DEA21EC6F960BCF5F8CB
                                                                                                                                                                                                                                                          SHA-512:D1A9C8C89025B305AF52F1510B3D4D2A3C556847D345844367FF34C89B917F1646DE81F08994EA1697F8F8526D9FD2602F9AC440B52097CAB5951901DBBD6EBD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# menu.tcl --..#..# This file defines the default bindings for Tk menus and menubuttons...# It also implements keyboard traversal of menus and implements a few..# other utility procedures related to menus...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 1998-1999 Scriptics Corporation...# Copyright (c) 2007 Daniel A. Steffen <das@users.sourceforge.net>..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of tk::Priv that are used in this file:..#..# cursor -..Saves the -cursor option for the posted menubutton...# focus -..Saves the focus during a menu selection operation...#...Focus gets restored here when the menu is unposted...# grabGlobal -..Used in conjunction with tk::Priv(oldGrab): if..#...tk::Priv(oldGrab) is non
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):30840
                                                                                                                                                                                                                                                          Entropy (8bit):5.142909056222569
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:+c4g8rSnBGzHsGK83Ch0x/0kmSq6O4+rNfPCpM2sEmqKys3pCJxi5dEaY:+c4g8OnBGzBK83Ch0x/0FSq6OnrGM2h3
                                                                                                                                                                                                                                                          MD5:983C7B78F1A0EBACAB8006D391A01FCD
                                                                                                                                                                                                                                                          SHA1:7EA37474EA039ED7A37BFDD7D76EAE673E666283
                                                                                                                                                                                                                                                          SHA-256:C5BDCA3ABA671F03DC4624AB5FD260490F5002491D6C619142CCF5A1A744528A
                                                                                                                                                                                                                                                          SHA-512:A006EF9B7213E572F6FC540D1512A52C52FEC44E3A07846DE09662AE32B7191C5CF639798531847B39E4076BF9DD6314B6F5373065C04F4FEF221185B39C3117
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# mkpsenc.tcl --..#..# This file generates the postscript prolog used by Tk.....namespace eval ::tk {.. # Creates Postscript encoding vector for ISO-8859-1 (could theoretically.. # handle any 8-bit encoding, but Tk never generates characters outside.. # ASCII)... #.. proc CreatePostscriptEncoding {} {...variable psglyphs...# Now check for known. Even if it is known, it can be other than we...# need. GhostScript seems to be happy with such approach...set result "\[\n"...for {set i 0} {$i<256} {incr i 8} {... for {set j 0} {$j<8} {incr j} {....set enc [encoding convertfrom "iso8859-1" \.....[format %c [expr {$i+$j}]]]....catch {.... set hexcode {}.... set hexcode [format %04X [scan $enc %c]]....}....if {[info exists psglyphs($hexcode)]} {.... append result "/$psglyphs($hexcode)"....} else {.... append result "/space"....}... }... append result "\n"...}...append result "\]"...return $result.. }.... # List of adobe glyph names. Converted from glyph
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:xbm image (32x, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):16786
                                                                                                                                                                                                                                                          Entropy (8bit):4.717927930017041
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:+haZOxBpK8uxGe4V88/wxY3Fxqipz4zz4zxxFzxT4OcErDxqdRRZeuC/Vj2CoopC:+hRWRG3FFjvsfCoopwITHzLHFHHAABs
                                                                                                                                                                                                                                                          MD5:217087AB6B2A8F9D7252E311D69C3769
                                                                                                                                                                                                                                                          SHA1:09AEB2BC5B7C7F4AB3DE4211D786C519AE0970F6
                                                                                                                                                                                                                                                          SHA-256:A07E3A3809CED3C6C9C1E171DCA5AD1F28357734CD41B2B9DD9F58085B3D2842
                                                                                                                                                                                                                                                          SHA-512:6E57633C924BFC16D380C014C20DD24D5727E70D4843FCEC4D7995B4DB21941EA8F2A5FD6E5386DF3364B6905D4D66B2B9595DC8FC70CFF40A2D49A92A1B6FBA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# msgbox.tcl --..#..#.Implements messageboxes for platforms that do not have native..#.messagebox support...#..# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# Ensure existence of ::tk::dialog namespace..#..namespace eval ::tk::dialog {}....image create bitmap ::tk::dialog::b1 -foreground black \..-data "#define b1_width 32\n#define b1_height 32..static unsigned char q1_bits[] = {.. 0x00, 0xf8, 0x1f, 0x00, 0x00, 0x07, 0xe0, 0x00, 0xc0, 0x00, 0x00, 0x03,.. 0x20, 0x00, 0x00, 0x04, 0x10, 0x00, 0x00, 0x08, 0x08, 0x00, 0x00, 0x10,.. 0x04, 0x00, 0x00, 0x20, 0x02, 0x00, 0x00, 0x40, 0x02, 0x00, 0x00, 0x40,.. 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80,.. 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80,.. 0x01, 0x00, 0x00, 0x80, 0x02, 0x00, 0x00, 0x40, 0x02, 0x00, 0x00, 0x40,.. 0x04, 0x00,
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4235
                                                                                                                                                                                                                                                          Entropy (8bit):4.789130604359491
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:nlw9Twd+j3gLhokqwX+hTnJgNanPNcgRhgP+5QPwJJENL:nlw9TjjwI3hTnJgNaRhgP75L
                                                                                                                                                                                                                                                          MD5:5A8B46B85DCCBF74E2B5B820E1A7B9D1
                                                                                                                                                                                                                                                          SHA1:980F4FC5BABA82BA0FE02F9BD03A23DF6D565BB1
                                                                                                                                                                                                                                                          SHA-256:4DFFBEEDBF0D66D84B13088016D1A782CEAAD4DED27BE1E38842F8969C0E533F
                                                                                                                                                                                                                                                          SHA-512:2D81FC06CF3C20E4F6314BD13AF81FDE38A9B06510584C84C6A0C8C36314F980F77D02BD8056E7EE5DE599A0620E0C0349124147334B9C141145270046B19D90
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset cs "&Abort" "&P\u0159eru\u0161it".. ::msgcat::mcset cs "&About..." "&O programu...".. ::msgcat::mcset cs "All Files" "V\u0161echny soubory".. ::msgcat::mcset cs "Application Error" "Chyba programu".. ::msgcat::mcset cs "Bold Italic".. ::msgcat::mcset cs "&Blue" "&Modr\341".. ::msgcat::mcset cs "Cancel" "Zru\u0161it".. ::msgcat::mcset cs "&Cancel" "&Zru\u0161it".. ::msgcat::mcset cs "Cannot change to the directory \"%1\$s\".\nPermission denied." "Nemohu zm\u011bnit atku\341ln\355 adres\341\u0159 na \"%1\$s\".\nP\u0159\355stup odm\355tnut.".. ::msgcat::mcset cs "Choose Directory" "V\375b\u011br adres\341\u0159e".. ::msgcat::mcset cs "Cl&ear" "Sma&zat".. ::msgcat::mcset cs "&Clear Console" "&Smazat konzolu".. ::msgcat::mcset cs "Color" "Barva".. ::msgcat::mcset cs "Console" "Konzole".. ::msgcat::mcset cs "&Copy" "&Kop\355rovat".. ::msgcat::mcset cs "Cu&t" "V&y\u0159\355znout".. ::msgcat::mcset cs "&
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3987
                                                                                                                                                                                                                                                          Entropy (8bit):4.651948695787255
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:nRZ2uDMr05sIEzs2KkrT+XuTKN0FjDDP9:nRZzDy4kBKkrT+QpP9
                                                                                                                                                                                                                                                          MD5:227B0F255F854460E8E5146ED7A17B85
                                                                                                                                                                                                                                                          SHA1:99A080CAD631F21963C51A5B254BDAD3724DC866
                                                                                                                                                                                                                                                          SHA-256:FEEF8F8AD33BB3362C845A25D6ED273C398051047D899B31790474614C7AFD2D
                                                                                                                                                                                                                                                          SHA-512:36A4B48831316CC29686CC76DA00110EB078EC56F55A960D11AE427AA3D913C340C1E3805BF2AD40C1A8A92FC6587DA5D2C245E7501289FC3E228BE14FE49598
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset da "&Abort" "&Afbryd".. ::msgcat::mcset da "&About..." "&Om...".. ::msgcat::mcset da "All Files" "Alle filer".. ::msgcat::mcset da "Application Error" "Programfejl".. ::msgcat::mcset da "&Blue" "&Bl\u00E5".. ::msgcat::mcset da "Cancel" "Annuller".. ::msgcat::mcset da "&Cancel" "&Annuller".. ::msgcat::mcset da "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan ikke skifte til katalog \"%1\$s\".\nIngen rettigheder.".. ::msgcat::mcset da "Choose Directory" "V\u00E6lg katalog".. ::msgcat::mcset da "Cl&ear" "&Ryd".. ::msgcat::mcset da "&Clear Console" "&Ryd konsolen".. ::msgcat::mcset da "Color" "Farve".. ::msgcat::mcset da "Console" "Konsol".. ::msgcat::mcset da "&Copy" "&Kopier".. ::msgcat::mcset da "Cu&t" "Kli&p".. ::msgcat::mcset da "&Delete" "&Slet".. ::msgcat::mcset da "Details >>" "Detailer".. ::msgcat::mcset da "Directory \"%1\$s\" does not exist." "Katalog \"%1\$s\" finde
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4914
                                                                                                                                                                                                                                                          Entropy (8bit):4.6221938909259475
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:nxLEpatioUqGBLbz4ME/XKKVN9R7S/0oYr9:epY3MkXKKxRu2r9
                                                                                                                                                                                                                                                          MD5:2203F65BCDA61BC15AEAC4F868C6D94A
                                                                                                                                                                                                                                                          SHA1:C4CC3975679D23892406E4E8971359A0775B1B86
                                                                                                                                                                                                                                                          SHA-256:C0F574B14068A049E93421C73873D750C98DE28B7B77AA42FE72CBE0270A4186
                                                                                                                                                                                                                                                          SHA-512:79F134FDAD3B12524D43BF9F59D3C04CAE30A95F591A51B82C8DF7CC8563BEA5D464AEECC457D9F60C04365E30459C447ED537AFC832BA25E1815DE06C2B81E5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset de "&Abort" "&Abbruch".. ::msgcat::mcset de "&About..." "&\u00dcber...".. ::msgcat::mcset de "All Files" "Alle Dateien".. ::msgcat::mcset de "Application Error" "Applikationsfehler".. ::msgcat::mcset de "&Apply" "&Anwenden".. ::msgcat::mcset de "Bold" "Fett".. ::msgcat::mcset de "Bold Italic" "Fett kursiv".. ::msgcat::mcset de "&Blue" "&Blau".. ::msgcat::mcset de "Cancel" "Abbruch".. ::msgcat::mcset de "&Cancel" "&Abbruch".. ::msgcat::mcset de "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kann nicht in das Verzeichnis \"%1\$s\" wechseln.\nKeine Rechte vorhanden.".. ::msgcat::mcset de "Choose Directory" "W\u00e4hle Verzeichnis".. ::msgcat::mcset de "Cl&ear" "&R\u00fccksetzen".. ::msgcat::mcset de "&Clear Console" "&Konsole l\u00f6schen".. ::msgcat::mcset de "Color" "Farbe".. ::msgcat::mcset de "Console" "Konsole".. ::msgcat::mcset de "&Copy" "&Kopieren".. ::msgcat::mcset de "
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (355), with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8784
                                                                                                                                                                                                                                                          Entropy (8bit):4.334043617395095
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:tVj/F+oxBHbkI8+xTqFt2zPJ0k63fRGIUvPXrfBNnzc+zIF7meUOT7GC8MO07S0g:fj9+AHlLoozHn7fBFrMVmehCAGb
                                                                                                                                                                                                                                                          MD5:780F863903BBDAA6C371EC0D3C7E6D59
                                                                                                                                                                                                                                                          SHA1:DF5D435E132BEE4C076A7FC577C8C275A8B68CD5
                                                                                                                                                                                                                                                          SHA-256:3F6F155864FE59A341BFD869735E54DD21CEE21BBD038433D9B271AD77BA3F7E
                                                                                                                                                                                                                                                          SHA-512:091965EE912513AE1943BE840A2E757188FBA6F760F7C47BE80D06313D59B051F183E3A29D4B1CEDE1F9E54CA3CA23D75FF2C3A3672A4E71FB56F0FA76F7FA0D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:## Messages for the Greek (Hellenic - "el") language...## Please report any changes/suggestions to:..## petasis@iit.demokritos.gr....namespace eval ::tk {.. ::msgcat::mcset el "&Abort" "\u03a4\u03b5\u03c1\u03bc\u03b1\u03c4\u03b9\u03c3\u03bc\u03cc\u03c2".. ::msgcat::mcset el "About..." "\u03a3\u03c7\u03b5\u03c4\u03b9\u03ba\u03ac...".. ::msgcat::mcset el "All Files" "\u038c\u03bb\u03b1 \u03c4\u03b1 \u0391\u03c1\u03c7\u03b5\u03af\u03b1".. ::msgcat::mcset el "Application Error" "\u039b\u03ac\u03b8\u03bf\u03c2 \u0395\u03c6\u03b1\u03c1\u03bc\u03bf\u03b3\u03ae\u03c2".. ::msgcat::mcset el "&Blue" "\u039c\u03c0\u03bb\u03b5".. ::msgcat::mcset el "&Cancel" "\u0391\u03ba\u03cd\u03c1\u03c9\u03c3\u03b7".. ::msgcat::mcset el \.."Cannot change to the directory \"%1\$s\".\nPermission denied." \.."\u0394\u03b5\u03bd \u03b5\u03af\u03bd\u03b1\u03b9 \u03b4\u03c5\u03bd\u03b1\u03c4\u03ae \u03b7 \u03b1\u03bb\u03bb\u03b1\u03b3\u
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3377
                                                                                                                                                                                                                                                          Entropy (8bit):4.279601088621442
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:sQ7dw5bO0V3gqmCNyoKJ6iwp/uvENv4SKEcET2hsHFjr:n7dwNOc3RmOKJQcvEl4SK1ET2hYFjr
                                                                                                                                                                                                                                                          MD5:D48CFC9EC779085E8F6AAA7B1C40C89A
                                                                                                                                                                                                                                                          SHA1:0CF6253BFF39F40CA0991F9B06D3394BFEA21ED2
                                                                                                                                                                                                                                                          SHA-256:4A33B44B2E220E28EAAE7FAC407CAFE43D97C270DA58FA5F3B699A1760BFB2A4
                                                                                                                                                                                                                                                          SHA-512:C00EC0CFB48ABE621EF625C51952BCF177CE3BC7F0DEC5276EF84C9A97C7E014806B106EA8DEE202C43F8DD54ED7261A8D899E3EE12E3F37A90C387D864463AE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset en "&Abort".. ::msgcat::mcset en "&About...".. ::msgcat::mcset en "All Files".. ::msgcat::mcset en "Application Error".. ::msgcat::mcset en "&Apply".. ::msgcat::mcset en "Bold".. ::msgcat::mcset en "Bold Italic".. ::msgcat::mcset en "&Blue".. ::msgcat::mcset en "Cancel".. ::msgcat::mcset en "&Cancel".. ::msgcat::mcset en "Cannot change to the directory \"%1\$s\".\nPermission denied.".. ::msgcat::mcset en "Choose Directory".. ::msgcat::mcset en "Cl&ear".. ::msgcat::mcset en "&Clear Console".. ::msgcat::mcset en "Color".. ::msgcat::mcset en "Console".. ::msgcat::mcset en "&Copy".. ::msgcat::mcset en "Cu&t".. ::msgcat::mcset en "&Delete".. ::msgcat::mcset en "Details >>".. ::msgcat::mcset en "Directory \"%1\$s\" does not exist.".. ::msgcat::mcset en "&Directory:".. ::msgcat::mcset en "&Edit".. ::msgcat::mcset en "Effects".. ::msgcat::mcset en "Error: %1\$s".. ::msgcat::mcs
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):66
                                                                                                                                                                                                                                                          Entropy (8bit):4.262228832346611
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:fEGp6fRyv//mGoW8vMKEQXyVn:sooyv//xoQOOn
                                                                                                                                                                                                                                                          MD5:3D41FC47CD9936F817EF9645D73A77ED
                                                                                                                                                                                                                                                          SHA1:E62BBE094B71CAF4A389DE3ECD84D2EEFBA33827
                                                                                                                                                                                                                                                          SHA-256:01238293356E82F1D298896491F8B299BB7DC9C34F299C9E756254C736DA612B
                                                                                                                                                                                                                                                          SHA-512:B92582C32C4D7CD9DE6571CBB6B93DD693A8B5A80645468E2D02B80C339BE2B95D5B4878A0DA9AFFE9E2F98A6C38AAE9CC1FF2440146D0ED128FE8C9A92EECDB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset en_gb Color Colour..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4035
                                                                                                                                                                                                                                                          Entropy (8bit):4.614759526381991
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:n6oXunu4/LQmI+nl0WemQ+uISIKk/2nibN5My/uXcFSZHBohy:n6oXuu4jJtlPemVuISIKkuniJS1Gy
                                                                                                                                                                                                                                                          MD5:3704A08985B0AA3C521FDF9C2DA59D97
                                                                                                                                                                                                                                                          SHA1:3F1E42C5697504B4DEE1EE314CD361B4203BF686
                                                                                                                                                                                                                                                          SHA-256:84B117857674A2426290946053A61316C5C8C6808F2C6EDF0ECC5C4A9C5C72AC
                                                                                                                                                                                                                                                          SHA-512:99FE97B10B1CA59DDA0385161E7C05F7D22424B6B1FB844138921EF94B2E9809D73EBC0062897D0DDE040CF92C96A6E4916CC9F3F02442AE2C4162858434B6BA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset eo "&Abort" "&\u0108esigu".. ::msgcat::mcset eo "&About..." "Pri...".. ::msgcat::mcset eo "All Files" "\u0108iuj dosieroj".. ::msgcat::mcset eo "Application Error" "Aplikoeraro".. ::msgcat::mcset eo "&Blue" "&Blua".. ::msgcat::mcset eo "Cancel" "Rezignu".. ::msgcat::mcset eo "&Cancel" "&Rezignu".. ::msgcat::mcset eo "Cannot change to the directory \"%1\$s\".\nPermission denied." "Neeble \u015dan\u011di al dosierujo \"%1\$s\".\nVi ne rajtas tion.".. ::msgcat::mcset eo "Choose Directory" "Elektu Dosierujon".. ::msgcat::mcset eo "Cl&ear" "&Vakigu".. ::msgcat::mcset eo "&Clear Console" "&Vakigu konzolon".. ::msgcat::mcset eo "Color" "Koloro".. ::msgcat::mcset eo "Console" "Konzolo".. ::msgcat::mcset eo "&Copy" "&Kopiu".. ::msgcat::mcset eo "Cu&t" "&Eltondu".. ::msgcat::mcset eo "&Delete" "&Forigu".. ::msgcat::mcset eo "Details >>" "Detaloj >>".. ::msgcat::mcset eo "Directory \"%1\$s\" does not exi
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4024
                                                                                                                                                                                                                                                          Entropy (8bit):4.536517819515934
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:nN0T1Lt8ZYSih/aiik148aFscyTzoixccUTqjcg60Dx/H5:nN0BLSQUXy/o8re055
                                                                                                                                                                                                                                                          MD5:4765F3C055742530E4644771EBC6C69F
                                                                                                                                                                                                                                                          SHA1:8BEA722AC00522DEAA5B380AEEF4CA57D7A271BD
                                                                                                                                                                                                                                                          SHA-256:D2842B80F1B521EFF2D2656A69274B5F2A8F4F5831AF2E8EE73E3C37389F981F
                                                                                                                                                                                                                                                          SHA-512:9CA247F22797A1A1FCA42B5CDABF58262ED95EECDDD321CEB1440A60A4375923E0F511238F360D159EB5EED6F82CBBE0B8907A07CC77DB831BF97082932CD0FD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset es "&Abort" "&Abortar".. ::msgcat::mcset es "&About..." "&Acerca de ...".. ::msgcat::mcset es "All Files" "Todos los archivos".. ::msgcat::mcset es "Application Error" "Error de la aplicaci\u00f3n".. ::msgcat::mcset es "&Blue" "&Azul".. ::msgcat::mcset es "Cancel" "Cancelar".. ::msgcat::mcset es "&Cancel" "&Cancelar".. ::msgcat::mcset es "Cannot change to the directory \"%1\$s\".\nPermission denied." "No es posible acceder al directorio \"%1\$s\".\nPermiso denegado.".. ::msgcat::mcset es "Choose Directory" "Elegir directorio".. ::msgcat::mcset es "Cl&ear" "&Borrar".. ::msgcat::mcset es "&Clear Console" "&Borrar consola".. ::msgcat::mcset es "Color".. ::msgcat::mcset es "Console" "Consola".. ::msgcat::mcset es "&Copy" "&Copiar".. ::msgcat::mcset es "Cu&t" "Cor&tar".. ::msgcat::mcset es "&Delete" "&Borrar".. ::msgcat::mcset es "Details >>" "Detalles >>".. ::msgcat::mcset es "Directory \"%1\$s\"
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4693
                                                                                                                                                                                                                                                          Entropy (8bit):4.640083757706223
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:najdLGoC0TXwqTwPRNQXfdHzAIX169ZZv6CpvgIPJupuupw6kWVVxn6/9Yv:nWdLGo2WiMn4t5pvbxuPtx6F6
                                                                                                                                                                                                                                                          MD5:BD795A1D95446BEE7AEB16FB6E346271
                                                                                                                                                                                                                                                          SHA1:38469DBD386C35B90EBE0A0FE2CE9F1AB5A5444A
                                                                                                                                                                                                                                                          SHA-256:893BEDCDAED4602898D988E6248B8BB0857DD66C06194B45F31340CA03D82369
                                                                                                                                                                                                                                                          SHA-512:B9BDDECB1DE2025C6C4027BF6228A14D5F573F5859ED3444298809266F06E6203F72004D589314C6529A2E198039355B4FD6160F87DA8F97B55E9F841B6C3F5A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset fi "&Abort" "&Keskeyt\u00e4".. ::msgcat::mcset fi "&About..." "&Tietoja...".. ::msgcat::mcset fi "All Files" "Kaikki tiedostot".. ::msgcat::mcset fi "Application Error" "Ohjelmavirhe".. ::msgcat::mcset fi "&Apply" "K\u00e4&yt\u00e4".. ::msgcat::mcset fi "Bold" "Lihavoitu".. ::msgcat::mcset fi "Bold Italic" "Lihavoitu, kursivoitu".. ::msgcat::mcset fi "&Blue" "&Sininen".. ::msgcat::mcset fi "Cancel" "Peruuta".. ::msgcat::mcset fi "&Cancel" "&Peruuta".. ::msgcat::mcset fi "Cannot change to the directory \"%1\$s\".\nPermission denied." "Ei voitu vaihtaa hakemistoon \"%1\$s\".\nLupa ev\u00e4tty.".. ::msgcat::mcset fi "Choose Directory" "Valitse hakemisto".. ::msgcat::mcset fi "Cl&ear" "&Tyhjenn\u00e4".. ::msgcat::mcset fi "&Clear Console" "&Tyhjenn\u00e4 konsoli".. ::msgcat::mcset fi "Color" "V\u00e4ri".. ::msgcat::mcset fi "Console" "Konsoli".. ::msgcat::mcset fi "&Copy" "K&opioi".. ::msgcat::mcs
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3877
                                                                                                                                                                                                                                                          Entropy (8bit):4.630737553723335
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:nByEWs/3lHFB9FamsIfSAzZ2eaISAxh0BRc3jC:nByEWaRNzsSSWonMAv
                                                                                                                                                                                                                                                          MD5:E279E5FFF03E1B8E9063ABC8A499A6BD
                                                                                                                                                                                                                                                          SHA1:80910911F6B4830BA4DCBA9A9EAD12C9F802DDC9
                                                                                                                                                                                                                                                          SHA-256:3F2CEB4A33695AB6B56E27F61A4C60C029935BB026497D99CB2C246BCB4A63C4
                                                                                                                                                                                                                                                          SHA-512:8333388E421AC3F342317BEBE352809B0B190EF8B044A0BAE2FE4051974D86008BAFDCB7098E9DC39A8D9E1E08FB87F54B9D3388AF2D0185FF913DB6788C5AB5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset fr "&Abort" "&Annuler".. ::msgcat::mcset fr "About..." "\u00c0 propos...".. ::msgcat::mcset fr "All Files" "Tous les fichiers".. ::msgcat::mcset fr "Application Error" "Erreur d'application".. ::msgcat::mcset fr "&Blue" "&Bleu".. ::msgcat::mcset fr "Cancel" "Annuler".. ::msgcat::mcset fr "&Cancel" "&Annuler".. ::msgcat::mcset fr "Cannot change to the directory \"%1\$s\".\nPermission denied." "Impossible d'acc\u00e9der au r\u00e9pertoire \"%1\$s\".\nPermission refus\u00e9e.".. ::msgcat::mcset fr "Choose Directory" "Choisir r\u00e9pertoire".. ::msgcat::mcset fr "Cl&ear" "Effacer".. ::msgcat::mcset fr "Color" "Couleur".. ::msgcat::mcset fr "Console".. ::msgcat::mcset fr "Copy" "Copier".. ::msgcat::mcset fr "Cu&t" "Couper".. ::msgcat::mcset fr "Delete" "Effacer".. ::msgcat::mcset fr "Details >>" "D\u00e9tails >>".. ::msgcat::mcset fr "Directory \"%1\$s\" does not exist." "Le r\u00e9pertoire \"%1\$s\"
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4678
                                                                                                                                                                                                                                                          Entropy (8bit):4.7955991577265245
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:nkCEz2TTrKmA17fzq/Hj+pUva+fQR/a5a/Thn5kU:kTqM17u/8NiMrhb
                                                                                                                                                                                                                                                          MD5:4F1610E0C73DAE668E3F9D9235631152
                                                                                                                                                                                                                                                          SHA1:63EE54A6C1A69B798C65C999D5F80A7AB252B6D8
                                                                                                                                                                                                                                                          SHA-256:E063AD7CA93F37728A65E4CD7C0433950F22607D307949F6CB056446AFEAA4FE
                                                                                                                                                                                                                                                          SHA-512:37F4B8A9CD020A77591C09AF40FBC2FA82107B2596D31B5F30CE6ECAA225417CF7A5C62FB7A93539B0D7E930D0A44F9BF2EE6BE113F831B0A72B229444672AFD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset hu "&Abort" "&Megszak\u00edt\u00e1s".. ::msgcat::mcset hu "&About..." "N\u00e9vjegy...".. ::msgcat::mcset hu "All Files" "Minden f\u00e1jl".. ::msgcat::mcset hu "Application Error" "Alkalmaz\u00e1s hiba".. ::msgcat::mcset hu "&Blue" "&K\u00e9k".. ::msgcat::mcset hu "Cancel" "M\u00e9gsem".. ::msgcat::mcset hu "&Cancel" "M\u00e9g&sem".. ::msgcat::mcset hu "Cannot change to the directory \"%1\$s\".\nPermission denied." "A k\u00f6nyvt\u00e1rv\u00e1lt\u00e1s nem siker\u00fclt: \"%1\$s\".\nHozz\u00e1f\u00e9r\u00e9s megtagadva.".. ::msgcat::mcset hu "Choose Directory" "K\u00f6nyvt\u00e1r kiv\u00e1laszt\u00e1sa".. ::msgcat::mcset hu "Cl&ear" "T\u00f6rl\u00e9s".. ::msgcat::mcset hu "&Clear Console" "&T\u00f6rl\u00e9s Konzol".. ::msgcat::mcset hu "Color" "Sz\u00edn".. ::msgcat::mcset hu "Console" "Konzol".. ::msgcat::mcset hu "&Copy" "&M\u00e1sol\u00e1s".. ::msgcat::mcset hu "Cu&t" "&Kiv\u00e1g\u00e1s".. ::ms
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3765
                                                                                                                                                                                                                                                          Entropy (8bit):4.49679862548805
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:nmU4xnonTjwUE5Xs6ZrT8BpXAg+Wr+u92C8t7mU9nUSs:nZ4FonFE58HBpXjr+fBJs
                                                                                                                                                                                                                                                          MD5:B74C54666A5A431A782DB691B4CA3315
                                                                                                                                                                                                                                                          SHA1:2BC63982C14BBA8A4C451CE31540181F40CE2216
                                                                                                                                                                                                                                                          SHA-256:806930F283FD097195C7850E3486B3815D1564529B4F8E5FA6D26F3175183BC1
                                                                                                                                                                                                                                                          SHA-512:8120E2FFD14E0A992E254796ADDC0DC995C921BE31688C0995D7A36FE82609D78791FEF73EAF5B14E2F0D40AD256AB8DAAA07C18E6950362B28E40B71E47C0B6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset it "&Abort" "&Interrompi".. ::msgcat::mcset it "&About..." "Informazioni...".. ::msgcat::mcset it "All Files" "Tutti i file".. ::msgcat::mcset it "Application Error" "Errore dell' applicazione".. ::msgcat::mcset it "&Blue" "&Blu".. ::msgcat::mcset it "Cancel" "Annulla".. ::msgcat::mcset it "&Cancel" "&Annulla".. ::msgcat::mcset it "Cannot change to the directory \"%1\$s\".\nPermission denied." "Impossibile accedere alla directory \"%1\$s\".\nPermesso negato.".. ::msgcat::mcset it "Choose Directory" "Scegli una directory".. ::msgcat::mcset it "Cl&ear" "Azzera".. ::msgcat::mcset it "&Clear Console" "Azzera Console".. ::msgcat::mcset it "Color" "Colore".. ::msgcat::mcset it "Console".. ::msgcat::mcset it "&Copy" "Copia".. ::msgcat::mcset it "Cu&t" "Taglia".. ::msgcat::mcset it "Delete" "Cancella".. ::msgcat::mcset it "Details >>" "Dettagli >>".. ::msgcat::mcset it "Directory \"%1\$s\" does not ex
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4557
                                                                                                                                                                                                                                                          Entropy (8bit):4.524344068436489
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:nucQswBju0x0M4U2z9KSSOzZL5KhWTqGGIrlxXvhYbL/ZO5NT+T4kiLzzdDf1SDM:nLGa0x0Mp2KSHKSv2bL/ZO5u6nRfAXU9
                                                                                                                                                                                                                                                          MD5:E56229BAC5A8ABB90C4DD8EE3F9FF9F8
                                                                                                                                                                                                                                                          SHA1:7527D6C3C6C84BFF0E683FFA86A21C58458EB55D
                                                                                                                                                                                                                                                          SHA-256:0914FBA42361227D14FA281E8A9CBF57C16200B4DA1E61CC3402EF0113A512C7
                                                                                                                                                                                                                                                          SHA-512:13649DDB06DB4BA9E39BEAF828211086A519444DA9AB5CBDD1B88B29208388189A5141F75AD94B56A348EDDE534FFADE8B19B557CB988EA4ECC9A84B135D36C1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset nl "&Abort" "&Afbreken".. ::msgcat::mcset nl "&About..." "Over...".. ::msgcat::mcset nl "All Files" "Alle Bestanden".. ::msgcat::mcset nl "Application Error" "Toepassingsfout".. ::msgcat::mcset nl "&Apply" "Toepassen".. ::msgcat::mcset nl "Bold" "Vet".. ::msgcat::mcset nl "Bold Italic" "Vet Cursief".. ::msgcat::mcset nl "&Blue" "&Blauw".. ::msgcat::mcset nl "Cancel" "Annuleren".. ::msgcat::mcset nl "&Cancel" "&Annuleren".. ::msgcat::mcset nl "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan niet naar map \"%1\$s\" gaan.\nU heeft hiervoor geen toestemming.".. ::msgcat::mcset nl "Choose Directory" "Kies map".. ::msgcat::mcset nl "Cl&ear" "Wissen".. ::msgcat::mcset nl "&Clear Console" "&Wis Console".. ::msgcat::mcset nl "Color" "Kleur".. ::msgcat::mcset nl "Console".. ::msgcat::mcset nl "&Copy" "Kopi\u00ebren".. ::msgcat::mcset nl "Cu&t" "Knippen".. ::msgcat::mcset nl "&Dele
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4932
                                                                                                                                                                                                                                                          Entropy (8bit):4.799369674927008
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:nXra9E310fwNCeVsvSmy6MZv8lWBTDGdZ3tojTyrEQmAUCIx4wBxZ:n7a9Q0fyw5MQWgP3uoZChB3
                                                                                                                                                                                                                                                          MD5:8CFA2E38822303FDCB55AE3277F0B81B
                                                                                                                                                                                                                                                          SHA1:447F28A5064FCEA019C60B3F9B6D50CD43C2D0E3
                                                                                                                                                                                                                                                          SHA-256:EACEB1F08DE0863CCF726881E07FE5B135EA09646C5253E0CBF7DDB987EB0D92
                                                                                                                                                                                                                                                          SHA-512:E38BA9059AFF55C2B22A4AE24D6A76149C76DBA8BF8646AE81D6E07D7ED490D0605034B29D9AC848E6685C8EC26A3DBE5B2EAF462B14D96376E80076FBE7082A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset pl "&Abort" "&Przerwij".. ::msgcat::mcset pl "&About..." "O programie...".. ::msgcat::mcset pl "All Files" "Wszystkie pliki".. ::msgcat::mcset pl "Application Error" "B\u0142\u0105d w programie".. ::msgcat::mcset pl "&Apply" "Zastosuj".. ::msgcat::mcset pl "Bold" "Pogrubienie".. ::msgcat::mcset pl "Bold Italic" "Pogrubiona kursywa".. ::msgcat::mcset pl "&Blue" "&Niebieski".. ::msgcat::mcset pl "Cancel" "Anuluj".. ::msgcat::mcset pl "&Cancel" "&Anuluj".. ::msgcat::mcset pl "Cannot change to the directory \"%1\$s\".\nPermission denied." "Nie mo\u017cna otworzy\u0107 katalogu \"%1\$s\".\nOdmowa dost\u0119pu.".. ::msgcat::mcset pl "Choose Directory" "Wybierz katalog".. ::msgcat::mcset pl "Cl&ear" "&Wyczy\u015b\u0107".. ::msgcat::mcset pl "&Clear Console" "&Wyczy\u015b\u0107 konsol\u0119".. ::msgcat::mcset pl "Color" "Kolor".. ::msgcat::mcset pl "Console" "Konsola".. ::msgcat::mcset pl "&Copy" "&Kopiu
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3987
                                                                                                                                                                                                                                                          Entropy (8bit):4.63232183429232
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:nHOT1mM5qHHxiBHb3joTjtcp2UqMxweo6VvilCMKKXx9vjM:nHOT1mMQnwB/otcUUpGX6VPVoLjM
                                                                                                                                                                                                                                                          MD5:4018686F2A8E299D86BDB1478BC97896
                                                                                                                                                                                                                                                          SHA1:0EECE3D57F2EA5EECE8157B06F3AFB97E1F2551A
                                                                                                                                                                                                                                                          SHA-256:D687F71F0432BB0D02EFDF576E526D2C19D4136F76C41A3224A2F034168F3F34
                                                                                                                                                                                                                                                          SHA-512:4D730068B2A21E1D6004205B10A9D0D5EE9683FEB03B6FB673E8B9B94ED6BE468086A52DFE97C4DBF35A07CBB2C5E276DF0952A06C78E029D53D796CB6FCC8DF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset pt "&Abort" "&Abortar".. ::msgcat::mcset pt "About..." "Sobre ...".. ::msgcat::mcset pt "All Files" "Todos os arquivos".. ::msgcat::mcset pt "Application Error" "Erro de aplica\u00e7\u00e3o".. ::msgcat::mcset pt "&Blue" "&Azul".. ::msgcat::mcset pt "Cancel" "Cancelar".. ::msgcat::mcset pt "&Cancel" "&Cancelar".. ::msgcat::mcset pt "Cannot change to the directory \"%1\$s\".\nPermission denied." "N\u00e3o foi poss\u00edvel mudar para o diret\u00f3rio \"%1\$s\".\nPermiss\u00e3o negada.".. ::msgcat::mcset pt "Choose Directory" "Escolha um diret\u00f3rio".. ::msgcat::mcset pt "Cl&ear" "Apagar".. ::msgcat::mcset pt "&Clear Console" "Apagar Console".. ::msgcat::mcset pt "Color" "Cor".. ::msgcat::mcset pt "Console".. ::msgcat::mcset pt "&Copy" "Copiar".. ::msgcat::mcset pt "Cu&t" "Recortar".. ::msgcat::mcset pt "&Delete" "Excluir".. ::msgcat::mcset pt "Details >>" "Detalhes >>".. ::msgcat::mcset pt "D
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8620
                                                                                                                                                                                                                                                          Entropy (8bit):4.477728981060218
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:n9MEBGkFKT4YHCDhxqEMk0yOC2xXLtSRoxwKl9zFAWx2yuV9cDcwRjnWNQuNFNfO:T0rm8IONoRkN1w+jRQ/FoxrRHRJP
                                                                                                                                                                                                                                                          MD5:C69A904A57FDC95520086E9DDFED362C
                                                                                                                                                                                                                                                          SHA1:F0220602ABE91FE563E5AA6A4EA4AB43818C0CFC
                                                                                                                                                                                                                                                          SHA-256:F0D310A2EE9C0AF928D822CBB39BCBE54FB2C1C95EE8167DFFD55EDC1B2FE040
                                                                                                                                                                                                                                                          SHA-512:808B82F29B7BA06AF5AE44C6C23EC8DD743E93B391F060C7586D6D3FF26C97294BD11AD215848EBA422491BD50C4509330DD24C83134C7A384E81304133CAADB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset ru "&Abort" "&\u041e\u0442\u043c\u0435\u043d\u0438\u0442\u044c".. ::msgcat::mcset ru "&About..." "\u041f\u0440\u043e...".. ::msgcat::mcset ru "All Files" "\u0412\u0441\u0435 \u0444\u0430\u0439\u043b\u044b".. ::msgcat::mcset ru "Application Error" "\u041e\u0448\u0438\u0431\u043a\u0430 \u0432 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0435".. ::msgcat::mcset ru "&Apply" "&\u041f\u0440\u0438\u043c\u0435\u043d\u0438\u0442\u044c".. ::msgcat::mcset ru "Bold" "Bold".. ::msgcat::mcset ru "Bold Italic" "Bold Italic".. ::msgcat::mcset ru "&Blue" " &\u0413\u043e\u043b\u0443\u0431\u043e\u0439".. ::msgcat::mcset ru "Cancel" "\u041e\u0442\u043c\u0435\u043d\u0430".. ::msgcat::mcset ru "&Cancel" "\u041e\u0442&\u043c\u0435\u043d\u0430".. ::msgcat::mcset ru "Cannot change to the directory \"%1\$s\".\nPermission denied." \....."\u041d\u0435 \u043c\u043e\u0433\u0443 \u043f\u0435\u0440\u0435\u0439\u0442\u0438 \u0432 \u043a\u043
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3908
                                                                                                                                                                                                                                                          Entropy (8bit):4.658068191079967
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:nT8A5cbwKmtI1sE9xt6BDyepTr2iiK/yGqXZlBp9:nD5cb2extDepTCnVpJ9
                                                                                                                                                                                                                                                          MD5:1D085A672A6FCDECEF5D7D876E4C74A3
                                                                                                                                                                                                                                                          SHA1:1A40C03F15A6926359CA3E5C0A809485CAD28AEE
                                                                                                                                                                                                                                                          SHA-256:A6821A13D34FB31F1827294B82C4BF9586BB255CA14F78C3ACE11181F42EF211
                                                                                                                                                                                                                                                          SHA-512:981EDEEF5E4C915BB8F10044096B412D1855CAD08F98A448C6C0A49A54222945EBD102DDCB9525535E0FB19313C319155FA59384605B2C36CC8B4A58693D57E7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset sv "&Abort" "&Avsluta".. ::msgcat::mcset sv "&About..." "&Om...".. ::msgcat::mcset sv "All Files" "Samtliga filer".. ::msgcat::mcset sv "Application Error" "Programfel".. ::msgcat::mcset sv "&Blue" "&Bl\u00e5".. ::msgcat::mcset sv "Cancel" "Avbryt".. ::msgcat::mcset sv "&Cancel" "&Avbryt".. ::msgcat::mcset sv "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan ej n\u00e5 mappen \"%1\$s\".\nSaknar r\u00e4ttigheter.".. ::msgcat::mcset sv "Choose Directory" "V\u00e4lj mapp".. ::msgcat::mcset sv "Cl&ear" "&Radera".. ::msgcat::mcset sv "&Clear Console" "&Radera konsollen".. ::msgcat::mcset sv "Color" "F\u00e4rg".. ::msgcat::mcset sv "Console" "Konsoll".. ::msgcat::mcset sv "&Copy" "&Kopiera".. ::msgcat::mcset sv "Cu&t" "Klipp u&t".. ::msgcat::mcset sv "&Delete" "&Radera".. ::msgcat::mcset sv "Details >>" "Detaljer >>".. ::msgcat::mcset sv "Directory \"%1\$s\" does not exist." "Mapp
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4948
                                                                                                                                                                                                                                                          Entropy (8bit):5.318834981738548
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:nnIoT3wHqLHQslojYhOvZSVGNUpi6Z40qBAE9A+uiTrBsyqCgnPLz:nnIoT3wHU/osIAwNILi0HE2oV6CgPLz
                                                                                                                                                                                                                                                          MD5:3CB2966C9F24425075635FE24BE413FD
                                                                                                                                                                                                                                                          SHA1:87E9C83723AAE890E3582DFAB2BB059E6564E0A3
                                                                                                                                                                                                                                                          SHA-256:FD33A3408B054C297A9263B9B695CD629818BC9A882321AE8AC9E4C01AC07CC8
                                                                                                                                                                                                                                                          SHA-512:05C4970E6628934663334B5AC5749A55961D99517CF7FFBF262CD49AE2464DD9E6A52295735124266BD9CF055C506111E283B495F054E7EFDF17E392FB16261F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:namespace eval ::tk {.. ::msgcat::mcset zh_cn "&Abort" "&..".. ::msgcat::mcset zh_cn "&About..." "&....".. ::msgcat::mcset zh_cn "All Files" "....".. ::msgcat::mcset zh_cn "Application Error" "......".. ::msgcat::mcset zh_cn "&Apply" "&..".. ::msgcat::mcset zh_cn "Bold" "..".. ::msgcat::mcset zh_cn "Bold Italic" "....".. ::msgcat::mcset zh_cn "&Blue" "&..".. ::msgcat::mcset zh_cn "Cancel" "..".. ::msgcat::mcset zh_cn "&Cancel" "&..".. ::msgcat::mcset zh_cn "Cannot change to the directory \"%1\$s\".\nPermission denied." "...... \"%1\$s\".\n......".. ::msgcat::mcset zh_cn "Choose Directory" ".....".. ::msgcat::mcset zh_cn "Cl&ear" ".&.".. ::msgcat::mcset zh_cn "&Clear Console" "&....".. ::msgcat::mcset zh_cn "Color" "..".. ::msgcat::mcset zh_cn "Console" "..".. ::msgcat::mcset zh_cn "&Copy" "&..".. ::msgcat::mcset zh
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5772
                                                                                                                                                                                                                                                          Entropy (8bit):5.038729016734604
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:onzxtm7EMgdMjwPqeuAmz9LD1kFIQETZqoIK/RLf7w:ozxtm7qUwi79l0sZqoBJLDw
                                                                                                                                                                                                                                                          MD5:FC9E03823BEB08DAF7681C09D106DF7D
                                                                                                                                                                                                                                                          SHA1:7D06FC8F98140E0FFAA2571BD522FC772E58DE54
                                                                                                                                                                                                                                                          SHA-256:540EEECBA17207A56290BAFFDAE882BBD4F88364791204AD5D14C7BEDD022CCC
                                                                                                                                                                                                                                                          SHA-512:2B5BAD311A703A0FE2ED67ACE311BAD4C767BCD23DFC3D9ABDF5C3604146A6A15D6BD13A14BDEFCDB2B602C708AACFAB404E96FCBA7C546AD0DAECD4BE2EB34A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# obsolete.tcl --..#..# This file contains obsolete procedures that people really shouldn't..# be using anymore, but which are kept around for backward compatibility...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# The procedures below are here strictly for backward compatibility with..# Tk version 3.6 and earlier. The procedures are no longer needed, so..# they are no-ops. You should not use these procedures anymore, since..# they may be removed in some future release.....proc tk_menuBar args {}..proc tk_bindForTraversal args {}....# ::tk::classic::restore --..#..# Restore the pre-8.5 (Tk classic) look as the widget defaults for classic..# Tk widgets...#..# The value following an 'option add' call is the new 8.5 value...#..namespace eval ::tk::classic {.. # This may need t
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1629
                                                                                                                                                                                                                                                          Entropy (8bit):4.784780799273752
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:g2hBuOrlkBytcqYXRE5fvvXq1EhJPqOj6Wf0cVlN:gQ6q4E5HCqhBqOhcaD
                                                                                                                                                                                                                                                          MD5:9B7A8FD2C6B538FF31BDC380452C6DE3
                                                                                                                                                                                                                                                          SHA1:3F915BFE85CED9F6C7E9A352718770E9F14F098E
                                                                                                                                                                                                                                                          SHA-256:40CA505C9784B0767D4854485C5C311829594A4FCBDFD7251E60E6BB7EA74FD1
                                                                                                                                                                                                                                                          SHA-512:43937152B844BE1E597E99DA1270E54AB1D572AE89CB759E6D41C18C9C8044CCC15A6925F9C5AF617AE9EC1404E78C2733231F4D5C6CFE4D23C546387B1FC328
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# optMenu.tcl --..#..# This file defines the procedure tk_optionMenu, which creates..# an option button and its associated menu...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk_optionMenu --..# This procedure creates an option button named $w and an associated..# menu. Together they provide the functionality of Motif option menus:..# they can be used to select one of many values, and the current value..# appears in the global variable varName, as well as in the text of..# the option menubutton. The name of the menu is returned as the..# procedure's result, so that the caller can use it to change configuration..# options on the menu or otherwise manipulate it...#..# Arguments:..# w -...The name to use for the menubutton...# varName -..Global variable to hold the currently
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8418
                                                                                                                                                                                                                                                          Entropy (8bit):4.964814946573677
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:HWh/x+hFMyTA/CTzxFoUuliRLDm8pQrQlENPyF3o48M6C:HWL+MyTA/CTzvAiRqyEw3ok
                                                                                                                                                                                                                                                          MD5:4CE08A10CD9AE941654B8C679DF669F3
                                                                                                                                                                                                                                                          SHA1:F1288BABCA698FD18C3BD221E6AE6C02F2975AAE
                                                                                                                                                                                                                                                          SHA-256:849B4C57E4644E51BEAEAEB3AE59B7FF067E582ECD10F1B2CAF6B6E72F11F506
                                                                                                                                                                                                                                                          SHA-512:0F37539DA3540E9B1DA7B0377E3BBB359B71DB4271D63BC9501E95931B4E609E8CB91DC2F7B08A6452598D4A0D58C6A2034049A215000EEF0F93A9963D003632
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# palette.tcl --..#..# This file contains procedures that change the color palette used..# by Tk...#..# Copyright (c) 1995-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk_setPalette --..# Changes the default color scheme for a Tk application by setting..# default colors in the option database and by modifying all of the..# color options for existing widgets that have the default value...#..# Arguments:..# The arguments consist of either a single color name, which..# will be used as the new background color (all other colors will..# be computed from this) or an even number of values consisting of..# option names and values. The name for an option is the one used..# for the option database, such as activeForeground, not -activeforeground.....proc ::tk_setPalette {args} {.. if {[winfo depth .] == 1} {...# Just return on monochrome displays, otherwise errors
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5370
                                                                                                                                                                                                                                                          Entropy (8bit):4.979530133775421
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:ssAXzkTQ9w5fLQYkJLZkRXKUXfwyZTq2sz8j2Em3YKhrYK:jAXgE0DQpJLGR6UXfpqnzG3m3YKhrYK
                                                                                                                                                                                                                                                          MD5:286C01A1B12261BC47F5659FD1627ABD
                                                                                                                                                                                                                                                          SHA1:4CA36795CAB6DFE0BBBA30BB88A2AB71A0896642
                                                                                                                                                                                                                                                          SHA-256:AA4F87E41AC8297F51150F2A9F787607690D01793456B93F0939C54D394731F9
                                                                                                                                                                                                                                                          SHA-512:D54D5A89B7408A9724A1CA1387F6473BDAD33885194B2EC5A524C7853A297FD65CE2A57F571C51DB718F6A00DCE845DE8CF5F51698F926E54ED72CDC81BCFE54
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# panedwindow.tcl --..#..# This file defines the default bindings for Tk panedwindow widgets and..# provides procedures that help in implementing those bindings.....bind Panedwindow <Button-1> { ::tk::panedwindow::MarkSash %W %x %y 1 }..bind Panedwindow <Button-2> { ::tk::panedwindow::MarkSash %W %x %y 0 }....bind Panedwindow <B1-Motion> { ::tk::panedwindow::DragSash %W %x %y 1 }..bind Panedwindow <B2-Motion> { ::tk::panedwindow::DragSash %W %x %y 0 }....bind Panedwindow <ButtonRelease-1> {::tk::panedwindow::ReleaseSash %W 1}..bind Panedwindow <ButtonRelease-2> {::tk::panedwindow::ReleaseSash %W 0}....bind Panedwindow <Motion> { ::tk::panedwindow::Motion %W %x %y }....bind Panedwindow <Leave> { ::tk::panedwindow::Leave %W }....# Initialize namespace..namespace eval ::tk::panedwindow {}....# ::tk::panedwindow::MarkSash --..#..# Handle marking the correct sash for possible dragging..#..# Arguments:..# w..the widget..# x..widget local x coord..# y..widget local y coord..# proxy.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):376
                                                                                                                                                                                                                                                          Entropy (8bit):5.040809246948068
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:CsUgabAOgjDnzJNBc6ynID/cL4RpncleXN17MQ9PZBIQ08hof7MQ9PZBIQei:lGbyntNO6LYZliZBIUhkZBIFi
                                                                                                                                                                                                                                                          MD5:2DE9606B1F945CDB29C891A20A681351
                                                                                                                                                                                                                                                          SHA1:3856C58B73E7EB5E1313A3E50090DB1798CA0F03
                                                                                                                                                                                                                                                          SHA-256:1390F260EA7AF5B0779549FA29615530FF9E3BC202806D2024AC644B1FAC5DBC
                                                                                                                                                                                                                                                          SHA-512:03DE591BD1E9325EFFEBF90C7206F6813A9AC9726B44C386055F878CD893C62EE5D6C709A299EF2368B67E139BFEE2DC9F35010F4E57C55399F5A82E2FABAB17
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:if {![package vsatisfies [package provide Tcl] 8.6.0]} return..if {($::tcl_platform(platform) eq "unix") && ([info exists ::env(DISPLAY)]...|| ([info exists ::argv] && ("-display" in $::argv)))} {.. package ifneeded Tk 8.6.14 [list load [file join $dir .. .. bin libtk8.6.dll]]..} else {.. package ifneeded Tk 8.6.14 [list load [file join $dir .. .. bin tk86t.dll]]..}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7632
                                                                                                                                                                                                                                                          Entropy (8bit):4.891666209090638
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:Eet0t8bm9Z+Yjo+j/YKOtOUOtk8XKUal320:EetG8biZZs+bIAUoxX0d
                                                                                                                                                                                                                                                          MD5:21A3AC11146EC26784C0E729D8D644D0
                                                                                                                                                                                                                                                          SHA1:C7E0918E8692C42C1D1DD1BBCBFFF22A85979B69
                                                                                                                                                                                                                                                          SHA-256:579701605669AADFFBCDB7E3545C68442495428EE6E93C2D3A3133583BCD3D33
                                                                                                                                                                                                                                                          SHA-512:724ED83B989AD9033BEC4211EE50E4C9E85B51054C518CDF7E02D0ED0416F636B9F38C0B0D29F8F4F7F465B77C7D2E01D0918D2C2C3FEC4C7739EA982302FA2E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# safetk.tcl --..#..# Support procs to use Tk in safe interpreters...#..# Copyright (c) 1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....# see safetk.n for documentation....#..#..# Note: It is now ok to let untrusted code being executed..# between the creation of the interp and the actual loading..# of Tk in that interp because the C side Tk_Init will..# now look up the parent interp and ask its safe::TkInit..# for the actual parameters to use for it's initialization (if allowed),..# not relying on the child state...#....# We use opt (optional arguments parsing)..package require opt 0.4.1;....namespace eval ::safe {.... # counter for safe toplevels.. variable tkSafeId 0..}....#..# tkInterpInit : prepare the child interpreter for tk loading..# most of the real job is done by loadTk..# returns the child name (tkInterpInit
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8693
                                                                                                                                                                                                                                                          Entropy (8bit):4.968450834020619
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:GSusE8YOdpO4aDtao+QYa6t2jooB6ajpaqa5xQGmLGKOC9dLrVx:KsbYQO48t+QYa+NkFjpagGmKKX9dLrVx
                                                                                                                                                                                                                                                          MD5:D45202D3D2D052D4C6BFE8D1322AAB39
                                                                                                                                                                                                                                                          SHA1:8CDF184AC2E9299B2B2A107A64E9D1803AA298DE
                                                                                                                                                                                                                                                          SHA-256:0747A387FDD1B2C7135ECEAE7B392ED52E1D1EBF3FFA90FEBE886DBC0981EB74
                                                                                                                                                                                                                                                          SHA-512:27B005F955BAE00D15C4492E7BD3EBDC5EE3BF9C164C418198B4BD185709C8810AA6CF76CBCC07EEB4C1D20F8C76EF8DF8B219563C18B88C94954C910BFF575D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# scale.tcl --..#..# This file defines the default bindings for Tk scale widgets and provides..# procedures that help in implementing the bindings...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994-1995 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# The code below creates the default class bindings for entries...#-------------------------------------------------------------------------....# Standard Motif bindings:....bind Scale <Enter> {.. if {$tk_strictMotif} {...set tk::Priv(activeBg) [%W cget -activebackground]...%W configure -activebackground [%W cget -background].. }.. tk::ScaleActivate %W %x %y..}..bind Scale <Motion> {.. tk::ScaleActivate %W %x %y..}..bind Scale <Leave> {.. if {$tk_strictMotif} {...%W configure -activebackground
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):13188
                                                                                                                                                                                                                                                          Entropy (8bit):5.063842571848725
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:Gf7RV8ei32PHKT8H2wwucyRlXn+kl1nBKp4nu5FCyK:2mei3qHKT8WPurnXn+I1nBg4nu5MyK
                                                                                                                                                                                                                                                          MD5:5249CD1E97E48E3D6DEC15E70B9D7792
                                                                                                                                                                                                                                                          SHA1:612E021BA25B5E512A0DFD48B6E77FC72894A6B9
                                                                                                                                                                                                                                                          SHA-256:EEC90404F702D3CFBFAEC0F13BF5ED1EBEB736BEE12D7E69770181A25401C61F
                                                                                                                                                                                                                                                          SHA-512:E4E0AB15EB9B3118C30CD2FF8E5AF87C549EAA9B640FFD809A928D96B4ADDEFB9D25EFDD1090FBD0019129CDF355BB2F277BC7194001BA1D2ED4A581110CEAFC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# scrlbar.tcl --..#..# This file defines the default bindings for Tk scrollbar widgets...# It also provides procedures that help in implementing the bindings...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994-1996 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# The code below creates the default class bindings for scrollbars...#-------------------------------------------------------------------------....# Standard Motif bindings:..if {[tk windowingsystem] eq "x11" || [tk windowingsystem] eq "aqua"} {....bind Scrollbar <Enter> {.. if {$tk_strictMotif} {...set tk::Priv(activeBg) [%W cget -activebackground]...%W configure -activebackground [%W cget -background].. }.. %W activate [%W identify %x %y]..}..bind Scrollbar <Motion> {.. %W activate [%
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):16543
                                                                                                                                                                                                                                                          Entropy (8bit):5.034958189335699
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:IMpfyeKu9TzD0E8+9T1wqBaQKpiqQr7E32fnzXfWJU:IMpfyeKu9Tx8WODTp2zPP
                                                                                                                                                                                                                                                          MD5:EAA36F0AA69AE19DDBDD0448FBAD9D4D
                                                                                                                                                                                                                                                          SHA1:EB0ADB4F4D937BAC2F17480ADAF6F948262E754D
                                                                                                                                                                                                                                                          SHA-256:747889C3086C917A34554A9DC495BC0C08A03FD3A5828353ED2A64B97F376835
                                                                                                                                                                                                                                                          SHA-512:C8368F19EC6842ED67073B9FC9C9274107E643324CB23B28C54DF63FB720F63B043281B30DBEA053D08481B0442A87465F715A8AA0711B01CE83FF7B9F8A4F4C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# spinbox.tcl --..#..# This file defines the default bindings for Tk spinbox widgets and provides..# procedures that help in implementing those bindings. The spinbox builds..# off the entry widget, so it can reuse Entry bindings and procedures...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 1999-2000 Jeffrey Hobbs..# Copyright (c) 2000 Ajuba Solutions..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of tk::Priv that are used in this file:..#..# afterId -..If non-null, it means that auto-scanning is underway..#...and it gives the "after" id for the next auto-scan..#...command to be executed...# mouseMoved -..Non-zero means the mouse has moved a significant..#...amount since the button went down (so, for example,..#.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20523
                                                                                                                                                                                                                                                          Entropy (8bit):4.786929402401609
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:eeVL0UI9Ms++J7VT/hc+ISyNsATbOan/uW/UFQ1gs1gxtKZufe2SvdJcmq/YbhEB:eeF0UI9Ms++J7VT/hc+ISyCATbOan2W+
                                                                                                                                                                                                                                                          MD5:9378397DD3DCA9DFB181F6F512B15631
                                                                                                                                                                                                                                                          SHA1:4F95DD6B658B6A912725DC7D6226F8414020D6C7
                                                                                                                                                                                                                                                          SHA-256:B04B1A675572E6FCD12C5FE82C4FD0930395548436FF93D848BF340AE202E7E3
                                                                                                                                                                                                                                                          SHA-512:D28CC3C8F3D0B1B2371CBD9EE29AC6881BABD8A07C762FF8F3284449998EE44FA44752CC8AB0DE47A3492776CE1D13BC8EA18CFDBDF710639D2D62D02CB917A9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# Tcl autoload index file, version 2.0..# This file is generated by the "auto_mkindex" command..# and sourced to set up indexing information for one or..# more commands. Typically each line is a command that..# sets an element in the auto_index array, where the..# element name is the name of a command and the value is..# a script that loads the command.....set auto_index(::tk::dialog::error::Return) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::Details) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::SaveToLog) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::Destroy) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::bgerror) [list source [file join $dir bgerror.tcl]]..set auto_index(bgerror) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::ButtonInvoke) [list source [file join $dir button.tcl]]..set auto_index(::tk::ButtonAutoInvoke) [list sou
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4625
                                                                                                                                                                                                                                                          Entropy (8bit):4.751120784854044
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:wfQXIqAv6iEw6dNrKVlPBnXWASbvs8DjXKpQQkK2tTsZf9:wf+IqI6iE43PJYbvs8DjXKpsK2tIZ9
                                                                                                                                                                                                                                                          MD5:0512EE07E0A8071971CFBB654C69C145
                                                                                                                                                                                                                                                          SHA1:44F6E2990D5C67ADF5958D1FE5CD6AB6B43FD095
                                                                                                                                                                                                                                                          SHA-256:04B284915DA1940758D0FD73BBB9CBBC9967BBAA5E5A9DB9947F7E8FEDD0DF96
                                                                                                                                                                                                                                                          SHA-512:3B98B094647A7848B45698EDBBA87F1B3A21CBF720C6402F7CD9D49003DCF627C2C23D2EC21703CB808846E7DA44E5DD41830B1EBC4C0DC08CD0F3117C1C59EF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# tearoff.tcl --..#..# This file contains procedures that implement tear-off menus...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk::TearoffMenu --..# Given the name of a menu, this procedure creates a torn-off menu..# that is identical to the given menu (including nested submenus)...# The new torn-off menu exists as a toplevel window managed by the..# window manager. The return value is the name of the new menu...# The window is created at the point specified by x and y..#..# Arguments:..# w -...The menu to be torn-off (duplicated)...# x -...x coordinate where window is created..# y -...y coordinate where window is created....proc ::tk::TearOffMenu {w {x 0} {y 0}} {.. # Find a unique name to use for the torn-off menu. Find the first.. # ancestor of w that is a
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):35183
                                                                                                                                                                                                                                                          Entropy (8bit):4.9567627831293395
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Rp4LaQDlOrqquMwIMyv4Et8rvJLgmTGXs1bYMeNnnZl8n6KRD:RYK8rymTGs1b0xncn6KR
                                                                                                                                                                                                                                                          MD5:016613531555C4F30F670DAB58F10B3D
                                                                                                                                                                                                                                                          SHA1:3AFC8AA3E10950D79D1003B0810F2E0DC2135EB9
                                                                                                                                                                                                                                                          SHA-256:F7ECC5AE6EB297C79AAD5CFC200B29C4E72409641FA369C5CDBBA30AE41E982A
                                                                                                                                                                                                                                                          SHA-512:C5D071FC8CB68C5985E74AB7E90367E9261B291474689C37ABD7F921716053E9D5E9446A45C5E91F3BB927589270E818E22E2D675ACBE04E0627ECD5D532BC05
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# text.tcl --..#..# This file defines the default bindings for Tk text widgets and provides..# procedures that help in implementing the bindings...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 1998 by Scriptics Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of ::tk::Priv that are used in this file:..#..# afterId -..If non-null, it means that auto-scanning is underway..#...and it gives the "after" id for the next auto-scan..#...command to be executed...# char -..Character position on the line; kept in order..#...to allow moving up or down past short lines while..#...still remembering the desired position...# mouseMoved -..Non-zero means the mouse has moved a significant..#...amount since the button we
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):24322
                                                                                                                                                                                                                                                          Entropy (8bit):5.137715953500608
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:NIyxt+WaB9USY15gSgC3DbTbXLXKr3aIIXyDAbK2LMGgtewT+3oFQRyH5bAy59HU:NIItNe9USZbeXysm7GgteoFQRYMESL
                                                                                                                                                                                                                                                          MD5:2261CB7D57C972C2418CD222B83265F7
                                                                                                                                                                                                                                                          SHA1:A62466C2A678D341B6BD03BE8BE45C7AB84CC14E
                                                                                                                                                                                                                                                          SHA-256:AEA1F1F01E2DF0CCCD8C2010C4035DEEA297424A9174383E5EE016EB25484E5A
                                                                                                                                                                                                                                                          SHA-512:92CF1BD11E6B819E69BCCB237865092ABCEE95383F9158C9FE10AAB0D48888279D9AD4CF51B567DB214D99960E8FB21899085E3D77F1A297DBCAFA38F0CB322A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# tk.tcl --..#..# Initialization script normally executed in the interpreter for each Tk-based..# application. Arranges class bindings for widgets...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1996 Sun Microsystems, Inc...# Copyright (c) 1998-2000 Ajuba Solutions...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES.....# Verify that we have Tk binary and script components from the same release..package require -exact Tk 8.6.14.....# Create a ::tk namespace..namespace eval ::tk {.. # Set up the msgcat commands.. namespace eval msgcat {...namespace export mc mcmax.. if {[interp issafe] || [catch {package require msgcat}]} {.. # The msgcat package is not available. Supply our own.. # minimal replacement... proc mc {src args} {.. return [format $src {*}$args].. }.. proc mc
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):39606
                                                                                                                                                                                                                                                          Entropy (8bit):5.185943230848209
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:+oj+Aq49cn9tJNgDt0/vsKulXgo65Eh6pQb:+6+ZT/ggEdio65Ehdb
                                                                                                                                                                                                                                                          MD5:57D60D17CD3EF211D18BF4F82586DDCB
                                                                                                                                                                                                                                                          SHA1:0A7415EA599725F81118F4B833C4FA1D601D7BA6
                                                                                                                                                                                                                                                          SHA-256:BAF1ED7B617FB64CA097E81059454783C4D922999E19000CF2953CC09C8F4505
                                                                                                                                                                                                                                                          SHA-512:D3279D24885CB0C4E72FA0C3783FAB215A32DC591E367C5640A3FDB1AED33933504DDDAABCE98455B485B68BCA3C75A97249EAC40ABEEE945B9ABAAB7974EE0D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# tkfbox.tcl --..#..#.Implements the "TK" standard file selection dialog box. This dialog..#.box is used on the Unix platforms whenever the tk_strictMotif flag is..#.not set...#..#.The "TK" standard file selection dialog box is similar to the file..#.selection dialog box on Win95(TM). The user can navigate the..#.directories by clicking on the folder icons or by selecting the..#."Directory" option menu. The user can select files by clicking on the..#.file icons or by entering a filename in the "Filename:" entry...#..# Copyright (c) 1994-1998 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::file {.. namespace import -force ::tk::msgcat::*.. variable showHiddenBtn 0.. variable showHiddenVar 1.... # Create the images if they did not already exist... if {![info exists ::tk::Priv(updirImage)]} {...s
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3713
                                                                                                                                                                                                                                                          Entropy (8bit):4.915055696129498
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:InrWdo3L7Fe5qusQGdrMNnQbfIxEOxE0kFgG0FgGouox9FrGVuwg3kNcT+z5UlEr:UWdsOBn/1i+pqxwNjKs
                                                                                                                                                                                                                                                          MD5:01F28512E10ACBDDF93AE2BB29E343BC
                                                                                                                                                                                                                                                          SHA1:C9CF23D6315218B464061F011E4A9DC8516C8F1F
                                                                                                                                                                                                                                                          SHA-256:AE0437FB4E0EBD31322E4EACA626C12ABDE602DA483BB39D0C5EE1BC00AB0AF4
                                                                                                                                                                                                                                                          SHA-512:FE3BAE36DDB67F6D7A90B7A91B6EC1A009CF26C0167C46635E5A9CEAEC9083E59DDF74447BF6F60399657EE9604A2314B170F78A921CF948B2985DDF02A89DA6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Ttk widget set: Alternate theme..#....namespace eval ttk::theme::alt {.... variable colors.. array set colors {...-frame .."#d9d9d9"...-window.."#ffffff"...-darker ."#c3c3c3"...-border.."#414141"...-activebg ."#ececec"...-disabledfg."#a3a3a3"...-selectbg."#4a6984"...-selectfg."#ffffff"...-altindicator."#aaaaaa".. }.... ttk::style theme settings alt {.....ttk::style configure "." \... -background .$colors(-frame) \... -foreground .black \... -troughcolor.$colors(-darker) \... -bordercolor.$colors(-border) \... -selectbackground .$colors(-selectbg) \... -selectforeground .$colors(-selectfg) \... -font ..TkDefaultFont \... ;.....ttk::style map "." -background \... [list disabled $colors(-frame) active $colors(-activebg)] ;...ttk::style map "." -foreground [list disabled $colors(-disabledfg)] ;.. ttk::style map "." -embossed [list disabled 1] ;.....ttk::style configure TButton \... -anchor center -width -11 -padding "1 1" \... -reli
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3838
                                                                                                                                                                                                                                                          Entropy (8bit):4.940737732832436
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:WdbclJFvlyLi+8OWXgQahpvAdNutdHrFBlCFBK2tdHkFBlhKgY1geAWUWeFVvtdp:C8EQPNeWgFeqdXj
                                                                                                                                                                                                                                                          MD5:F07A3A86362E9E253BE91F59714FE134
                                                                                                                                                                                                                                                          SHA1:84DE1AB2EAE62E4B114F0E613BD94955AFA9E6C7
                                                                                                                                                                                                                                                          SHA-256:E199CC9C429B35A09721D0A22543C3729E2B8462E68DFA158C0CEC9C70A0D79D
                                                                                                                                                                                                                                                          SHA-512:324EAF9F857076CA4FECB26D8DF76F8BB1D3F15EAE55D6B6C9689BF1682B306AC7A3592B6A518D23F9FE4DC21EFB6ACF1ECA948F889FA1ADFFA0E12C0BEAB57F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Aqua theme (OSX native look and feel)..#....namespace eval ttk::theme::aqua {.. ttk::style theme settings aqua {.....ttk::style configure . \... -font TkDefaultFont \... -background systemWindowBackgroundColor \... -foreground systemLabelColor \... -selectbackground systemSelectedTextBackgroundColor \... -selectforeground systemSelectedTextColor \... -selectborderwidth 0 \... -insertwidth 1.....ttk::style map . \... -foreground {....disabled systemDisabledControlTextColor....background systemLabelColor} \... -selectbackground {....background systemSelectedTextBackgroundColor....!focus systemSelectedTextBackgroundColor} \... -selectforeground {....background systemSelectedTextColor....!focus systemSelectedTextColor}.....# Button...ttk::style configure TButton -anchor center -width -6 \... -foreground systemControlTextColor...ttk::style map TButton \... -foreground {....pressed white... {alternate !pressed !background} white}...ttk::styl
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3014
                                                                                                                                                                                                                                                          Entropy (8bit):4.917794267131833
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:A5N+EqJWR1eTC01cG61ELLgrDgk1JgQ6TQGvhV5giT6TUP+3JWMHTeJ:kN+RQfccG61ooDgQ6dNT6TUP+PHO
                                                                                                                                                                                                                                                          MD5:D4BF1AF5DCDD85E3BD11DBF52EB2C146
                                                                                                                                                                                                                                                          SHA1:B1691578041319E671D31473A1DD404855D2038B
                                                                                                                                                                                                                                                          SHA-256:E38A9D1F437981AA6BF0BDD074D57B769A4140C0F7D9AFF51743FE4ECC6DFDDF
                                                                                                                                                                                                                                                          SHA-512:25834B4B231F4FF1A88EEF67E1A102D1D0546EC3B0D46856258A6BE6BBC4B381389C28E2EB60A01FF895DF24D6450CD16CA449C71F82BA53BA438A4867A47DCD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Bindings for Buttons, Checkbuttons, and Radiobuttons...#..# Notes: <Button1-Leave>, <Button1-Enter> only control the "pressed"..# state; widgets remain "active" if the pointer is dragged out...# This doesn't seem to be conventional, but it's a nice way..# to provide extra feedback while the grab is active...# (If the button is released off the widget, the grab deactivates and..# we get a <Leave> event then, which turns off the "active" state)..#..# Normally, <ButtonRelease> and <ButtonN-Enter/Leave> events are..# delivered to the widget which received the initial <Button>..# event. However, Tk [grab]s (#1223103) and menu interactions..# (#1222605) can interfere with this. To guard against spurious..# <Button1-Enter> events, the <Button1-Enter> binding only sets..# the pressed state if the button is currently active...#....namespace eval ttk::button {}....bind TButton <Enter> ..{ %W instate !disabled {%W state active} }..bind TButton <Leave>..{ %W state !active }..bind TButton <s
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4809
                                                                                                                                                                                                                                                          Entropy (8bit):4.905115353394083
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:KrS4se/XhW03cC7TxPp/uo1ZUb0WZvSoetCgV+tMWG3xT3xgNB4x76FAuoxVYuIJ:oS4sSjWwFAGkhiP3xT3xL6B2bbe
                                                                                                                                                                                                                                                          MD5:2B20E7B2E6BDDBEB14F5F63BF38DBF24
                                                                                                                                                                                                                                                          SHA1:43DB48094C4BD7DE3B76AFBC051D887FEFE9887E
                                                                                                                                                                                                                                                          SHA-256:CFFC59931FDD1683AD23895E92522CF49B099128753FCDFF34374024E42CF995
                                                                                                                                                                                                                                                          SHA-512:1EB5EA78D26D18EAD6563AFBF1798F71723001DCC945E7DB3E4368564D0563029BE3565876AD8CB97331CFE34B2A0A313FA1BF252B87049160FE5DCD65434775
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# "Clam" theme...#..# Inspired by the XFCE family of Gnome themes...#....namespace eval ttk::theme::clam {.. variable colors.. array set colors {...-disabledfg.."#999999"...-frame .."#dcdad5"...-window .."#ffffff"...-dark..."#cfcdc8"...-darker .."#bab5ab"...-darkest.."#9e9a91"...-lighter.."#eeebe7"...-lightest .."#ffffff"...-selectbg.."#4a6984"...-selectfg.."#ffffff"...-altindicator.."#5895bc"...-disabledaltindicator."#a0a0a0".. }.... ttk::style theme settings clam {.....ttk::style configure "." \... -background $colors(-frame) \... -foreground black \... -bordercolor $colors(-darkest) \... -darkcolor $colors(-dark) \... -lightcolor $colors(-lighter) \... -troughcolor $colors(-darker) \... -selectbackground $colors(-selectbg) \... -selectforeground $colors(-selectfg) \... -selectborderwidth 0 \... -font TkDefaultFont \... ;.....ttk::style map "." \... -background [list disabled $colors(-frame) \..... active $colors(-lighter)] \..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3864
                                                                                                                                                                                                                                                          Entropy (8bit):4.935603001745302
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:zcJZjdWs+WVB4ULsMF7tnvnuSuqo5DKxiFgG0FgGHx9FrGTtu/3Kt+iW2PbuAk38:zcJZEstB4UoituSm+VtYErY
                                                                                                                                                                                                                                                          MD5:0205663142775F4EF2EB104661D30979
                                                                                                                                                                                                                                                          SHA1:452A0D613288A1CC8A1181C3CC1167E02AA69A73
                                                                                                                                                                                                                                                          SHA-256:424BBA4FB6836FEEBE34F6C176ED666DCE51D2FBA9A8D7AA756ABCBBAD3FC1E3
                                                                                                                                                                                                                                                          SHA-512:FB4D212A73A6F5A8D2774F43D310328B029B52B35BEE133584D8326363B385AB7AA4AE25E98126324CC716962888321E0006E5F6EF8563919A1D719019B2D117
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# "classic" Tk theme...#..# Implements Tk's traditional Motif-like look and feel...#....namespace eval ttk::theme::classic {.... variable colors; array set colors {...-frame.."#d9d9d9"...-window.."#ffffff"...-activebg."#ececec"...-troughbg."#c3c3c3"...-selectbg."#c3c3c3"...-selectfg."#000000"...-disabledfg."#a3a3a3"...-indicator."#b03060"...-altindicator."#b05e5e".. }.... ttk::style theme settings classic {...ttk::style configure "." \... -font..TkDefaultFont \... -background..$colors(-frame) \... -foreground..black \... -selectbackground.$colors(-selectbg) \... -selectforeground.$colors(-selectfg) \... -troughcolor.$colors(-troughbg) \... -indicatorcolor.$colors(-frame) \... -highlightcolor.$colors(-frame) \... -highlightthickness.1 \... -selectborderwidth.1 \... -insertwidth.2 \... ;.....# To match pre-Xft X11 appearance, use:...#.ttk::style configure . -font {Helvetica 12 bold}.....ttk::style map "." -background \... [list disabled
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):12718
                                                                                                                                                                                                                                                          Entropy (8bit):5.063548300335668
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:otLzBJ9SfinaXUBLPYXlk7fKiLH+AzIoJdJwGknmyLsxoVEQGITse8g5sarkT32e:wB5aXmLPYXmrKxLL7A
                                                                                                                                                                                                                                                          MD5:F7065D345A4BFB3127C3689BF1947C30
                                                                                                                                                                                                                                                          SHA1:9631C05365B0F5A36E4CA5CBA83628CCD7FCBDE1
                                                                                                                                                                                                                                                          SHA-256:68EED4AF6D2EC5B3EA24B1122A704B040366CBE2F458103137479352FFA1475A
                                                                                                                                                                                                                                                          SHA-512:74B99B9E326680150DD5EC7263192691BCD8A71B2A4EE7F3177DEDDD43E924A7925085C6D372731A70570F96B3924450255B2F54CA3B9C44D1160CA37E715B00
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Combobox bindings...#..# <<NOTE-WM-TRANSIENT>>:..#..#.Need to set [wm transient] just before mapping the popdown..#.instead of when it's created, in case a containing frame..#.has been reparented [#1818441]...#..#.On Windows: setting [wm transient] prevents the parent..#.toplevel from becoming inactive when the popdown is posted..#.(Tk 8.4.8+)..#..#.On X11: WM_TRANSIENT_FOR on override-redirect windows..#.may be used by compositing managers and by EWMH-aware..#.window managers (even though the older ICCCM spec says..#.it's meaningless)...#..#.On OSX: [wm transient] does utterly the wrong thing...#.Instead, we use [MacWindowStyle "help" "noActivates hideOnSuspend"]...#.The "noActivates" attribute prevents the parent toplevel..#.from deactivating when the popdown is posted, and is also..#.necessary for "help" windows to receive mouse events...#."hideOnSuspend" makes the popdown disappear (resp. reappear)..#.when the parent toplevel is deactivated (resp. reactivated)...#.(see [#18147
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4674
                                                                                                                                                                                                                                                          Entropy (8bit):4.836935825704301
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:DRYEqfLDxGmxGUetobPT6t6brv0q3O4Uxz0:DWEqTDbxdKobPqe5PUxw
                                                                                                                                                                                                                                                          MD5:1A799FE3754307A5AADE98C367E2F5D7
                                                                                                                                                                                                                                                          SHA1:C64BE4B77F0D298610F4EE20FCEBBAEE3C8B5F22
                                                                                                                                                                                                                                                          SHA-256:5B33F32B0139663347D6CF70A5A838F8E4554E0E881E97C8478B77733162EA73
                                                                                                                                                                                                                                                          SHA-512:89F367F9A59730BCDFC5ABDE0E35A10B72A1F19C68A768BA4524C938EF5C5CAF094C1BFA8FC74173F65201F6617544223C2143252A9F691EE9AAA7543315179F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Map symbolic cursor names to platform-appropriate cursors...#..# The following cursors are defined:..#..#.standard.-- default cursor for most controls..#.""..-- inherit cursor from parent window..#.none..-- no cursor..#..#.text..-- editable widgets (entry, text)..#.link..-- hyperlinks within text..#.crosshair.-- graphic selection, fine control..#.busy..-- operation in progress..#.forbidden.-- action not allowed..#..#.hresize..-- horizontal resizing..#.vresize..-- vertical resizing..#..# Also resize cursors for each of the compass points,..# {nw,n,ne,w,e,sw,s,se}resize...#..# Platform notes:..#..# Windows doesn't distinguish resizing at the 8 compass points,..# only horizontal, vertical, and the two diagonals...#..# OSX doesn't have resize cursors for nw, ne, sw, or se corners...# We use the Tk-defined X11 fallbacks for these...#..# X11 doesn't have a "forbidden" cursor (usually a slashed circle);..# "pirate" seems to be the conventional cursor for this purpose...#..# Windows has a
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4553
                                                                                                                                                                                                                                                          Entropy (8bit):4.933885986949396
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:lNl3u3lCFUeuMGN3xbVJU+N3xbVJh3IwxkxlBqatUrtY:zl3ZUe9GN3NVC+N3NVjqntUZY
                                                                                                                                                                                                                                                          MD5:FC79F42761D63172163C08F0F5C94436
                                                                                                                                                                                                                                                          SHA1:AABAB4061597D0D6DC371F46D14AAA1A859096DF
                                                                                                                                                                                                                                                          SHA-256:49AE8FAF169165BDDAF01D50B52943EBAB3656E9468292B7890BE143D0FCBC91
                                                                                                                                                                                                                                                          SHA-512:F619834A95C9DEB93F8184BCC437D701A961C77E24A831ADBD5C145556D26986BFDA2A6ACB9E8784F8B2380E122D12AC893EB1B6ACF03098922889497E1FF9EA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Settings for default theme...#....namespace eval ttk::theme::default {.. variable colors.. array set colors {...-frame..."#d9d9d9"...-foreground.."#000000"...-window..."#ffffff"...-text .."#000000"...-activebg.."#ececec"...-selectbg.."#4a6984"...-selectfg.."#ffffff"...-darker .."#c3c3c3"...-disabledfg.."#a3a3a3"...-indicator.."#4a6984"...-disabledindicator."#a3a3a3"...-altindicator.."#9fbdd8"...-disabledaltindicator."#c0c0c0".. }.... ttk::style theme settings default {.....ttk::style configure "." \... -borderwidth .1 \... -background .$colors(-frame) \... -foreground .$colors(-foreground) \... -troughcolor .$colors(-darker) \... -font ..TkDefaultFont \... -selectborderwidth.1 \... -selectbackground.$colors(-selectbg) \... -selectforeground.$colors(-selectfg) \... -insertwidth .1 \... -indicatordiameter.10 \... ;.....ttk::style map "." -background \... [list disabled $colors(-frame) active $colors(-activebg)]...ttk::style map "."
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):18006
                                                                                                                                                                                                                                                          Entropy (8bit):5.0251298333416825
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:sca9Jzcyzf6yzQO+e+iPT3vKof8q3YIuR13a:sT9Jzcy76diV3YNa
                                                                                                                                                                                                                                                          MD5:DBCEDD7BFB63A55C210C25DCF230C657
                                                                                                                                                                                                                                                          SHA1:B05CF01453A22016995627176F6339068C58BA01
                                                                                                                                                                                                                                                          SHA-256:F2CACB1B3A941CC7079627644E91F0D4729BF820C481C8CE7FA28C952B803E4D
                                                                                                                                                                                                                                                          SHA-512:7F8E9A7D80B463D9CEC791EF59B1A27F8ACEC95CEEDE45ECA06C4DBF9BA805C2C1AEE19A0118709EE47768F1B735A74A32B35FB9D8559D94DA77C71E4EC5D117
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# DERIVED FROM: tk/library/entry.tcl r1.22..#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 2004, Joe English..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....namespace eval ttk {.. namespace eval entry {...variable State.....set State(x) 0...set State(selectMode) none...set State(anchor) 0...set State(scanX) 0...set State(scanIndex) 0...set State(scanMoved) 0.....# Button-2 scan speed is (scanNum/scanDen) characters...# per pixel of mouse movement....# The standard Tk entry widget uses the equivalent of...# scanNum = 10, scanDen = average character width....# I don't know why that was chosen....#...set State(scanNum) 1...set State(scanDen) 1...set State(deadband) 3.;# #pixels for mouse-moved deadband... }..}....### Option database settings...#..option add *TEntry.cursor [ttk::cursor text] widg
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5639
                                                                                                                                                                                                                                                          Entropy (8bit):4.9968844674828485
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:NzEh94ntnVU8Z/1LkAIW22SeLMQR8hzcksejmOF4ytZm:Sh9ahV3ZWAIWDfktm
                                                                                                                                                                                                                                                          MD5:8514CF728A5782E457C50D7C61740CE5
                                                                                                                                                                                                                                                          SHA1:EDE61C428D1865F10AE093D5C4BEF29C0EC7E8CE
                                                                                                                                                                                                                                                          SHA-256:6574067A91858506460AC44DDF8CF9270E81D67B2FEFF2A43B4D5F774568A5EC
                                                                                                                                                                                                                                                          SHA-512:2E24F15887193FFB884AB6AF9ECF619EF913E3F6C6DFB0FC980BFB59A57FFEC56B68DD36935A2998FBC66D12EF40A58DC3B3F278EC0E21D84DFFEAD6A80C4C96
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Font specifications...#..# This file, [source]d at initialization time, sets up the following..# symbolic fonts based on the current platform:..#..# TkDefaultFont.-- default for GUI items not otherwise specified..# TkTextFont.-- font for user text (entry, listbox, others)..# TkFixedFont.-- standard fixed width font..# TkHeadingFont.-- headings (column headings, etc)..# TkCaptionFont -- dialog captions (primary text in alert dialogs, etc.)..# TkTooltipFont.-- font to use for tooltip windows..# TkIconFont.-- font to use for icon captions..# TkMenuFont.-- used to use for menu items..#..# In Tk 8.5, some of these fonts may be provided by the TIP#145 implementation..# (On Windows and Mac OS X as of Oct 2007)...#..# +++ Platform notes:..#..# Windows:..#.The default system font changed from "MS Sans Serif" to "Tahoma"..# .in Windows XP/Windows 2000...#..#.MS documentation says to use "Tahoma 8" in Windows 2000/XP,..#.although many MS programs still use "MS Sans Serif 8"..#..#.Should use
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6408
                                                                                                                                                                                                                                                          Entropy (8bit):4.920607671427164
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:toMcJQkmcE6fNuLyiCzSLSRwgppdT3kXdpK3dSH2tOTjvAG:tRc6kFbcH2pyXz+E2y
                                                                                                                                                                                                                                                          MD5:AEC91DD23DE04196AF5EB31E8BBD0946
                                                                                                                                                                                                                                                          SHA1:BDF5A5A42A147D7484E5A2966EA949FA68F52348
                                                                                                                                                                                                                                                          SHA-256:0935FB97B6628F055BAEB2E2BABBF2A6C8905260E1107972B0E7A1DF0752E180
                                                                                                                                                                                                                                                          SHA-512:6EA4A2EC378E6CBABBF8FF20FB1CAD0C68A90E5089F20D195FEF2EE4FF9259BD3B622378E7203BD238402140F7EAB7E316B8A8F9C4B6C0D3D3ACBE81F0A25EA4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Bindings for Menubuttons...#..# Menubuttons have three interaction modes:..#..# Pulldown: Press menubutton, drag over menu, release to activate menu entry..# Popdown: Click menubutton to post menu..# Keyboard: <space> or accelerator key to post menu..#..# (In addition, when menu system is active, "dropdown" -- menu posts..# on mouse-over. Ttk menubuttons don't implement this)...#..# For keyboard and popdown mode, we hand off to tk_popup and let..# the built-in Tk bindings handle the rest of the interaction...#..# ON X11:..#..# Standard Tk menubuttons use a global grab on the menubutton...# This won't work for Ttk menubuttons in pulldown mode,..# since we need to process the final <ButtonRelease> event,..# and this might be delivered to the menu. So instead we..# rely on the passive grab that occurs on <Button> events,..# and transition to popdown mode when the mouse is released..# or dragged outside the menubutton...#..# ON WINDOWS:..#..# I'm not sure what the hell is going on h
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5863
                                                                                                                                                                                                                                                          Entropy (8bit):4.963192408446461
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:RErUhyi5JeUQBWdz6eP8ClK6/u6AsBmPNNiREUkheLY1EVL23sN2JJjQdD:6uyiyDQBP8Z6/u6AUREUsNEVq3y2jkdD
                                                                                                                                                                                                                                                          MD5:39AEC76C4E7B810873545C6A137ACCF3
                                                                                                                                                                                                                                                          SHA1:165372DCCDD018D980AA2167094A4E0FA82B65F1
                                                                                                                                                                                                                                                          SHA-256:B1210147F9DAF3068DE3D28D4B18C04ECFA8C8574E3E0AD275C1D0D75E9A99B2
                                                                                                                                                                                                                                                          SHA-512:759436CA4462DF6C217F1502D1350735004EDD31472FDAA9860F3FD8FBC2F4978BE2B5A57993C37B9DCE4A8237840F50D620BA95C22900F658B29A2AC38A5218
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Bindings for TNotebook widget..#....namespace eval ttk::notebook {.. variable TLNotebooks ;# See enableTraversal..}....bind TNotebook <Button-1>..{ ttk::notebook::Press %W %x %y }..bind TNotebook <Right>...{ ttk::notebook::CycleTab %W 1; break }..bind TNotebook <Left>...{ ttk::notebook::CycleTab %W -1; break }..bind TNotebook <Control-Tab>..{ ttk::notebook::CycleTab %W 1; break }..bind TNotebook <Control-Shift-Tab>.{ ttk::notebook::CycleTab %W -1; break }..catch {..bind TNotebook <Control-ISO_Left_Tab>.{ ttk::notebook::CycleTab %W -1; break }..}..bind TNotebook <Destroy>..{ ttk::notebook::Cleanup %W }....# ActivateTab $nb $tab --..#.Select the specified tab and set focus...#..# Desired behavior:..#.+ take focus when reselecting the currently-selected tab;..#.+ keep focus if the notebook already has it;..#.+ otherwise set focus to the first traversable widget..#. in the newly-selected tab;..#.+ do not leave the focus in a deselected tab...#..proc ttk::notebook::ActivateTab {
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2274
                                                                                                                                                                                                                                                          Entropy (8bit):4.951790637542993
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:zVAqE3ZF8b4rXzsqAOAXsmCLFeNqkFeNXez:zLeU4bzSs1M
                                                                                                                                                                                                                                                          MD5:848A62BCF6ED3C16A8CFD26C43E1BC4E
                                                                                                                                                                                                                                                          SHA1:6F5E3EDF62716B511CF575BE2C6C997AFA2FA1E7
                                                                                                                                                                                                                                                          SHA-256:20EE6AD9D701709724292A926AF93C93784B254B48A656ECC140EF3A0FE10A11
                                                                                                                                                                                                                                                          SHA-512:AE78028EAF96E5B77DEFF0CD655360DB3A8058AC98B6753D9B77D629EDFFC582999A22A7075B9F5BA83EE65DA093E2CCB0EEAA4049898910D7AF517FDE60B28E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Bindings for ttk::panedwindow widget...#....namespace eval ttk::panedwindow {.. variable State.. array set State {...pressed 0.. .pressX.-...pressY.-...sash .-...sashPos -.. }..}....## Bindings:..#..bind TPanedwindow <Button-1> ..{ ttk::panedwindow::Press %W %x %y }..bind TPanedwindow <B1-Motion>..{ ttk::panedwindow::Drag %W %x %y }..bind TPanedwindow <ButtonRelease-1> .{ ttk::panedwindow::Release %W %x %y }....bind TPanedwindow <Motion> ..{ ttk::panedwindow::SetCursor %W %x %y }..bind TPanedwindow <Enter> ..{ ttk::panedwindow::SetCursor %W %x %y }..bind TPanedwindow <Leave> ..{ ttk::panedwindow::ResetCursor %W }..# See <<NOTE-PW-LEAVE-NOTIFYINFERIOR>>..bind TPanedwindow <<EnteredChild>>.{ ttk::panedwindow::ResetCursor %W }....## Sash movement:..#..proc ttk::panedwindow::Press {w x y} {.. variable State.... set sash [$w identify $x $y].. if {$sash eq ""} {.. .set State(pressed) 0...return.. }.. set State(pressed) .1.. set State(pressX) .$x.. set
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1138
                                                                                                                                                                                                                                                          Entropy (8bit):4.763501917862434
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:nJ8v3O0NSiio0pNFVkIks0ImxlnINgDImSgGINSyWghT:JFqS/o03fkxs0Rn+gD4v+S2F
                                                                                                                                                                                                                                                          MD5:DBF3BF0E8F04E9435E9561F740DFC700
                                                                                                                                                                                                                                                          SHA1:C7619A05A834EFB901C57DCFEC2C9E625F42428F
                                                                                                                                                                                                                                                          SHA-256:697CC0A75AE31FE9C2D85FB25DCA0AFA5D0DF9C523A2DFAD2E4A36893BE75FBA
                                                                                                                                                                                                                                                          SHA-512:D3B323DFB3EAC4A78DA2381405925C131A99C6806AF6FD8041102162A44E48BF166982A4AE4AA142A14601736716F1A628D9587E292FA8E4842BE984374CC192
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Ttk widget set: progress bar utilities...#....namespace eval ttk::progressbar {.. variable Timers.;# Map: widget name -> after ID..}....# Autoincrement --..#.Periodic callback procedure for autoincrement mode..#..proc ttk::progressbar::Autoincrement {pb steptime stepsize} {.. variable Timers.... if {![winfo exists $pb]} {.. .# widget has been destroyed -- cancel timer...unset -nocomplain Timers($pb)...return.. }.... set Timers($pb) [after $steptime \.. .[list ttk::progressbar::Autoincrement $pb $steptime $stepsize] ].... $pb step $stepsize..}....# ttk::progressbar::start --..#.Start autoincrement mode. Invoked by [$pb start] widget code...#..proc ttk::progressbar::start {pb {steptime 50} {stepsize 1}} {.. variable Timers.. if {![info exists Timers($pb)]} {...Autoincrement $pb $steptime $stepsize.. }..}....# ttk::progressbar::stop --..#.Cancel autoincrement mode. Invoked by [$pb stop] widget code...#..proc ttk::progressbar::stop {pb} {.. variabl
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2787
                                                                                                                                                                                                                                                          Entropy (8bit):4.795451191784129
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:IKADAzizZIcAlRqucObmn4AzyVN2AJyhAzukPNP:IHIBRqupmLSZkklP
                                                                                                                                                                                                                                                          MD5:F1C33CC2D47115BBECD2E7C2FCB631A7
                                                                                                                                                                                                                                                          SHA1:0123A961242ED8049B37C77C726DB8DBD94C1023
                                                                                                                                                                                                                                                          SHA-256:B909ADD0B87FA8EE08FD731041907212A8A0939D37D2FF9B2F600CD67DABD4BB
                                                                                                                                                                                                                                                          SHA-512:96587A8C3555DA1D810010C10C516CE5CCAB071557A3C8D9BD65C647C7D4AD0E35CBED0788F1D72BAFAC8C84C7E2703FC747F70D9C95F720745A1FC4A701C544
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# scale.tcl - Copyright (C) 2004 Pat Thoyts <patthoyts@users.sourceforge.net>..#..# Bindings for the TScale widget....namespace eval ttk::scale {.. variable State.. array set State {...dragging 0.. }..}....bind TScale <Button-1> { ttk::scale::Press %W %x %y }..bind TScale <B1-Motion> { ttk::scale::Drag %W %x %y }..bind TScale <ButtonRelease-1> { ttk::scale::Release %W %x %y }....bind TScale <Button-2> { ttk::scale::Jump %W %x %y }..bind TScale <B2-Motion> { ttk::scale::Drag %W %x %y }..bind TScale <ButtonRelease-2> { ttk::scale::Release %W %x %y }....bind TScale <Button-3> { ttk::scale::Jump %W %x %y }..bind TScale <B3-Motion> { ttk::scale::Drag %W %x %y }..bind TScale <ButtonRelease-3> { ttk::scale::Release %W %x %y }....## Keyboard navigation bindings:..#..bind TScale <<LineStart>> { %W set [%W cget -from] }..bind TScale <<LineEnd>> { %W set [%W cget -to] }....bind TScale <<PrevChar>> { ttk::scale::Increment %W -1 }..bin
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3285
                                                                                                                                                                                                                                                          Entropy (8bit):4.979174619784594
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:tyASEji8RYQ8FGD7BDos9Q1TBfvq/HKTh9lkHv8T/mAezeLEAAFULxZh4x:eIi8qFu2d11XlhfkPcczeLS4Zm
                                                                                                                                                                                                                                                          MD5:3FB31A225CEC64B720B8E579582F2749
                                                                                                                                                                                                                                                          SHA1:9C0151D9E2543C217CF8699FF5D4299A72E8F13C
                                                                                                                                                                                                                                                          SHA-256:6EAA336B13815A7FC18BCD6B9ADF722E794DA2888D053C229044784C8C8E9DE8
                                                                                                                                                                                                                                                          SHA-512:E6865655585E3D2D6839B56811F3FD86B454E8CD44E258BB1AC576AD245FF8A4D49FBB7F43458BA8A6C9DAAC8DFA923A176F0DD8A9976A11BEA09E6E2D17BF45
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Bindings for TScrollbar widget..#....namespace eval ttk::scrollbar {.. variable State.. # State(xPress).--.. # State(yPress).-- initial position of mouse at start of drag... # State(first).-- value of -first at start of drag...}....bind TScrollbar <Button-1> ..{ ttk::scrollbar::Press %W %x %y }..bind TScrollbar <B1-Motion>..{ ttk::scrollbar::Drag %W %x %y }..bind TScrollbar <ButtonRelease-1>.{ ttk::scrollbar::Release %W %x %y }....bind TScrollbar <Button-2> ..{ ttk::scrollbar::Jump %W %x %y }..bind TScrollbar <B2-Motion>..{ ttk::scrollbar::Drag %W %x %y }..bind TScrollbar <ButtonRelease-2>.{ ttk::scrollbar::Release %W %x %y }....# Redirect scrollwheel bindings to the scrollbar widget..#..# The shift-bindings scroll left/right (not up/down)..# if a widget has both possibilities..set eventList [list <MouseWheel> <Shift-MouseWheel>]..switch [tk windowingsystem] {.. aqua {.. lappend eventList <Option-MouseWheel> <Shift-Option-MouseWheel>.. }.. x11 {..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2503
                                                                                                                                                                                                                                                          Entropy (8bit):4.830288003879418
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:naLvMnAqeYQWYh7FvBrrbnMCfY/aVAbAigWAuFM0PfWAX20:nWQapprPnJY/8A8iRFdPtj
                                                                                                                                                                                                                                                          MD5:DD6A1737B14D3F7B2A0B4F8BE99C30AF
                                                                                                                                                                                                                                                          SHA1:E6B06895317E73CD3DC78234DD74C74F3DB8C105
                                                                                                                                                                                                                                                          SHA-256:E92D77B5CDCA2206376DB2129E87E3D744B3D5E31FDE6C0BBD44A494A6845CE1
                                                                                                                                                                                                                                                          SHA-512:B74AE92EDD53652F8A3DB0D84C18F9CE9069805BCAB0D3C2DBB537D7C241AA2681DA69B699D88A10029798D7B5BC015682F64699BA475AE6A379EEF23B48DAAF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Sizegrip widget bindings...#..# Dragging a sizegrip widget resizes the containing toplevel...#..# NOTE: the sizegrip widget must be in the lower right hand corner...#....switch -- [tk windowingsystem] {.. x11 -.. win32 {...option add *TSizegrip.cursor [ttk::cursor seresize] widgetDefault.. }.. aqua {.. .# Aqua sizegrips use default Arrow cursor... }..}....namespace eval ttk::sizegrip {.. variable State.. array set State {...pressed .0...pressX ..0...pressY ..0...width ..0...height ..0...widthInc.1...heightInc.1.. resizeX 1.. resizeY 1...toplevel .{}.. }..}....bind TSizegrip <Button-1> ..{ ttk::sizegrip::Press.%W %X %Y }..bind TSizegrip <B1-Motion> ..{ ttk::sizegrip::Drag .%W %X %Y }..bind TSizegrip <ButtonRelease-1> .{ ttk::sizegrip::Release %W %X %Y }....proc ttk::sizegrip::Press {W X Y} {.. variable State.... if {[$W instate disabled]} { return }.... set top [winfo toplevel $W].... # If the toplevel is not resi
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5003
                                                                                                                                                                                                                                                          Entropy (8bit):5.055050310142795
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:1qg/+yrjqA/K5ytxm1J1Ve6J1yQLUAzz/S76hrwxGGe2F:N/+yr2Gk1J1Ve6fxUAzDS76hrwxs2F
                                                                                                                                                                                                                                                          MD5:9C2833FAA9248F09BC2E6AB1BA326D59
                                                                                                                                                                                                                                                          SHA1:F13CF048FD706BBB1581DC80E33D1AAD910D93E8
                                                                                                                                                                                                                                                          SHA-256:DF286BB59F471AA1E19DF39AF0EF7AA84DF9F04DC4A439A747DD8BA43C300150
                                                                                                                                                                                                                                                          SHA-512:5FF3BE1E3D651C145950C3FC5B8C2E842211C937D1042173964383D4D59ECF5DD0EC39FF7771D029716F2D895F0B1A72591EF3BF7947FE64D4D6DB5F0B8ABFFB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# ttk::spinbox bindings..#....namespace eval ttk::spinbox { }....### Spinbox bindings...#..# Duplicate the Entry bindings, override if needed:..#....ttk::copyBindings TEntry TSpinbox....bind TSpinbox <Motion>...{ ttk::spinbox::Motion %W %x %y }..bind TSpinbox <Button-1> ..{ ttk::spinbox::Press %W %x %y }..bind TSpinbox <ButtonRelease-1> .{ ttk::spinbox::Release %W }..bind TSpinbox <Double-Button-1> .{ ttk::spinbox::DoubleClick %W %x %y }..bind TSpinbox <Triple-Button-1> .{} ;# disable TEntry triple-click....bind TSpinbox <Up>...{ event generate %W <<Increment>> }..bind TSpinbox <Down> ...{ event generate %W <<Decrement>> }....bind TSpinbox <<Increment>>..{ ttk::spinbox::Spin %W +1 }..bind TSpinbox <<Decrement>> ..{ ttk::spinbox::Spin %W -1 }....ttk::bindMouseWheel TSpinbox ..[list ttk::spinbox::MouseWheel %W]....## Motion --..#.Sets cursor...#..proc ttk::spinbox::Motion {w x y} {.. variable State.. ttk::saveCursor $w State(userConfCursor) [ttk::cursor text].. if { [$w ide
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10180
                                                                                                                                                                                                                                                          Entropy (8bit):4.886259798213254
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:FoTvMxHZZ1u2xj7+ZBHxjiXJv9IfwW+vr3UxjXEJDTF/MyLF3JcMzlsra2tYGa5P:mImAkRKYXMH59o4UbS30LWb
                                                                                                                                                                                                                                                          MD5:F705B3A292D02061DA0ABB4A8DD24077
                                                                                                                                                                                                                                                          SHA1:FD75C2250F6F66435444F7DEEF383C6397ED2368
                                                                                                                                                                                                                                                          SHA-256:C88B60FFB0F72E095F6FC9786930ADD7F9ED049EABC713F889F9A7DA516E188C
                                                                                                                                                                                                                                                          SHA-512:09817638DD3D3D5C57FA630C7EDF2F19C3956C9BD264DBF07627FA14A03AECD22D5A5319806E49EF1030204FADEF17C57CE8EAE4378A319AD2093321D9151C8F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# ttk::treeview widget bindings and utilities...#....namespace eval ttk::treeview {.. variable State.... # Enter/Leave/Motion.. #.. set State(activeWidget) .{}.. set State(activeHeading) .{}.... # Press/drag/release:.. #.. set State(pressMode) .none.. set State(pressX)..0.... # For pressMode == "resize".. set State(resizeColumn).#0.... # For pressmode == "heading".. set State(heading) .{}..}....### Widget bindings...#....bind Treeview.<Motion> ..{ ttk::treeview::Motion %W %x %y }..bind Treeview.<B1-Leave>..{ #nothing }..bind Treeview.<Leave>...{ ttk::treeview::ActivateHeading {} {}}..bind Treeview.<Button-1> ..{ ttk::treeview::Press %W %x %y }..bind Treeview.<Double-Button-1> .{ ttk::treeview::DoubleClick %W %x %y }..bind Treeview.<ButtonRelease-1> .{ ttk::treeview::Release %W %x %y }..bind Treeview.<B1-Motion> ..{ ttk::treeview::Drag %W %x %y }..bind Treeview .<Up> ..{ ttk::treeview::Keynav %W up }..bind Treeview .<Down> ..{ ttk::treeview
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4993
                                                                                                                                                                                                                                                          Entropy (8bit):4.954034141173847
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:lfxukTy5jPTq8LIgF2diyNTNR6nkrn4ijSSvNigyJ5612HtZG835MSvWOTRsHWU:BM+y5jrq8G/2nkEijSSvNigyJ5612Htw
                                                                                                                                                                                                                                                          MD5:AF45B2C8B43596D1BDECA5233126BD14
                                                                                                                                                                                                                                                          SHA1:A99E75D299C4579E10FCDD59389B98C662281A26
                                                                                                                                                                                                                                                          SHA-256:2C48343B1A47F472D1A6B9EE8D670CE7FB428DB0DB7244DC323FF4C7A8B4F64B
                                                                                                                                                                                                                                                          SHA-512:C8A8D01C61774321778AB149F6CA8DDA68DB69133CB5BA7C91938E4FD564160ECDCEC473222AFFB241304A9ACC73A36B134B3A602FD3587C711F2ADBB64AFA80
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Ttk widget set initialization script...#....### Source library scripts...#....namespace eval ::ttk {.. variable library.. if {![info exists library]} {...set library [file dirname [info script]].. }..}....source -encoding utf-8 [file join $::ttk::library fonts.tcl]..source -encoding utf-8 [file join $::ttk::library cursors.tcl]..source -encoding utf-8 [file join $::ttk::library utils.tcl]....## ttk::deprecated $old $new --..#.Define $old command as a deprecated alias for $new command..#.$old and $new must be fully namespace-qualified...#..proc ttk::deprecated {old new} {.. interp alias {} $old {} ttk::do'deprecate $old $new..}..## do'deprecate --..#.Implementation procedure for deprecated commands --..#.issue a warning (once), then re-alias old to new...#..proc ttk::do'deprecate {old new args} {.. deprecated'warning $old $new.. interp alias {} $old {} $new.. uplevel 1 [linsert $args 0 $new]..}....## deprecated'warning --..#.Gripe about use of deprecated comman
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):8624
                                                                                                                                                                                                                                                          Entropy (8bit):5.001791071900077
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:e0ebpSp+IZwnmTmpx8xzaHfw8K7LlJWQl8p7M+R5:rw0+WmpWxa/w9nlJHu
                                                                                                                                                                                                                                                          MD5:51086BC3315A4AE4A8591A654CFC3CEA
                                                                                                                                                                                                                                                          SHA1:2AC08309C63575B7A01FA62D3C262643CD8C823A
                                                                                                                                                                                                                                                          SHA-256:4AA041C050758B3331DC395381F7FBCE81E387908FC7A3C6107C4E7140F56F2E
                                                                                                                                                                                                                                                          SHA-512:6D69F7EAC9D5AF3B3EA85AE3E74BDFA6278789502D5E35EFE94349BFC543503BE7540D783D2632E349DD53F21074C702AC1FC487EE70C74234A08397F7238723
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Utilities for widget implementations...#....### Focus management...#..# See also: #1516479..#....## ttk::takefocus --..#.This is the default value of the "-takefocus" option..#.for ttk::* widgets that participate in keyboard navigation...#..# NOTES:..#.tk::FocusOK (called by tk_focusNext) tests [winfo viewable]..#.if -takefocus is 1, empty, or missing; but not if it's a..#.script prefix, so we have to check that here as well...#..#..proc ttk::takefocus {w} {.. expr {[$w instate !disabled] && [winfo viewable $w]}..}....## ttk::GuessTakeFocus --..#.This routine is called as a fallback for widgets..#.with a missing or empty -takefocus option...#..#.It implements the same heuristics as tk::FocusOK...#..proc ttk::GuessTakeFocus {w} {.. # Don't traverse to widgets with '-state disabled':.. #.. if {![catch {$w cget -state} state] && $state eq "disabled"} {...return 0.. }.... # Allow traversal to widgets with explicit key or focus bindings:.. #.. if {[regexp {Key|F
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9710
                                                                                                                                                                                                                                                          Entropy (8bit):4.6639701588183895
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:BktY1F+qXd95WSZaHFHRE3GRKFh2oaoT/ezKpqvYMHab:V1F+cd95WSZuhRE34KbPmKmY2ab
                                                                                                                                                                                                                                                          MD5:0AA7F8B43C3E07F3A4DA07FC6DF9A1B0
                                                                                                                                                                                                                                                          SHA1:153AFB735B10BBA16CFBE161777232F983845D90
                                                                                                                                                                                                                                                          SHA-256:EC5F203C69DF390E9B99944CF3526D6E77DC6F68E9B1A029F326A41AFED1EF81
                                                                                                                                                                                                                                                          SHA-512:5406553211CD6714C98EF7765ABD46424CCB013343EFF693FDD3AE6E0AAE9B5983446E0E1CC706D6B2C285084BF83D397306D3D52028CBBCFB8F369857C5B69C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Settings for Microsoft Windows Vista and Server 2008..#....# The Vista theme can only be defined on Windows Vista and above. The theme..# is created in C due to the need to assign a theme-enabled function for..# detecting when themeing is disabled. On systems that cannot support the..# Vista theme, there will be no such theme created and we must not..# evaluate this script.....if {"vista" ni [ttk::style theme names]} {.. return..}....namespace eval ttk::theme::vista {.... ttk::style theme settings vista {.... .ttk::style configure . \... -background SystemButtonFace \... -foreground SystemWindowText \... -selectforeground SystemHighlightText \... -selectbackground SystemHighlight \... -insertcolor SystemWindowText \... -font TkDefaultFont \... ;.....ttk::style map "." \... -foreground [list disabled SystemGrayText] \... ;.....ttk::style configure TButton -anchor center -padding {1 1} -width -11...ttk::style configure TRadiobutton -padding 2...ttk::
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2865
                                                                                                                                                                                                                                                          Entropy (8bit):4.917847108902527
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:b69VhW2gL5FPVWRzQsVqrEuF3yYrf7rfJF8xUqBgLt6g3ktO5jo4+iZ6O2htYtCW:bbXl+CEqZNNSxU0Ht2MR7W
                                                                                                                                                                                                                                                          MD5:769C0719A4044F91E7D132A25291E473
                                                                                                                                                                                                                                                          SHA1:6FB07B0C887D443A43FB15D5728920B578171219
                                                                                                                                                                                                                                                          SHA-256:AE82BCCCE708FF9C303CBCB3D4CC3FF5577A60D5B23822EA79E3E07CCE3CBBD1
                                                                                                                                                                                                                                                          SHA-512:47FED061DDC6B4EB63EF77901D0094FF2EBB1BAFACB3F44FBF13FB59DEA1EC83985B2862086ECF1A7957819A88A0FAA144B35F16BEA9356BBD9775070D42E636
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Settings for 'winnative' theme...#....namespace eval ttk::theme::winnative {.. ttk::style theme settings winnative {.....ttk::style configure "." \... -background SystemButtonFace \... -foreground SystemWindowText \... -selectforeground SystemHighlightText \... -selectbackground SystemHighlight \... -fieldbackground SystemWindow \... -insertcolor SystemWindowText \... -troughcolor SystemScrollbar \... -font TkDefaultFont \... ;.....ttk::style map "." -foreground [list disabled SystemGrayText] ;.. ttk::style map "." -embossed [list disabled 1] ;.....ttk::style configure TButton \... -anchor center -width -11 -relief raised -shiftrelief 1...ttk::style configure TCheckbutton -padding "2 4"...ttk::style configure TRadiobutton -padding "2 4"...ttk::style configure TMenubutton \... -padding "8 4" -arrowsize 3 -relief raised.....ttk::style map TButton -relief {{!disabled pressed} sunken}.....ttk::style configure TEntry \... -padding 2 -select
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2103
                                                                                                                                                                                                                                                          Entropy (8bit):4.9805308941424355
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:aaiIu89VhW2gLRWJyO514rf+rfzxTrf/MW+iZ6O2htYtCp:XoXAk21nxQ7p
                                                                                                                                                                                                                                                          MD5:162F30D2716438C75EA16B57E6F63088
                                                                                                                                                                                                                                                          SHA1:3F626FF0496BB16B27106BED7E38D1C72D1E3E27
                                                                                                                                                                                                                                                          SHA-256:AEDB21C6B2909A4BB4686837D2126E521A8CC2B38414A4540387B801EBD75466
                                                                                                                                                                                                                                                          SHA-512:6EBF9648F1381D04F351BB469B6E3A38F3D002189C92EAF80A18D65632037FF37D34EC8814BBF7FAE34553645BFC13985212F24684EE8C4E205729B975C88C97
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:#..# Settings for 'xpnative' theme..#....namespace eval ttk::theme::xpnative {.... ttk::style theme settings xpnative {.....ttk::style configure . \... -background SystemButtonFace \... -foreground SystemWindowText \... -selectforeground SystemHighlightText \... -selectbackground SystemHighlight \... -insertcolor SystemWindowText \... -font TkDefaultFont \... ;.....ttk::style map "." \... -foreground [list disabled SystemGrayText] \... ;.....ttk::style configure TButton -anchor center -padding {1 1} -width -11...ttk::style configure TRadiobutton -padding 2...ttk::style configure TCheckbutton -padding 2...ttk::style configure TMenubutton -padding {8 4}.....ttk::style configure TNotebook -tabmargins {2 2 2 0}...ttk::style map TNotebook.Tab \... -expand [list selected {2 2 2 2}].....ttk::style configure TLabelframe.Label -foreground "#0046d5".....# OR: -padding {3 3 3 6}, which some apps seem to use....ttk::style configure TEntry -padding {2 2 2 4}...ttk::
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10521
                                                                                                                                                                                                                                                          Entropy (8bit):5.0647027375963996
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:1Y3uWEXm/swEePmJhRAXd1hTHsHG2ML/9Lm2daM0Hu:8hodMiM0Hu
                                                                                                                                                                                                                                                          MD5:508F7E258C04970FAE526990168CB773
                                                                                                                                                                                                                                                          SHA1:33785204B18C0E0F5CDCB5B49399B5907351FDB8
                                                                                                                                                                                                                                                          SHA-256:B463B366F139DDF7FED31F34C6D2341F9F27845A1A358011DFC801E1333B1828
                                                                                                                                                                                                                                                          SHA-512:A12985B58DD1D46297119CED47B7F44EF4139CED6C36FD028E66DD657E5ED0663B744C679A5BF7A39B39D17A32E1280D2945F6B9AD59AEF20436F68040F6070C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# unsupported.tcl --..#..# Commands provided by Tk without official support. Use them at your..# own risk. They may change or go away without notice...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....# ----------------------------------------------------------------------..# Unsupported compatibility interface for folks accessing Tk's private..# commands and variable against recommended usage...# ----------------------------------------------------------------------....namespace eval ::tk::unsupported {.... # Map from the old global names of Tk private commands to their.. # new namespace-encapsulated names..... variable PrivateCommands.. array set PrivateCommands {...tkButtonAutoInvoke..::tk::ButtonAutoInvoke...tkButtonDown...::tk::ButtonDown...tkButtonEnter...::tk::ButtonEnter...tkButtonInvoke...::tk::ButtonInvoke...tkButtonLeave...::tk::ButtonLeave...tkButtonUp...::tk::ButtonUp...tk
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):26991
                                                                                                                                                                                                                                                          Entropy (8bit):4.974180990171971
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:0BLzjXhss64XKNFXm39QJ63nwFiHLgRIdNPCRE5phLtffsNP4XWdxWk+I5oP9jNR:0BvjXoFCB3flLCRE5phLCP3xWq8vWTod
                                                                                                                                                                                                                                                          MD5:FA99EF44FAA88A6BA1967A1257DEB97B
                                                                                                                                                                                                                                                          SHA1:CC99DBF678F4169A90ACC5A89C6F8DAB48052EC6
                                                                                                                                                                                                                                                          SHA-256:C4722EADEDE763FA52E7937D40067B0F8EB86B7A4B707F90212ED3E5289690D0
                                                                                                                                                                                                                                                          SHA-512:3AF16095784908A444CD61EEF178A30B9FED9C20AA91D94044A3AECB6047267FB80BCE790FC1F28FB19AEF664A6618FD832612F541FDADCC34B6C01E92E5EA40
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# xmfbox.tcl --..#..#.Implements the "Motif" style file selection dialog for the..#.Unix platform. This implementation is used only if the..#."::tk_strictMotif" flag is set...#..# Copyright (c) 1996 Sun Microsystems, Inc...# Copyright (c) 1998-2000 Scriptics Corporation..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::file {}......# ::tk::MotifFDialog --..#..#.Implements a file dialog similar to the standard Motif file..#.selection box...#..# Arguments:..#.type.."open" or "save"..#.args..Options parsed by the procedure...#..# Results:..#.When -multiple is set to 0, this returns the absolute pathname..#.of the selected file. (NOTE: This is not the same as a single..#.element list.)..#..#.When -multiple is set to > 0, this returns a Tcl list of absolute..# pathnames. The argument for -multiple is ignored, but for consistency..#
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):66320
                                                                                                                                                                                                                                                          Entropy (8bit):6.282149407992637
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:Lx2s2VF41qe6gwfdHd5MlU9oBilPrdIJvSi7Sy7z:Lv2VNe6Lfd9alPIlPrdIJvSiJ
                                                                                                                                                                                                                                                          MD5:EDFFCEA2091A5661F451CCD83AD4527D
                                                                                                                                                                                                                                                          SHA1:F81847C0ADC0F58134B195A13486D851911FC516
                                                                                                                                                                                                                                                          SHA-256:A6851D7C25A1216D2C8FA5C1D2E9ECA3D0392D60E3B7441AD9F66C23FFDD2F08
                                                                                                                                                                                                                                                          SHA-512:ABC9FBF7BFBD705016A9D0430243358A1E8F7C4E398B6BA0FC5B1A147F0A1F635E27B859D742E4184AE9D396A68572B169476703312BABC3E7530D698FF9AB48
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........@..@..@..I._.F..PT.B..PT.C..PT.H..PT.M...U.B.....B../Q.E..@......U..B...U.A...U3.A...U.A..Rich@..........PE..d......g.........." ...).n...j.......................................................@....`.............................................P.............................../......0.......T...............................@...............x............................text....l.......n.................. ..`.rdata..jB.......D...r..............@..@.data... ...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..0...........................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38160
                                                                                                                                                                                                                                                          Entropy (8bit):6.338856805460127
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:fEkK9VgWOZbs3550QcJpPllIJLiX5YiSyvQ602Euf0:fE93jkbQcJvlIJLiJ7Syq00
                                                                                                                                                                                                                                                          MD5:1C30CC7DF3BD168D883E93C593890B43
                                                                                                                                                                                                                                                          SHA1:31465425F349DAE4EDAC9D0FEABC23CE83400807
                                                                                                                                                                                                                                                          SHA-256:6435C679A3A3FF4F16708EBC43F7CA62456C110AC1EA94F617D8052C90C143C7
                                                                                                                                                                                                                                                          SHA-512:267A1807298797B190888F769D998357B183526DFCB25A6F1413E64C5DCCF87F51424B7E5D6F2349D7A19381909AB23B138748D8D9F5858F7DC0552F5C5846AC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........H2.&a.&a.&a..a.&a..'`.&a..%`.&a.."`.&a..'`.&a..#`.&a..'`.&a.'a..&a.."`.&a../`.&a..&`.&a...a.&a..$`.&aRich.&a................PE..d.....g.........." ...).,...<.......)..............................................'.....`.........................................0V..H...xV.......................f.../......x...tG..T............................C..@............@.......T..@....................text....*.......,.................. ..`.rdata..d ...@..."...0..............@..@.data........p.......R..............@....pdata...............V..............@..@.rsrc................Z..............@..@.reloc..x............d..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Zip archive data, at least v2.0 to extract, compression method=store
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1394456
                                                                                                                                                                                                                                                          Entropy (8bit):5.531698507573688
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:IW7WpLV6yNLeGQbVz3YQfiBgDPtLwjFx278e6ZQnHS91lqyL+DXUgnxOr+dx5/GO:B7WpLtHa9BHSHAW+dx5/GP05vddD
                                                                                                                                                                                                                                                          MD5:A9CBD0455B46C7D14194D1F18CA8719E
                                                                                                                                                                                                                                                          SHA1:E1B0C30BCCD9583949C247854F617AC8A14CBAC7
                                                                                                                                                                                                                                                          SHA-256:DF6C19637D239BFEDC8CD13D20E0938C65E8FDF340622FF334DB533F2D30FA19
                                                                                                                                                                                                                                                          SHA-512:B92468E71490A8800E51410DF7068DD8099E78C79A95666ECF274A9E9206359F049490B8F60B96081FAFD872EC717E67020364BCFA972F26F0D77A959637E528
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:PK..........!..b.e............_collections_abc.pyc......................................\.....S.r.S.S.K.J.r.J.r. .S.S.K.r.\.".\.\.....5.......r.\.".S.5.......r.S...r.\.".\.5.......r.C./.S.Q.r.S.r.\.".\.".S.5.......5.......r.\.".\.".\.".5.......5.......5.......r.\.".\.".0.R%..................5.......5.......5.......r.\.".\.".0.R)..................5.......5.......5.......r.\.".\.".0.R-..................5.......5.......5.......r.\.".\."./.5.......5.......r.\.".\.".\."./.5.......5.......5.......r.\.".\.".\.".S.5.......5.......5.......r.\.".\.".\.".S.S.-...5.......5.......5.......r.\.".\.".\.".5.......5.......5.......r.\.".\.".S.5.......5.......r \.".\.".S.5.......5.......r!\.".\.".\"".5.......5.......5.......r#\.".0.R%..................5.......5.......r$\.".0.R)..................5.......5.......r%\.".0.R-..................5.......5.......r&\.".\.RN..................5.......r(S...r)\)".5.......r*C)\.".S...".5.......5.......r+S...r,\,".5.......r,\.".\,5.......r-\,R]..................5.......
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):521216
                                                                                                                                                                                                                                                          Entropy (8bit):6.367473142339346
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:C+p4hUGVgCLWA6ntGLFOFlUGoKW1N9T/oqVB/Lok66FeCuBIw3nGYJsI:zpxG5Gt8FcA3xAETG/OI
                                                                                                                                                                                                                                                          MD5:0CB9AC2F2843183D4F1790E8D8BDC825
                                                                                                                                                                                                                                                          SHA1:AFC8A1139F91BFEE0C093B4F6529A45984F320D3
                                                                                                                                                                                                                                                          SHA-256:2D0776ED8B164C420BC0D7AB4661C05831D3CAA88A2537D7A321A9DDF2159974
                                                                                                                                                                                                                                                          SHA-512:D5BED3DC5FB3A0F2FA758D9DEE0DFA5ADFD09B14C816B997BF33407293FD34CB7C11214A4D819CF76BA3CEFF5DA0BC22EBC3F7ACD69CF142AD70092E4AAA7DA4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.....................D.....+......+......+......+......(...../.........J...i+...........i+.....i+.....Rich...........................PE..d...-FGg.........." ...*.....J.......2....................................... ............`.............................................L...,....................K.....................T.......................(.......@...............X............................text............................... ..`.rdata..x...........................@..@.data...............................@....pdata...K.......L..................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):299427
                                                                                                                                                                                                                                                          Entropy (8bit):6.047872935262006
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:QW1x/M8fRR1jplkXURrVADwYCuCigT/QRSRqNb7d8iu5Nahx:QWb/TRJLWURrI5RWavdF08/
                                                                                                                                                                                                                                                          MD5:50EA156B773E8803F6C1FE712F746CBA
                                                                                                                                                                                                                                                          SHA1:2C68212E96605210EDDF740291862BDF59398AEF
                                                                                                                                                                                                                                                          SHA-256:94EDEB66E91774FCAE93A05650914E29096259A5C7E871A1F65D461AB5201B47
                                                                                                                                                                                                                                                          SHA-512:01ED2E7177A99E6CB3FBEF815321B6FA036AD14A3F93499F2CB5B0DAE5B713FD2E6955AA05F6BDA11D80E9E0275040005E5B7D616959B28EFC62ABB43A3238F0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:.# Issuer: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Subject: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Label: "GlobalSign Root CA".# Serial: 4835703278459707669005204.# MD5 Fingerprint: 3e:45:52:15:09:51:92:e1:b7:5d:37:9f:b1:87:29:8a.# SHA1 Fingerprint: b1:bc:96:8b:d4:f4:9d:62:2a:a8:9a:81:f2:15:01:52:a4:1d:82:9c.# SHA256 Fingerprint: eb:d4:10:40:e4:bb:3e:c7:42:c9:e3:81:d3:1e:f2:a4:1a:48:b6:68:5c:96:e7:ce:f3:c1:df:6c:d4:33:1c:99.-----BEGIN CERTIFICATE-----.MIIDdTCCAl2gAwIBAgILBAAAAAABFUtaw5QwDQYJKoZIhvcNAQEFBQAwVzELMAkG.A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv.b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw05ODA5MDExMjAw.MDBaFw0yODAxMjgxMjAwMDBaMFcxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9i.YWxTaWduIG52LXNhMRAwDgYDVQQLEwdSb290IENBMRswGQYDVQQDExJHbG9iYWxT.aWduIFJvb3QgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDaDuaZ.jc6j40+Kfvvxi4Mla+pIH/EqsLmVEQS98GPR4mdmzxzdzxtIK+6NiY6arymAZavp.xy0Sy6scTHAHoT0KMM0VjU/43dSMUBUc71DuxC73/OlS8pF94G3VNTCOXkNz
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10752
                                                                                                                                                                                                                                                          Entropy (8bit):4.818583535960129
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:Mvs10hZd9D74ACb0xx2uKynu10YLsgxwJiUNiL0U5IZsJFPGDtCFCCQAADo+cX6m:MXv9XFCk2z1/t12iwU5usJFuCyPcqgE
                                                                                                                                                                                                                                                          MD5:56FE4F6C7E88212161F49E823CCC989A
                                                                                                                                                                                                                                                          SHA1:16D5CBC5F289AD90AEAA4FF7CB828627AC6D4ACF
                                                                                                                                                                                                                                                          SHA-256:002697227449B6D69026D149CFB220AC85D83B13056C8AA6B9DAC3FD3B76CAA4
                                                                                                                                                                                                                                                          SHA-512:7C9D09CF9503F73E6F03D30E54DBB50606A86D09B37302DD72238880C000AE2B64C99027106BA340753691D67EC77B3C6E5004504269508F566BDB5E13615F1E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........k............r_...........r................................................3..........Rich....................PE..d....$.g.........." ...).....................................................p............`..........................................'..p...`(..d....P.......@...............`..,...`#.............................. "..@............ ...............................text............................... ..`.rdata....... ......................@..@.data........0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......&..............@..@.reloc..,....`.......(..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):124928
                                                                                                                                                                                                                                                          Entropy (8bit):5.953784637413928
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:JDE+0ov6ojgN3qN8h51Zlh+YW5E38vCsmLS:JdefPZE2ICDLS
                                                                                                                                                                                                                                                          MD5:10116447F9276F10664BA85A5614BA3A
                                                                                                                                                                                                                                                          SHA1:EFD761A3E6D14E897D37AFB0C7317C797F7AE1D6
                                                                                                                                                                                                                                                          SHA-256:C393098E7803ABF08EE8F7381AD7B0F8FAFFBF66319C05D72823308E898F8CFC
                                                                                                                                                                                                                                                          SHA-512:C04461E52B7FE92D108CBDEB879B7A8553DD552D79C88DFA3F5D0036EED8D4B8C839C0BF2563BC0C796F8280ED2828CA84747CB781D2F26B44214FCA2091EAE4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........y.....................7...............7.......7.......7.......6..........D....6.......6.......6.......6......Rich............................PE..d....$.g.........." ...).@...........C.......................................0............`.........................................0...d.................................... ......................................P...@............P...............................text....?.......@.................. ..`.rdata..nY...P...Z...D..............@..@.data....=.......0..................@....pdata..............................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4
                                                                                                                                                                                                                                                          Entropy (8bit):1.5
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Mn:M
                                                                                                                                                                                                                                                          MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                                                                          SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                                                                          SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                                                                          SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:pip.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5440
                                                                                                                                                                                                                                                          Entropy (8bit):5.074230645519915
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:DloQIUQIhQIKQILbQIRIaMPktjaVxsxA2TLLDmplH7dwnqTIvrUmA0JQTQCQx5KN:RcPuP1srTLLDmplH7JTIvYX0JQTQ9x54
                                                                                                                                                                                                                                                          MD5:C891CD93024AF027647E6DE89D0FFCE2
                                                                                                                                                                                                                                                          SHA1:01D8D6F93F1B922A91C82D4711BCEFB885AD47B0
                                                                                                                                                                                                                                                          SHA-256:EB36E0E4251E8479EF36964440755EF22BEDD411BA87A93F726FA8E5BB0E64B0
                                                                                                                                                                                                                                                          SHA-512:3386FBB3DCF7383B2D427093624C531C50BE34E3E0AA0984547B953E04776D0D431D5267827F4194A9B0AD1AB897869115623E802A6A1C5D2AE1AD82C96CCE71
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:Metadata-Version: 2.3.Name: cryptography.Version: 43.0.3.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: Apache Software License.Classifier: License :: OSI Approved :: BSD License.Classifier: Natural Language :: English.Classifier: Operating System :: MacOS :: MacOS X.Classifier: Operating System :: POSIX.Classifier: Operating System :: POSIX :: BSD.Classifier: Operating System :: POSIX :: Linux.Classifier: Operating System :: Microsoft :: Windows.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: 3.7.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Classifier: Programming Language :: Python :: 3.12.Classif
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:CSV text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):15579
                                                                                                                                                                                                                                                          Entropy (8bit):5.5670696451446435
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:1XeTB7oz5jF4EHRThXsI4WPm6LciTwqU+NX6in5hqw/t+B:1Xk7ohCE3sIPm6LciTwqU+96inhgB
                                                                                                                                                                                                                                                          MD5:6BA7EACDC603A21F205A9F4CF0FBF12E
                                                                                                                                                                                                                                                          SHA1:55CEB7C05E30C49B582E7B2C4CE03E2FE9351CC1
                                                                                                                                                                                                                                                          SHA-256:4AE8807DEAA2C41CB02FFB19601220AF425EA392D97375B85F18D1449F67F44F
                                                                                                                                                                                                                                                          SHA-512:E621D6059D456940A953E7FA12D90988F9E14D3CD41018EEFB1788514B580A589860306A3818AB8B2CDEF3FE3A341E8324B4F2F31EB64D249BBF46E8E9894C3D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:cryptography-43.0.3.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..cryptography-43.0.3.dist-info/METADATA,sha256=6zbg5CUehHnvNpZEQHVe8ivt1BG6h6k_cm-o5bsOZLA,5440..cryptography-43.0.3.dist-info/RECORD,,..cryptography-43.0.3.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..cryptography-43.0.3.dist-info/WHEEL,sha256=8_4EnrLvbhzH224YH8WypoB7HFn-vpbwr_zHlr3XUBI,94..cryptography-43.0.3.dist-info/license_files/LICENSE,sha256=Pgx8CRqUi4JTO6mP18u0BDLW8amsv4X1ki0vmak65rs,197..cryptography-43.0.3.dist-info/license_files/LICENSE.APACHE,sha256=qsc7MUj20dcRHbyjIJn2jSbGRMaBOuHk8F9leaomY_4,11360..cryptography-43.0.3.dist-info/license_files/LICENSE.BSD,sha256=YCxMdILeZHndLpeTzaJ15eY9dz2s0eymiSMqtwCPtPs,1532..cryptography/__about__.py,sha256=-FkHKD9mSuEfH37wsSKnQzJZmL5zUAUTpB5OeUQjPE0,445..cryptography/__init__.py,sha256=mthuUrTd4FROCpUYrTIqhjz6s6T9djAZrV7nZ1oMm2o,364..cryptography/__pycache__/__about__.cpython-313.pyc,,..cryptography/__pycache__/__ini
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):94
                                                                                                                                                                                                                                                          Entropy (8bit):5.016084900984752
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:RtEeX5pGogP+tkKciH/KQb:RtvoTWKTQb
                                                                                                                                                                                                                                                          MD5:C869D30012A100ADEB75860F3810C8C9
                                                                                                                                                                                                                                                          SHA1:42FD5CFA75566E8A9525E087A2018E8666ED22CB
                                                                                                                                                                                                                                                          SHA-256:F3FE049EB2EF6E1CC7DB6E181FC5B2A6807B1C59FEBE96F0AFFCC796BDD75012
                                                                                                                                                                                                                                                          SHA-512:B29FEAF6587601BBE0EDAD3DF9A87BFC82BB2C13E91103699BABD7E039F05558C0AC1EF7D904BCFAF85D791B96BC26FA9E39988DD83A1CE8ECCA85029C5109F0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:Wheel-Version: 1.0.Generator: maturin (1.7.0).Root-Is-Purelib: false.Tag: cp39-abi3-win_amd64.
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):197
                                                                                                                                                                                                                                                          Entropy (8bit):4.61968998873571
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:hWDncJhByZmJgXPForADu1QjygQuaAJygT2d5GeWreLRuOFEXAYeBKmJozlMHuO:h9Co8FyQjkDYc5tWreLBF/pn2mH1
                                                                                                                                                                                                                                                          MD5:8C3617DB4FB6FAE01F1D253AB91511E4
                                                                                                                                                                                                                                                          SHA1:E442040C26CD76D1B946822CAF29011A51F75D6D
                                                                                                                                                                                                                                                          SHA-256:3E0C7C091A948B82533BA98FD7CBB40432D6F1A9ACBF85F5922D2F99A93AE6BB
                                                                                                                                                                                                                                                          SHA-512:77A1919E380730BCCE5B55D76FBFFBA2F95874254FAD955BD2FE1DE7FC0E4E25B5FDAAB0FEFFD6F230FA5DC895F593CF8BFEDF8FDC113EFBD8E22FADAB0B8998
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:This software is made available under the terms of *either* of the licenses.found in LICENSE.APACHE or LICENSE.BSD. Contributions to cryptography are made.under the terms of *both* these licenses..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11360
                                                                                                                                                                                                                                                          Entropy (8bit):4.426756947907149
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:nUDG5KXSD9VYUKhu1JVF9hFGvV/QiGkS594drFjuHYx5dvTrLh3kTSEnQHbHR:UIvlKM1zJlFvmNz5VrlkTS0QHt
                                                                                                                                                                                                                                                          MD5:4E168CCE331E5C827D4C2B68A6200E1B
                                                                                                                                                                                                                                                          SHA1:DE33EAD2BEE64352544CE0AA9E410C0C44FDF7D9
                                                                                                                                                                                                                                                          SHA-256:AAC73B3148F6D1D7111DBCA32099F68D26C644C6813AE1E4F05F6579AA2663FE
                                                                                                                                                                                                                                                          SHA-512:F451048E81A49FBFA11B49DE16FF46C52A8E3042D1BCC3A50AAF7712B097BED9AE9AED9149C21476C2A1E12F1583D4810A6D36569E993FE1AD3879942E5B0D52
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:. Apache License. Version 2.0, January 2004. https://www.apache.org/licenses/.. TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION.. 1. Definitions... "License" shall mean the terms and conditions for use, reproduction,. and distribution as defined by Sections 1 through 9 of this document... "Licensor" shall mean the copyright owner or entity authorized by. the copyright owner that is granting the License... "Legal Entity" shall mean the union of the acting entity and all. other entities that control, are controlled by, or are under common. control with that entity. For the purposes of this definition,. "control" means (i) the power, direct or indirect, to cause the. direction or management of such entity, whether by contract or. otherwise, or (ii) ownership of fifty percent (50%) or more of the. outstanding shares, or (iii) beneficial ow
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1532
                                                                                                                                                                                                                                                          Entropy (8bit):5.058591167088024
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:MjUnoorbOFFTJJyRrYFTjzMbmqEvBTP4m96432s4EOkUTKQROJ32s3yxsITf+3tY:MkOFJSrYJsaN5P406432svv32s3EsIqm
                                                                                                                                                                                                                                                          MD5:5AE30BA4123BC4F2FA49AA0B0DCE887B
                                                                                                                                                                                                                                                          SHA1:EA5B412C09F3B29BA1D81A61B878C5C16FFE69D8
                                                                                                                                                                                                                                                          SHA-256:602C4C7482DE6479DD2E9793CDA275E5E63D773DACD1ECA689232AB7008FB4FB
                                                                                                                                                                                                                                                          SHA-512:DDBB20C80ADBC8F4118C10D3E116A5CD6536F72077C5916D87258E155BE561B89EB45C6341A1E856EC308B49A4CB4DBA1408EABD6A781FBE18D6C71C32B72C41
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:Copyright (c) Individual contributors..All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are met:.. 1. Redistributions of source code must retain the above copyright notice,. this list of conditions and the following disclaimer... 2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... 3. Neither the name of PyCA Cryptography nor the names of its contributors. may be used to endorse or promote products derived from this software. without specific prior written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND.ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOS
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7834624
                                                                                                                                                                                                                                                          Entropy (8bit):6.517862303223651
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:49152:oFNZj7fIo9W67PapgzJTkrXyzNzpXAbuiqCgIns3mYEXEqMrIU6i7GtlqdVwASO/:QI9X/gIFYEXME+oFNr5VQCJheq4BsxH
                                                                                                                                                                                                                                                          MD5:BFD28B03A4C32A9BCB001451FD002F67
                                                                                                                                                                                                                                                          SHA1:DD528FD5F4775E16B2E743D3188B66F1174807B2
                                                                                                                                                                                                                                                          SHA-256:8EF0F404A8BFF12FD6621D8F4F209499613F565777FE1C2A680E8A18F312D5A7
                                                                                                                                                                                                                                                          SHA-512:6DC39638435F147B399826E34F78571D7ED2ED1232275E213A2B020224C0645E379F74A0CA5DE86930D3348981C8BB03BBBECFA601F8BA781417E7114662DDEE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......r.b.6...6...6...?..$...&9..4...&9..2...&9..>...&9..'...}...8...Y<..5...6...2...~8..I...6.......~8..7...~8..7...Rich6...........PE..d......g.........." ...)..Y..$........W.......................................w...........`..........................................q.....l.q.............. s...............w......zi.T....................{i.(...Pyi.@.............Y..............................text...k.Y.......Y................. ..`.rdata...A....Y..B....Y.............@..@.data...@+....q.......q.............@....pdata....... s.......r.............@..@.reloc........w.......v.............@..B........................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5232408
                                                                                                                                                                                                                                                          Entropy (8bit):5.940072183736028
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:98304:/V+Qs2NuR5YV0L8PQ1CPwDvt3uFlDC4SC9c:9rs2NuDYV0L841CPwDvt3uFlDC4SCa
                                                                                                                                                                                                                                                          MD5:123AD0908C76CCBA4789C084F7A6B8D0
                                                                                                                                                                                                                                                          SHA1:86DE58289C8200ED8C1FC51D5F00E38E32C1AAD5
                                                                                                                                                                                                                                                          SHA-256:4E5D5D20D6D31E72AB341C81E97B89E514326C4C861B48638243BDF0918CFA43
                                                                                                                                                                                                                                                          SHA-512:80FAE0533BA9A2F5FA7806E86F0DB8B6AAB32620DDE33B70A3596938B529F3822856DE75BDDB1B06721F8556EC139D784BC0BB9C8DA0D391DF2C20A80D33CB04
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........._~.._~.._~..V.S.M~.....]~.....[~.....W~.....S~.._~...~......T~..J....~..J...7}..J...^~..J.?.^~..J...^~..Rich_~..........................PE..d......f.........." ...(..7..<......v........................................0P.......O...`...........................................H.0.....O.@....@O.|.... L. .....O../...PO.$...`{D.8............................yD.@.............O..............................text.....7.......7................. ..`.rdata........7.......7.............@..@.data...Ao....K..<....K.............@....pdata....... L.......K.............@..@.idata...%....O..&....N.............@..@.00cfg..u....0O.......N.............@..@.rsrc...|....@O.......N.............@..@.reloc..~....PO.......N.............@..B................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):39696
                                                                                                                                                                                                                                                          Entropy (8bit):6.641880464695502
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:NiQfxQemQJNrPN+moyijAc5YiSyvkIPxWEqG:dfxIQvPkmoyijP7SytPxF
                                                                                                                                                                                                                                                          MD5:0F8E4992CA92BAAF54CC0B43AACCCE21
                                                                                                                                                                                                                                                          SHA1:C7300975DF267B1D6ADCBAC0AC93FD7B1AB49BD2
                                                                                                                                                                                                                                                          SHA-256:EFF52743773EB550FCC6CE3EFC37C85724502233B6B002A35496D828BD7B280A
                                                                                                                                                                                                                                                          SHA-512:6E1B223462DC124279BFCA74FD2C66FE18B368FFBCA540C84E82E0F5BCBEA0E10CC243975574FA95ACE437B9D8B03A446ED5EE0C9B1B094147CEFAF704DFE978
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........iV...8...8...8..p....8.t9...8.p9...8...9...8.t=...8.t<...8.t;...8.1t<...8.1t;...8.1t8...8.1t:...8.Rich..8.........................PE..d...Sh.c.........." ...".H...(.......L...............................................n....`......................................... l.......p..P...............P....l.../......,...@d...............................c..@............`.. ............................text....G.......H.................. ..`.rdata..h....`.......L..............@..@.data................b..............@....pdata..P............d..............@..@.reloc..,............j..............@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):792856
                                                                                                                                                                                                                                                          Entropy (8bit):5.57949182561317
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:7LN1sdyIzHHZp5c3nlUa6lxzAG11rbmFe9Xbv:7LgfzH5I3nlUa2AU2Fe9Xbv
                                                                                                                                                                                                                                                          MD5:4FF168AAA6A1D68E7957175C8513F3A2
                                                                                                                                                                                                                                                          SHA1:782F886709FEBC8C7CEBCEC4D92C66C4D5DBCF57
                                                                                                                                                                                                                                                          SHA-256:2E4D35B681A172D3298CAF7DC670451BE7A8BA27C26446EFC67470742497A950
                                                                                                                                                                                                                                                          SHA-512:C372B759B8C7817F2CBB78ECCC5A42FA80BDD8D549965BD925A97C3EEBDCE0335FBFEC3995430064DEAD0F4DB68EBB0134EB686A0BE195630C49F84B468113E3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........l.>..|m..|m..|m.u.m..|m+.}l..|m.u}l..|m+..l..|m+.xl..|m+.yl..|m..}l..|m..}m..|m..xl..|m..|l..|m...m..|m..~l..|mRich..|m................PE..d......f.........." ...(.>..........K........................................0......!+....`..........................................x...Q..............s.... ...M......./......d...p...8...............................@............................................text....<.......>.................. ..`.rdata..hz...P...|...B..............@..@.data...qN.......H..................@....pdata..pV... ...X..................@..@.idata...c.......d...^..............@..@.00cfg..u...........................@..@.rsrc...s...........................@..@.reloc..C...........................@..B........................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20269568
                                                                                                                                                                                                                                                          Entropy (8bit):6.26223001093884
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:196608:YkRyLOBd+wrOzPW0K+VT2XZgBdeYzPXCt6eRe:YOOzPWy8kd7Xa6I
                                                                                                                                                                                                                                                          MD5:DA1EA9BEB18A0598191B523CBB725056
                                                                                                                                                                                                                                                          SHA1:1C0BB78A52723FEA8804BB4F5C4103622BCE6C3D
                                                                                                                                                                                                                                                          SHA-256:7A62620B556F4A485CA273E34F0E224F345DA4530D15029C74BA6EA5DE878934
                                                                                                                                                                                                                                                          SHA-512:B12C7EAEC2A83878503814C511EC66E0B864D92E3A75AE171025136DE4329586B89E8C1840987AE30332A2EA216819A22083A29C4730A4CD4AA99247AB817EFA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......f..........."...$..+..F5..$..P........................................5......U5...`... .......................................1.DO...`5.d.............0..#............5.l............................e0.(...................lf5.@............................text.....+.......+.................`.``.data........0+......"+.............@.`..rdata........+.......+.............@.p@.pdata...#....0..$...d0.............@.0@.xdata..,"....0..$....0.............@.0@.bss.... "....0.......................`..edata..DO....1..P....0.............@.0@.idata..d....`5.......4.............@.0..CRT....`.....5.......5.............@.@..tls..........5.......5.............@.@..reloc..l.....5..0....5.............@.0B........................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):585384
                                                                                                                                                                                                                                                          Entropy (8bit):6.565977665822063
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:SSTTigI46Bb3SUPvRgrKtzL4oaQEKZm+jWodEEVPLwtQi:SUStZaQEKZm+jWodEE9CQi
                                                                                                                                                                                                                                                          MD5:4DC9DA003ED0E3E9E7CFF3B1109470E3
                                                                                                                                                                                                                                                          SHA1:55A06DD5DBB0FE4E4762F1871903134EDD3EC7A4
                                                                                                                                                                                                                                                          SHA-256:66FA570BD6B879AA491F6E45A3E576C3EC7F5FE31ED0EBA8B7D81F88C3B01680
                                                                                                                                                                                                                                                          SHA-512:BDCA95ECB2BE5A5E14C650E8776914DAB60D277E923F3CAFC56B77C3D8055C72B2DDC45D8B3EF1B5BD8D9F52BA097C595AD25E07AB847B6CFEFF9858C5D6A42A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........)...H...H...H...0...H...0...H...H...H......H......H......H....._H......H....w..H......H..Rich.H..................PE..d...c/..........." ...(.6...X......0.....................................................`A.........................................2..h...X...,............p.. :...v...x..............p...........................`...@............P..x............................text....4.......6.................. ..`.rdata.......P.......:..............@..@.data...p8...0......................@....pdata.. :...p...<...,..............@..@.rsrc................h..............@..@.reloc...............l..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):63488
                                                                                                                                                                                                                                                          Entropy (8bit):6.037791685676174
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:8qBGC2YjK+ibtvEPGFt2KNCmH7YvCeC9p:8ffTb2KNCmH7YvCeC9p
                                                                                                                                                                                                                                                          MD5:DFC2F3E813E56639959D442754AB82F2
                                                                                                                                                                                                                                                          SHA1:3533217940BC771FCCE37D3ADA24447DC6B0C3CB
                                                                                                                                                                                                                                                          SHA-256:2AD31D78EDB98E52CBA7006C107FC0D2E89163D414CCAD463833C285D2CC93BD
                                                                                                                                                                                                                                                          SHA-512:B6278974F207A5F0FC21934F03CBA2E6AE2E33107D4BDAAF9F25EBF07072D19F1959F955CA3B0B8294EE3E0476C9035DF7A6AD4C082CE9D29708D93088FD5D9F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".........P..............................................@......P.....`.................................................,................ ..d............0..p...`...................................8...............8............................text.............................. .P`.rdata...7.......8..................@.P@.data...............................@.P..pdata..d.... ......................@.0@.reloc..p....0......................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4158976
                                                                                                                                                                                                                                                          Entropy (8bit):6.719935188075388
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:49152:7g8aO10EL5JZPs5/cBpoBsZOA1IutpAt5nf7P37Es80hqB5:11F7ZRXk5nfp80O
                                                                                                                                                                                                                                                          MD5:81E634EAA8A432AD070E62CD0B94344F
                                                                                                                                                                                                                                                          SHA1:8E5BCFC2724B4B2FF9C736FC155A3FA7AC0F09E7
                                                                                                                                                                                                                                                          SHA-256:B4B28C6D049AD705A498DAF40B245E9B710D0A9EF7CB123EAA0639CBF93DDAA9
                                                                                                                                                                                                                                                          SHA-512:E2A2B024DF0436FAC87DE84112946BD162C4C24ECB2625E2B5A80DF2332468D529B36323016B3380C7ADE22B0BE477BEC86FF428DF0EAEC7D6C9CCC0B256CE2D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."......2..V......$.2......................................0A.......?...`..........................................?;.t...T@;.@............ ?...............A..#...o8......................q8.(....p8.8.............2.X............................text...x.2.......2................. .P`.rdata........2.......2.............@.P@.data.........;......b;.............@.P..pdata..|.... ?......|=.............@.0@.reloc...#....A..$...R?.............@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):279040
                                                                                                                                                                                                                                                          Entropy (8bit):6.2246087773797925
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:HJGFkCjS3571R/F0fPnbp01IbX53ucVTRfTpZx+dZl2U+g3jQwy1eu9t:HJAjS3/R/anH53ucVTNEZUle
                                                                                                                                                                                                                                                          MD5:A860595D34CB47CAA2C5F4066E81F904
                                                                                                                                                                                                                                                          SHA1:9C7A683B11824E02E5C6689BF75A9CA04F935E69
                                                                                                                                                                                                                                                          SHA-256:486397EE32CF811EBDE6684A1C561D5FD3F1DBD4472F55BA7A8B5A2737AEA364
                                                                                                                                                                                                                                                          SHA-512:B5EE5CC7CA7345161448111FAD075BD9646E9F761FC201E7A52C200CCCDA1D5BBEBC865EBB05D5E2B6EB44A56A166226026E1AFFE09A758AB75D73F9E33344DE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".........P...............................................p......4&....`......................................... 1..p....1...............P..X............`......@...............................`...8............................................text...R........................... .P`.rdata...9.......:..................@.P@.data........@.......,..............@.P..pdata..X....P.......0..............@.0@.reloc.......`.......@..............@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):108032
                                                                                                                                                                                                                                                          Entropy (8bit):6.29951625124873
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:eK0mr1gismoFN6BdyaGBRDb95HgZp1DGC6il/9sgNrQsAbLir3B:oAoT6SaOhZgZp4Zm9sgNrQsAbLirR
                                                                                                                                                                                                                                                          MD5:A26B871C3AB58DD1EFE6DAA3F9053171
                                                                                                                                                                                                                                                          SHA1:D52CC71B9B197B5A6E65F719C6E56EB12B000019
                                                                                                                                                                                                                                                          SHA-256:89525CD59FF37723DEB1DB223CE34AD48D2DDCA238D73F52AF19E64E88516BE8
                                                                                                                                                                                                                                                          SHA-512:5C61E7761A6EC8363157CE2DFF633451CE038C415879F22E3429C4B51EA896AC1EA3B47A0D47AD02F74BB84BCB532758210F31F80EEA62441F309F4CA39F9EAA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....R...V......pV..............................................}-....`.............................................l..........................................................................0...8............p..H............................text...8Q.......R.................. .P`.rdata...7...p...8...V..............@.P@.data...............................@.P..pdata..............................@.0@.reloc..............................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):224768
                                                                                                                                                                                                                                                          Entropy (8bit):6.475801951032934
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:r1ij6/oRtQqpj1k1v3GBR49OgG1MBlC56GVI0iGgaCBNGj86ZT85F2aMUcfvsFn7:r1OnEJOgG1MBlCKPc+7yqEjwTrlNB
                                                                                                                                                                                                                                                          MD5:72F4125DFADFFC4855FAD03D8B27C48D
                                                                                                                                                                                                                                                          SHA1:DF453EF2B23BB3FB49CA66BB4C0024E9716AAC5B
                                                                                                                                                                                                                                                          SHA-256:040A1814A6D4198098AC21AFB79335E45FF892BC1BEEE2350CA42A0D74411DD3
                                                                                                                                                                                                                                                          SHA-512:04AFA6977D34E06BB2D6106B7DBF928439D1D59452FCC91AB62D805571FA79C3FCA0A67994B74C7E30B744CB37637A4122C3CF794E8C47282FCF34A44ADE7FC7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."................ ................................................{....`..........................................S.. ....\..x...............P...............P....8...............................8..8............................................text............................... .P`.rdata.............................@.P@.data...8....p.......X..............@.P..pdata..P............Z..............@.0@.reloc..P............l..............@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):168448
                                                                                                                                                                                                                                                          Entropy (8bit):6.155957771727146
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:4tIyGw59yRFJGhQWur/lM14tqWGfOBqxv2rrpTaIjIU:iIxO9yRFwh1ur/lY4YdWrr/jI
                                                                                                                                                                                                                                                          MD5:7EF68699FF1A1C3A41FA3636CC9834EC
                                                                                                                                                                                                                                                          SHA1:2B6BA28FFE8768F0528A1B7CE15CD58D9A0EAF7A
                                                                                                                                                                                                                                                          SHA-256:25A8FF0EDD69B7C0A954EA544EF26523533696EF11E224A52D7FE252BD94071C
                                                                                                                                                                                                                                                          SHA-512:7B01C21EFBA29BF7C40F1B7B3B55356BD8EA1A4F7D1D97A8FA4ADB7EC81A8BFE0DED88A6DC377AD01CA9E923C334F8227CF8316A07D13236803C39D424B3DEBB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."..... ...n.......$....................................................`..........................................q..`...@r..x....................................a.............................. a..8............0...............................text............ .................. .P`.rdata...X...0...Z...$..............@.P@.data................~..............@.P..pdata..............................@.0@.reloc..............................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):747008
                                                                                                                                                                                                                                                          Entropy (8bit):6.3219867193882635
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:r0IdOrZTTz/a00/27B6PgdShxPJAxeajwhfL:NdOV3k2UYdSJqGL
                                                                                                                                                                                                                                                          MD5:62ADC32B9D2AF7EE39D543079DA145BC
                                                                                                                                                                                                                                                          SHA1:DC4C55AFFF97A4418AF819B93523E13456E339C8
                                                                                                                                                                                                                                                          SHA-256:E8C4F744A01A123D96A1ED04729D2A9F0EABE20674322F717984710DAEAD986B
                                                                                                                                                                                                                                                          SHA-512:3D52BAF127FEF38F6057F7AE31CC324EE89F94D0EA91CD12ABB102A79B1D438AD09AEE4378FDB942BDF11F528F7AD30569D954BAC408404E00FF8A4E8B2B7E31
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".................................................................9....`.................................................l...........................................................................8............................................text............................... .P`.rdata...Y.......Z..................@.P@.data....E...@..."..."..............@.P..pdata...............D..............@.0@.reloc...............b..............@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):89088
                                                                                                                                                                                                                                                          Entropy (8bit):6.13191188689023
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:lt8hUt6iTz2gT6JcIjWHWDu7vzzfWHrD6G0md3UrHhyZHce:P8hU6iv2kxI6WqvzLW5UrQZHc
                                                                                                                                                                                                                                                          MD5:C9192CFB49CB990C40D44C22AAB4420A
                                                                                                                                                                                                                                                          SHA1:511A3C1EFCDFD3BF39E388935869D89728AB666A
                                                                                                                                                                                                                                                          SHA-256:17E06A47F64D29171D8BCF706661E2B0798B89C2912A732B4EAF297E4825250C
                                                                                                                                                                                                                                                          SHA-512:21B0BF6A16676F98F4A3CF1E0FAE9E45E6BF9BEA482630D2F52C6D37565A4E04DAAF8BA733EFE981724E244EFBD47DD5DD5F7E2B5A005FAB5E82DF4F1DC984FF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".........z......................................................wJ....`..........................................>..`....>..x...............4....................1...............................1..8...............H............................text...8........................... .P`.rdata..Fb.......d..................@.P@.data...h....`.......F..............@.P..pdata..4............P..............@.0@.reloc...............Z..............@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):95232
                                                                                                                                                                                                                                                          Entropy (8bit):6.0260239366927815
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:W28ZQCqOFfrFjfx6tdWmD1Uf4CVxiGPk5/ybt5:W2pCqs0DPWf4X5/6t5
                                                                                                                                                                                                                                                          MD5:CAC2001230AB7CC350250952D879BC1B
                                                                                                                                                                                                                                                          SHA1:9CA81D51433105D922FC35E2D84E7DCC0D49B3FB
                                                                                                                                                                                                                                                          SHA-256:54800581E9CA1A41407C4AD4EFAC7C0B98CBC08FB6DBA20F09BBF6DE9ACA4B02
                                                                                                                                                                                                                                                          SHA-512:1D40DBE1F2C96A8840CFB4B48B212B1651170875426BEC9EDB45778AF4FC26B22F5CF3C449D5FEC61462B23A29C3728B062D1685812844F7B59964CD5DDAFE83
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."................`....................................................`......................................... W..\...|W..x...............p...............H...PJ..............................pJ..8............... ............................text............................... .P`.rdata..Pj.......l..................@.P@.data...(....p.......Z..............@.P..pdata..p............h..............@.0@.reloc..H............r..............@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):80384
                                                                                                                                                                                                                                                          Entropy (8bit):6.057164779029352
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:FfBLgh7NT/t8JMZHLfsvG0XLXTGKV557bW6sE:FJLgVNTF8J4LwG0XLXpV55fW6sE
                                                                                                                                                                                                                                                          MD5:26F093E79CBD370DFC57ECFC190FE559
                                                                                                                                                                                                                                                          SHA1:DB6CEA068FEAF3774115EE9F00B378E8ADF43129
                                                                                                                                                                                                                                                          SHA-256:9A09F08C9A9B33D6FA077D888733043DF52AD0A880EFDBF1D26768151FE23CD4
                                                                                                                                                                                                                                                          SHA-512:623D6B8659E2B8B3FDD39A90AF28869BC2B706FBEEEE48C968189020939FBC10DF1DD92DDFD6ED21178E6B2CD71D64E51EA407FB59386B77C75BD70D60A9E6D8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".........p............................................................`.........................................P(..`....(..x............`.. ............p..........................................8...............8............................text............................... .P`.rdata...[.......\..................@.P@.data........@.......&..............@.P..pdata.. ....`.......0..............@.0@.reloc.......p.......8..............@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):59904
                                                                                                                                                                                                                                                          Entropy (8bit):5.8550279236850775
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:1nU1NUWenNolDJt76dLND4R3BQceibgbq7:1nUzUWen1dLNa3BQcJgb
                                                                                                                                                                                                                                                          MD5:0B170F079D8C4D85EC00FBC4C92E4697
                                                                                                                                                                                                                                                          SHA1:DAA917E8A8F1F6FE0440C5B759C2B7B66201D750
                                                                                                                                                                                                                                                          SHA-256:AE93A7BA8A458B6CB451C9BBBC2434A38615D636ED673FEE869C1508A6E41425
                                                                                                                                                                                                                                                          SHA-512:C2C795EC0EAEC706132CEA8D1A300B7B7014110B91855EC4D4C45A2586A3947FFB40A379B666C0312C673E5C783BEF22EB2D6A2CCC669794DAF94577B680FC9E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".........Z...............................................0......=.....`......................................... ...\...|...x...............$............ ......................................0...8............................................text...x........................... .P`.rdata..XE.......F..................@.P@.data...............................@.P..pdata..$...........................@.0@.reloc....... ......................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):171008
                                                                                                                                                                                                                                                          Entropy (8bit):6.1865231104677685
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:37h3Q62AWNoReC6EpKwJRYWfZ5WDZOyIX7QlDT5snbe/B/jqSM02+Warahu2+Wag:3t3Q62AWNoRfzpKmBT7Ett1qSM02+WaE
                                                                                                                                                                                                                                                          MD5:030FF813CB8ACCCB4F9B8432D63493DA
                                                                                                                                                                                                                                                          SHA1:71487B144088488DBE889B3F9CD5BABC3279ED32
                                                                                                                                                                                                                                                          SHA-256:AD86FCB92F2373B5BD4CCBE44EDABA24A32BC1126752DFE9EF907A3F365049A9
                                                                                                                                                                                                                                                          SHA-512:FBC4BC328DEC452C7AA036E613F18AD242CCCA60B2BF68F01F325C6827A4D1CF61D54685AEC310E32ACD39E96F48B29FCA7A35FE69FF256BC954CAB7D1F1B715
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."................`...............................................#.....`.........................................0k..l....k..x...............0....................X...............................X..8...............h............................text...(........................... .P`.rdata..............................@.P@.data....$...........v..............@.P..pdata..0...........................@.0@.reloc..............................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):632832
                                                                                                                                                                                                                                                          Entropy (8bit):6.232919360434691
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:q1DBPdRHY+rACcgVQIy/WMsmjSF/bn0gZCo0jwCI7k71A7:qJtdRHY+rACcu4/snFz0gw5I7k7e7
                                                                                                                                                                                                                                                          MD5:22FC6F586D169E0CF2BA3062F25D023F
                                                                                                                                                                                                                                                          SHA1:469BAEFB5008613B489ED5AB08139417060254B7
                                                                                                                                                                                                                                                          SHA-256:513FBEE8E024857CD6E9B21438706F823F4BFC1058684ECA6AA99DB9CC01F36D
                                                                                                                                                                                                                                                          SHA-512:80CC0B853A038EEBF1C7098B0C93689C69E9B00EE8C7B513F744F307C7CD6BE21D80E8C9243457D40BB4DA1CBD889D266EAC86CB77217712AA4533857F315463
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....R...R.......V...............................................\....`..........................................n.......v..................................x....L.............................. L..8............p...............................text....Q.......R.................. .P`.rdata.......p.......V..............@.P@.data...h6...........t..............@.P..pdata..............................@.0@.reloc..x...........................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):67072
                                                                                                                                                                                                                                                          Entropy (8bit):5.909456553599775
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:j3sHmR02IvVxv7WCyKm7c5Th4JBHTOvyyaZE:jnIvryCyKx5Th4J5OvyyO
                                                                                                                                                                                                                                                          MD5:49AC12A1F10AB93FAFAB064FD0523A63
                                                                                                                                                                                                                                                          SHA1:3AD6923AB0FB5D3DD9D22ED077DB15B42C2FBD4F
                                                                                                                                                                                                                                                          SHA-256:BA033B79E858DBFCBA6BF8FB5AFE10DEFD1CB03957DBBC68E8E62E4DE6DF492D
                                                                                                                                                                                                                                                          SHA-512:1BC0F50E0BB0A9D9DDDAD31390E5C73B0D11C2B0A8C5462065D477E93FF21F7EDC7AA2B2B36E478BE0A797A38F43E3FBEB6AAABEF0BADEC1D8D16EB73DF67255
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......nT..*5..*5..*5..#M2. 5..x@..(5..x@..&5..x@.."5..x@...5...k..(5..aM..;5..*5...5...@..:5...@..+5...@^.+5...@..+5..Rich*5..................PE..d...._.g.........." .........h......\........................................@............`.........................................0...`.......@.... .......................0..(.......................................8............................................text...h........................... ..`.rdata..\I.......J..................@..@.data...x...........................@....pdata..............................@..@.rsrc........ ......................@..@.reloc..(....0......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):639488
                                                                                                                                                                                                                                                          Entropy (8bit):6.202264088319606
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:nDZaKxAS8eFNctjdcg7fUoPkmUnXnEaExq09c:8Mctjdcg7fUoPkmUnXnLs
                                                                                                                                                                                                                                                          MD5:EAE765208D19C55B294C63DF9F629777
                                                                                                                                                                                                                                                          SHA1:F7304F8140373EEBD493640AAB8905CD18089FD8
                                                                                                                                                                                                                                                          SHA-256:F235E3AB0157B1D12D765798697B5603A6C8D257D00683F7918738A7EA5E26F6
                                                                                                                                                                                                                                                          SHA-512:56DF3FFFFAA76240742EB657A9CBD686ADD503F57860AC56E45BF81A911F38C0798757E7578A9F3EEA36D044C9CD0A241563DD8979F9FAC9AAC458704450804F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."..... .......h..0..........p.....................................&........ ...................................... ..]....0..x4...........P..$$..........................................`+..(...................p;...............................text...H........ ..................`.P`.data....F...0...H...$..............@.`..rdata..0............l..............@.`@.pdata..$$...P...&...4..............@.0@.xdata...&.......(...Z..............@.0@.bss.....f............................`..edata..].... ......................@.0@.idata..x4...0...6..................@.0..CRT....X....p......................@.@..tls................................@.@..reloc..............................@.0B........................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):201488
                                                                                                                                                                                                                                                          Entropy (8bit):6.375994899027017
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:cAPHiRwroqoLHMpCSNVysh9CV2i6P/1vTg:6wrExSU6PdvTg
                                                                                                                                                                                                                                                          MD5:CF2C3D127F11CB2C026E151956745564
                                                                                                                                                                                                                                                          SHA1:B1C8C432FC737D6F455D8F642A4F79AD95A97BD3
                                                                                                                                                                                                                                                          SHA-256:D3E81017B4A82AE1B85E8CD6B9B7EB04D8817E29E5BC9ECE549AC24C8BB2FF23
                                                                                                                                                                                                                                                          SHA-512:FE3A9C8122FFFF4AF7A51DF39D40DF18E9DB3BC4AED6B161A4BE40A586AC93C1901ACDF64CC5BFFF6975D22073558FC7A37399D016296432057B8150848F636E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1..P.P.P.(t..P...P...P...P...P....P..(.P.P..P....P....P......P....P.Rich.P.........................PE..d.....g.........." ...)..................................................... ............`............................................P... ............................/..........`4..T........................... 3..@............ ...............................text............................... ..`.rdata....... ......................@..@.data.... ..........................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):70416
                                                                                                                                                                                                                                                          Entropy (8bit):6.1258200129869405
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:pQEotsskOv6pWVCB4p/uKlZPRQcFIc9qunV0Jku/YFI1Hu1wEBbCpVNyD6VdPxiD:/otssyKcunV8PjZIJy0i7SyWH1
                                                                                                                                                                                                                                                          MD5:16855EBEF31C5B1EBE767F1C617645B3
                                                                                                                                                                                                                                                          SHA1:315521F3A748ABFA35CD4D48E8DD09D0556D989B
                                                                                                                                                                                                                                                          SHA-256:A5C6A329698490A035133433928D04368CE6285BB91A9D074FC285DE4C9A32A4
                                                                                                                                                                                                                                                          SHA-512:C3957B3BD36B10C7AD6EA1FF3BC7BD65CDCEB3E6B4195A25D0649AA0DA179276CE170DA903D77B50A38FC3D5147A45BE32DBCFDBFBF76CC46301199C529ADEA4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%?..a^e.a^e.a^e.).m.`^e.).e.`^e.)..`^e.).g.`^e.Richa^e.........PE..d......g.........." ...)............................................................z.....`.........................................`..................................../..............T............................................................................rdata..............................@..@.rsrc...............................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6083856
                                                                                                                                                                                                                                                          Entropy (8bit):6.126922729922386
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:49152:fXGc3O7T4DKX+vLFMmKYxiAYNBD987KdJlI9HbeX2jrgQcw6Zc4h67mM+XDQ3bLi:Of42zJiwJl/YF7v3vaHDMiEN3Kr
                                                                                                                                                                                                                                                          MD5:B9DE917B925DD246B709BB4233777EFD
                                                                                                                                                                                                                                                          SHA1:775F258D8B530C6EA9F0DD3D1D0B61C1948C25D2
                                                                                                                                                                                                                                                          SHA-256:0C0A66505093B6A4BB3475F716BD3D9552095776F6A124709C13B3F9552C7D99
                                                                                                                                                                                                                                                          SHA-512:F4BF3398F50FDD3AB7E3F02C1F940B4C8B5650ED7AF16C626CCD1B934053BA73A35F96DA03B349C1EB614BB23E0BC6B5CC58B07B7553A5C93C6D23124F324A33
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........s]{v ]{v ]{v M.w!_{v M.. S{v M.u!Y{v M.r!U{v M.s!P{v T.. G{v ..w!V{v ]{w .zv ..{!.{v ..v!\{v ... \{v ..t!\{v Rich]{v ........................PE..d......g.........." ...).:+..T9......J........................................d.....uF]...`...........................................O.....h.P.......d......0].......\../....d..... A3.T.....................I.(....?3.@............P+..............................text....8+......:+................. ..`.rdata....%..P+...%..>+.............@..@.data...$9....P..N....P.............@....pdata.......0]...... U.............@..@PyRuntim.N...._..P....W.............@....rsrc.........d.......[.............@..@.reloc........d.......[.............@..B........................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):135680
                                                                                                                                                                                                                                                          Entropy (8bit):6.0205382324631955
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:q9GPDeI1KuOQEbULZYY/r06YrqHXmZEdb/XAnLT:GgDJ1vOlbfY/rke3mZE9/XA
                                                                                                                                                                                                                                                          MD5:2A87D04E9E7CBFF67E8EA4F6315C0EBB
                                                                                                                                                                                                                                                          SHA1:CF5B2BB53B37087ECA18E509B8551ED5CB7575D9
                                                                                                                                                                                                                                                          SHA-256:D011068781CFBA0955258505DBE7E5C7D3D0B955E7F7640D2F1019D425278087
                                                                                                                                                                                                                                                          SHA-512:2138E051AC116D3ABE11101C75F8BD8388D7FBA89B15E6F82DC35FD78BDD913ED8BA468769F68440CE7834825806281AA15F0023855E3B8248266414D60A4A44
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A.J+.z$x.z$x.z$x...x.z$xW.%y.z$xc..x.z$xW.!y.z$xW. y.z$xW.'y.z$xN. y.z$xM.%y.z$xN.%y.z$x.z%x.z$x..-y.z$x..$y.z$x..&y.z$xRich.z$x................PE..d...X..g.........." .........................................................`............`.........................................0...lB......,....@..l.... ...............P..0....a..T............................b..8...............p............................text...9........................... ..`.rdata..............................@..@.data....-.......(..................@....pdata....... ......................@..@.rsrc...l....@......................@..@.reloc..0....P......................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:HTML document, ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9895
                                                                                                                                                                                                                                                          Entropy (8bit):4.8632942288856
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:r4jNP4Fg0+CTIC9kaceZZCyOn6XXZvb/HJiUkk7:rS8ICy5e2n6nZ7piUkG
                                                                                                                                                                                                                                                          MD5:E11EB8AC73160616E46C7D96099722EA
                                                                                                                                                                                                                                                          SHA1:102DAA40236B2A87399CA81760B4995721DF744A
                                                                                                                                                                                                                                                          SHA-256:178D38BC733EB361AFE2FFE1100BDB2B251EE9527620C0475CAA1A08162B00FE
                                                                                                                                                                                                                                                          SHA-512:088446E93B517C4FABBA44DFB396473A89656B479AD101AA838E35A8D12761930F323DE33638FC6A7716326C66F91CA3000635C4A34BEB9179E5814DB1F8CA52
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <title>illusion</title>. <style type="text/css">. body, html {. margin: 0;. padding: 0;. background-color: #16121a;. overflow-x: hidden;. }.. .content {. width: 100vw;. font-family: 'Times New Roman', serif;. }.. .section {. width: 100%;. height: 100vh;. display: flex;. justify-content: center;. align-items: center;. color: #D8B4FE; . text-align: center;. }.. .section div {. width: 90%;. }.. .section:nth-child(1) {. font-size: 20vh;. }.. @media (max-width: 600px) {. .section:nth-child(1) {. font-size: 25vw;. }. }.. @media (max-width: 350px) {. .section:nth-child(1) {. font-size: 30px;. }. }.. canvas#neuro {. position: fixed;. top: 0;. left: 0;. width: 100%;. pointer-events: none;. opacity: .95;. }.. a {. display: inline-block
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):30992
                                                                                                                                                                                                                                                          Entropy (8bit):6.554484610649281
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:7hhxm9tKLhuoNHfzzlvFy0ZZIJ9GckHQIYiSy1pCQ4HWSJIVE8E9VF0Ny6sC:tCytHf98uZIJ9Gx5YiSyvy2ES
                                                                                                                                                                                                                                                          MD5:20831703486869B470006941B4D996F2
                                                                                                                                                                                                                                                          SHA1:28851DFD43706542CD3EF1B88B5E2749562DFEE0
                                                                                                                                                                                                                                                          SHA-256:78E5994C29D8851F28B5B12D59D742D876683AEA58ECEEA1FB895B2036CDCDEB
                                                                                                                                                                                                                                                          SHA-512:4AAF5D66D2B73F939B9A91E7EDDFEB2CE2476C625586EF227B312230414C064AA850B02A4028363AA4664408C9510594754530A6D026A0A84BE0168D677C1BC4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........tV..'V..'V..'_.j'T..'F:.&T..'F:.&R..'F:.&^..'F:.&Z..'.;.&T..'V..'...'...&S..'.;.&W..'.;.&W..'.;.'W..'.;.&W..'RichV..'................PE..d.....g.........." ...).....2............................................................`..........................................@..L...<A..x....p.......`.......J.../......L....3..T............................2..@............0...............................text............................... ..`.rdata.......0......................@..@.data...p....P.......8..............@....pdata.......`.......:..............@..@.rsrc........p.......>..............@..@.reloc..L............H..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1822480
                                                                                                                                                                                                                                                          Entropy (8bit):6.496835067638848
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:49152:ehk299wKFi8C2Qt6IHCmGViSIV8JryqL3eD0:qN9wdeIAvt
                                                                                                                                                                                                                                                          MD5:8587238932B4F7F394CE587AD169846B
                                                                                                                                                                                                                                                          SHA1:6CDC9C1751E812BE3A11BB411A145E7AB6885DEF
                                                                                                                                                                                                                                                          SHA-256:C861F39AD0F4FC7F3875850925F61442BFF2BC1839BBBB3584A63BC4D6E5CEA6
                                                                                                                                                                                                                                                          SHA-512:C88506E5B78AB1459C25DE4C7EF65B3C9E24E0F79AB2132E8FDC7A02195AF2E137874512A0F423C80D558969E42E2A4BC7D2CDDEE696624DBD230B32C44F88F2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........'...Ft..Ft..Ft...u..Ft.....Ft...q..Ft...p..Ft...w..Ft.^/u..Ft..>..Ft..>p..Ft..>u..Ft..Fu..Gt...|.^Ft...t..Ft.....Ft...v..Ft.Rich.Ft.........................PE..d......e.........." ...&.&..........x'..............................................P.....`.........................................`....`..Xt..h....... .......(......../..........................................p...@............@..h............................text....%.......&.................. ..`.rdata..(Q...@...R...*..............@..@.data...0#...........|..............@....pdata..(...........................@..@.rsrc... ............~..............@..@.reloc..............................@..B................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11708
                                                                                                                                                                                                                                                          Entropy (8bit):5.033309358188091
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:rXlm2LnoZ7k2mOEhYoKVtWD2xLsdF+MNlPQ4lJ+B0O0DgryYY/+zy7go:rXlm2Lng7kvF2VtWD2xL/MNT+B0O0Urk
                                                                                                                                                                                                                                                          MD5:09136E22071F0B5AC55481E1AC5CB418
                                                                                                                                                                                                                                                          SHA1:B45E10211323E92D9A985C82C5CF0A8C3DC1E51D
                                                                                                                                                                                                                                                          SHA-256:FE9087E2779FF30D229356E87920F3ADD9E362A70FCCB832AE23086118BFC0DA
                                                                                                                                                                                                                                                          SHA-512:565B418C129C619BB92862B7AF52F75BDF3E0603AA365C8D6BDE0C60DAFC1C4C6C553216D484A35C2039C8640BD4871036BD644458F7282DC95454F11D5BAE1A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# -*- tcl -*-..# ### ### ### ######### ######### #########..## Overview....# Heuristics to assemble a platform identifier from publicly available..# information. The identifier describes the platform of the currently..# running tcl shell. This is a mixture of the runtime environment and..# of build-time properties of the executable itself...#..# Examples:..# <1> A tcl shell executing on a x86_64 processor, but having a..# wordsize of 4 was compiled for the x86 environment, i.e. 32..# bit, and loaded packages have to match that, and not the..# actual cpu...#..# <2> The hp/solaris 32/64 bit builds of the core cannot be..# distinguished by looking at tcl_platform. As packages have to..# match the 32/64 information we have to look in more places. In..# this case we inspect the executable itself (magic numbers,..# i.e. fileutil::magic::filetype)...#..# The basic information used comes out of the 'os' and 'machine'..# entries of the 'tcl_platform' array. A number of general and
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6217
                                                                                                                                                                                                                                                          Entropy (8bit):4.843096643524417
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:PV5U+VLnNUGVvH+knNUGVUHD5ngWftN+Ig1EfIdqi+g0SYiCXVDjqL:Nm6boXNuEwq51iCFD2
                                                                                                                                                                                                                                                          MD5:0C30529D7AD5DE360061E4365D0737F4
                                                                                                                                                                                                                                                          SHA1:33CF0EAE4D0D742C18145D3B987EEAD8B2220F79
                                                                                                                                                                                                                                                          SHA-256:F587F5F375CF6EA3410F7421FF51DB004E7231E952EED2F74100AE8D3E9BB91E
                                                                                                                                                                                                                                                          SHA-512:EB33545663B7E344EE09487C75B4CE052C202D81BAB5915171475E40AA2B1F0B8B1C3366F84CFF61D946012622A984BD2E19DB1FB71C91B911EBDCC9633658B9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:..# -*- tcl -*-..# ### ### ### ######### ######### #########..## Overview....# Higher-level commands which invoke the functionality of this package..# for an arbitrary tcl shell (tclsh, wish, ...). This is required by a..# repository as while the tcl shell executing packages uses the same..# platform in general as a repository application there can be..# differences in detail (i.e. 32/64 bit builds).....# ### ### ### ######### ######### #########..## Requirements....package require platform..namespace eval ::platform::shell {}....# ### ### ### ######### ######### #########..## Implementation....# -- platform::shell::generic....proc ::platform::shell::generic {shell} {.. # Argument is the path to a tcl shell..... CHECK $shell.. LOCATE base out.... set code {}.. # Forget any preexisting platform package, it might be in.. # conflict with this one... lappend code {package forget platform}.. # Inject our platform package.. lappend code [list source $base]..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):35141
                                                                                                                                                                                                                                                          Entropy (8bit):4.945541385716526
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:m3xQ0CzasW/rHPG2yfkZ0Kbh91iQ34nq5MIVYB8mbgijsPIAtw4qvUm:4xQ0CzasWDHPG2yW0kJ3dimXmUij6njG
                                                                                                                                                                                                                                                          MD5:62FDB2C6EC12160D3636F8D19485990B
                                                                                                                                                                                                                                                          SHA1:BAD3547AFD2D9E58BAA6841EC6CBA55F47B75F04
                                                                                                                                                                                                                                                          SHA-256:6CC549A37C051D0C70A935B26C2098D1CA4A10B1A60BCE03068BE268B5E81CA1
                                                                                                                                                                                                                                                          SHA-512:1867C11BD337B325BCEE00048720FC48CDB71E7C78F1B18F0880E036F22CDE89C25FBE15270BF7738D2FC8F376CE0608D78D9230295687D5DBD6F95F6C4D0920
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# msgcat.tcl --..#..#.This file defines various procedures which implement a..#.message catalog facility for Tcl programs. It should be..#.loaded with the command "package require msgcat"...#..# Copyright (c) 2010-2015 Harald Oehlmann...# Copyright (c) 1998-2000 Ajuba Solutions...# Copyright (c) 1998 Mark Harrison...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....package require Tcl 8.5-..# When the version number changes, be sure to update the pkgIndex.tcl file,..# and the installation directory in the Makefiles...package provide msgcat 1.6.1....namespace eval msgcat {.. namespace export mc mcexists mcload mclocale mcmax mcmset mcpreferences mcset\.. mcunknown mcflset mcflmset mcloadedlocales mcforgetpackage\... mcpackageconfig mcpackagelocale.... # Records the list of locales to search.. variable Loclist {}.... # List of currently loaded locales.. variable LoadedLoc
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):105075
                                                                                                                                                                                                                                                          Entropy (8bit):4.7881869186256925
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:rKURHPk3tqN0E7NkhtMcrQ3qoyXutpr/lTM5t2g/CrQiXcuIHS8DuHm7zvL2YlQt:rKUTzUcwiBIHS8Dim7DL2Y0K/Ha0rBC
                                                                                                                                                                                                                                                          MD5:B15354C98D6A676152A2C81E8EB5ECF7
                                                                                                                                                                                                                                                          SHA1:B027020D5AB2921E21C79E10C3EEB03BB47550FF
                                                                                                                                                                                                                                                          SHA-256:DF623D89CEF0FA5D2C53CB9ACE1EE8FF4AFD5A735AB6D86E68757DA89122F26B
                                                                                                                                                                                                                                                          SHA-512:5B5D2B19EF1F64EA6D4911B6568C0194E2E86C45514A5C778BCABE642E9A919FFB48107EA0E280E425BE1711B277D15303009D951BBAC110DAF860F60BBD05E3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# tcltest.tcl --.#.#.This file contains support code for the Tcl test suite. It.# defines the tcltest namespace and finds and defines the output.# directory, constraints available, output and error channels,.#.etc. used by Tcl tests. See the tcltest man page for more.#.details..#.# This design was based on the Tcl testing approach designed and.# initially implemented by Mary Ann May-Pumphrey of Sun.#.Microsystems..#.# Copyright . 1994-1997 Sun Microsystems, Inc..# Copyright . 1998-1999 Scriptics Corporation..# Copyright . 2000 Ajuba Solutions.# Contributions from Don Porter, NIST, 2002. (not subject to US copyright).# All rights reserved...namespace eval tcltest {.. # When the version number changes, be sure to update the pkgIndex.tcl file,. # and the install directory in the Makefiles. When the minor version. # changes (new feature) be sure to update the man page as well.. variable Version 2.5.7.. # Compatibility support for dumb variables
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):118422
                                                                                                                                                                                                                                                          Entropy (8bit):4.888857036034696
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:RYY1IO/KuUhIW17zr1DLJuuBuFsj6aIeGc3e6xGxjndp72y4eFBxIQ30Ik:RbyOCuUv9r5LJmsjjxTxGxjndpCBemQ0
                                                                                                                                                                                                                                                          MD5:CF01A75B7F92042E50002DAEC4B6AE63
                                                                                                                                                                                                                                                          SHA1:279C011127396DC8A23F73470761646EF38C1102
                                                                                                                                                                                                                                                          SHA-256:CEEEF25A5919509BF5889BBF5E70734F117F0876AE35C80F01977510A2A9D762
                                                                                                                                                                                                                                                          SHA-512:D01620365BD4847CC0B8A170C3A45C9BE515C59AF002AB5454CB2D72A800C4479BC0131E4BADAF22A6E661B822263D76F27D52BDE449CF2754B1F13EEB5B92C6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:# http.tcl --..#..#.Client-side HTTP for GET, POST, and HEAD commands. These routines can..#.be used in untrusted code that uses the Safesock security policy...#.These procedures use a callback interface to avoid using vwait, which..#.is not defined in the safe base...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES.....package require Tcl 8.6-..# Keep this in sync with pkgIndex.tcl and with the install directories in..# Makefiles..package provide http 2.9.8....namespace eval http {.. # Allow resourcing to not clobber existing data.... variable http.. if {![info exists http]} {...array set http {... -accept */*... -pipeline 1... -postfresh 0... -proxyhost {}... -proxyport {}... -proxyfilter http::ProxyRequired... -repost 0... -urlencoding utf-8... -zip 1...}...# We need a useragent string of this style or various servers will...# refuse to send us compressed content
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1569040
                                                                                                                                                                                                                                                          Entropy (8bit):6.183941021450726
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24576:tvVYTm+MKYeCmXNrhMMjMt41GZsbTYsgG04ChR3mxOl8v07B62sUCcmxNFClwdbR:tNY7YReNrhMMi41GZsbTYsgG04ChR3mB
                                                                                                                                                                                                                                                          MD5:6F06390D3AC095827DF2F1A8ED5DAE0C
                                                                                                                                                                                                                                                          SHA1:879F24522821F597C0341CA091E474163764B343
                                                                                                                                                                                                                                                          SHA-256:6425BF57ABCC1DFBBE8662B1956883AE0C5AB8C2D9314E19692B3D86BABC242C
                                                                                                                                                                                                                                                          SHA-512:27B975E15F6E1B9BC8E3E41152BAEE25F4B400DE3AA6E334C61B2165FECD27560FA5C4296A9B3FF0EB1103173CFB61C348BA11E01A44CBADBECF308B5D7C5095
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......K.`@............................................D.......`..............D...........F...`.......`.......`.......`.......Rich............................PE..d...3..e.........." ...&............H...............................................Gj....`..........................................h..h@......h....0...{...p.........../.......F..px..............................0w..@...............0............................text............................... ..`.rdata..............................@..@.data..............................@....pdata.......p.......H..............@..@.rsrc....{...0...|..................@..@.reloc...F.......H...z..............@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):709904
                                                                                                                                                                                                                                                          Entropy (8bit):5.861739047785334
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:FYGdLI/X77mvfldCKGihH32W3cnPSqrUgLIe:FYGW7qNxr3cnPXLIe
                                                                                                                                                                                                                                                          MD5:0902D299A2A487A7B0C2D75862B13640
                                                                                                                                                                                                                                                          SHA1:04BCBD5A11861A03A0D323A8050A677C3A88BE13
                                                                                                                                                                                                                                                          SHA-256:2693C7EE4FBA55DC548F641C0CB94485D0E18596FFEF16541BD43A5104C28B20
                                                                                                                                                                                                                                                          SHA-512:8CBEF5A9F2D24DA1014F8F1CCBDDD997A084A0B04DD56BCB6AC38DDB636D05EF7E4EA7F67A085363AAD3F43D45413914E55BDEF14A662E80BE955E6DFC2FECA3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Q.............(.....(.....(.....(.....)................).....).....)x....)....Rich..................PE..d.....g.........." ...).B...f......P,..............................................<.....`.........................................P...X................................/..........p...T...........................0...@............`..h............................text....@.......B.................. ..`.rdata...?...`...@...F..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):35328
                                                                                                                                                                                                                                                          Entropy (8bit):5.568442154849667
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2x6ZP0arBx++JtHZ+PIuZGigWW0PhmzZ+a:2oearBxZ3HZ+wuZfPh0Z+a
                                                                                                                                                                                                                                                          MD5:15F5101A5AC8C634A00AFB46EC4DAE77
                                                                                                                                                                                                                                                          SHA1:57CD309E0A85190BC1FED9DE758B8BE26B22917D
                                                                                                                                                                                                                                                          SHA-256:E68A56B68BE5945E3A72486C61A2B07515A254C5B57412634BD462B910FB483D
                                                                                                                                                                                                                                                          SHA-512:51ED5C978C08A53D6D579F64708BEBD20953A6996D25904BE33FE03612C44DB8430CF4ECE04350D271D06226D4EB73B6AE50FF3D8EDEFFC392DEF5072AC1C08E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......6/5drN[7rN[7rN[7{6.7tN[7 ;Z6vN[796Z6pN[7 ;^6~N[7 ;_6zN[7 ;X6qN[7.;Z6pN[7:.Z6qN[7rNZ7*N[7.;R6sN[7.;[6sN[7.;Y6sN[7RichrN[7................PE..d...o..g.........." .....F...@......$A....................................................`.........................................@...P...............\............................p..T............................q..8............`...............................text...>D.......F.................. ..`.rdata..N,...`.......J..............@..@.data...x............x..............@....pdata...............|..............@..@.rsrc...\...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):146192
                                                                                                                                                                                                                                                          Entropy (8bit):6.607123332668088
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:dvEO6FnGGVV1m4dkRR5Th2UgvGxbOUJCf/:dsVD+RrFgvi7Ju
                                                                                                                                                                                                                                                          MD5:3A46A119C9860C477F13FE98C878452C
                                                                                                                                                                                                                                                          SHA1:E0BCBE5B30EF2A2F58E1206C650672EE3F85ABC9
                                                                                                                                                                                                                                                          SHA-256:8C2ED3E1A90C9B0E3EF844BE20E1AF791AE8A1B665D4731162404F0EEE1697DC
                                                                                                                                                                                                                                                          SHA-512:0D3D4E8A2C8886FD6E480AECC5051644F39C1E06B1113DEF7273369F771C4429C757AED13BD8082F4768F617CA3499CD81B79A0893B5A2955FB4B68C8B571C71
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....d.e..........."...'............P..........A..........................................`... ......................................0.......@..8....p.................../......................................(....................A..p............................text...............................`..`.data...............................@....rdata...W.......X..................@..@.pdata..............................@..@.xdata..............................@..@.bss......... ...........................edata.......0......................@..@.idata..8....@......................@....CRT....X....P......................@....tls.........`......................@....rsrc........p......................@....reloc..............................@..B................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):650752
                                                                                                                                                                                                                                                          Entropy (8bit):6.407907101203656
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:Oz5QLUL4lK9bQkMZ/jZMaBHX7vu3XSAU128zkpWCucchvkf8HpbUPAKjgCX3oRx:Ozb4lK9ckWBHXKSA584ENcyv6sUPAKg
                                                                                                                                                                                                                                                          MD5:0C4037C8EE7D926265B6AC499C323599
                                                                                                                                                                                                                                                          SHA1:B2F5B324449814C25E7262E2B7598B2596AD34B8
                                                                                                                                                                                                                                                          SHA-256:5134A34833CDCDC64546BEB50AABFC09496F457FFB76F6ECDE01E8D9D30BC177
                                                                                                                                                                                                                                                          SHA-512:99C5CBA330D1266D46F51348CD1D08920385E42A41ED9BA53AACB5E39C9297B7153BB0F66EAC157D1869877D718BF24486E78033A2F2218E7891E415FE9EC2FD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......F...........1....r....I......r.....r.....r.....u......J..u.....u.....u]....u....Rich..........PE..d....'.f.........." ...(.....\......P........................................0............`.........................................0...\........................3........... .......d..............................Pc..@...............@............................text...x........................... ..`.rdata..b...........................@..@.data...............................@....pdata...3.......4..................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):520192
                                                                                                                                                                                                                                                          Entropy (8bit):6.408267868238645
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:AL1TGmvt0Vwyow0k1rErgw25rDjEA0Z7k45sWOC:A5lvt0Vw9fk1rErV25rE57k
                                                                                                                                                                                                                                                          MD5:23266E25821CE9E162F050DB8B81C6F9
                                                                                                                                                                                                                                                          SHA1:FD1049338E304D7688562991091D59C310999B23
                                                                                                                                                                                                                                                          SHA-256:0B494D168A67F2EB2D75593714A4DB65FE0F000B66388AB3C721A67515A2FEFC
                                                                                                                                                                                                                                                          SHA-512:E118531A6BF5354BF082D4CEAAF5247FEA3305A9ADD399ECBBE08AB083D39AB760F3CA28A0DD2B4D5D8400F3E88EC3DECD696E3987FB9F2264A5B8B16F66A61B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................k...........k.....k.....k.....l......T..l.....l.....ln....l....Rich..................PE..d....'.f.........." ...(............ ........................................0............`......................................... ...d........................)........... ..d...0\...............................Z..@...............(............................text...H........................... ..`.rdata.............................@..@.data....-.......(..................@....pdata...).......*..................@..@.rsrc...............................@..@.reloc..d.... ......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):83
                                                                                                                                                                                                                                                          Entropy (8bit):4.696756527931392
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Sy8ZBFReNmI4RMBAuF5QEyn:Sy8NMmI4X3
                                                                                                                                                                                                                                                          MD5:2EFB9B8FB86C8145002DA39BA89A72E2
                                                                                                                                                                                                                                                          SHA1:D5EC30E37ADAB1C70255C8E3559BE4B88050F643
                                                                                                                                                                                                                                                          SHA-256:4ED5989ED10A970D70438EC842D02FE06BEAB35DED5128E31B51B94C68E212D9
                                                                                                                                                                                                                                                          SHA-512:4113769E88DC18A1F41C01E74EF8881EF766EA9E05F50ADD79E57550D50F9166ECD66E21AAE92D723C76053D4AFC5C04980DAAD7C79C4D182A098C089811979F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Preview:[PYI-6436:ERROR] Failed to execute script '_external' due to unhandled exception!..
                                                                                                                                                                                                                                                          File type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Entropy (8bit):7.997054756730647
                                                                                                                                                                                                                                                          TrID:
                                                                                                                                                                                                                                                          • Win64 Executable Console (202006/5) 92.65%
                                                                                                                                                                                                                                                          • Win64 Executable (generic) (12005/4) 5.51%
                                                                                                                                                                                                                                                          • Generic Win/DOS Executable (2004/3) 0.92%
                                                                                                                                                                                                                                                          • DOS Executable Generic (2002/1) 0.92%
                                                                                                                                                                                                                                                          • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                                                                                                                                                                                                          File name:ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          File size:63'538'768 bytes
                                                                                                                                                                                                                                                          MD5:37c4774a4906c4344c5f55d019033718
                                                                                                                                                                                                                                                          SHA1:7a8603814259adfd4934ffdfde0a7fd78e1ac42c
                                                                                                                                                                                                                                                          SHA256:7b54b8972d8f870cb5cf66a4f9a92c78b56395ac802fb3d4bf05b18bbab9d5a4
                                                                                                                                                                                                                                                          SHA512:32cf54c3c28bb0d309ee4fdf558b5084d7e7a5e73e6f768c9839bc15484323d8e7abe943ef2548693cb2cb64d33d109fce8a08d07ecb5e8ef94087c778652840
                                                                                                                                                                                                                                                          SSDEEP:1572864:y9xTBEXGMK4XR3bLSCU/+6yPl314W63hrscr3yxp/R+yA/jo:wagYRPSC++6y92NrLr3QtO
                                                                                                                                                                                                                                                          TLSH:F3D73355F3E008CBE8A82A76E1D9974BC949F4E947A0C69352F409D740EB5C0CF67BA3
                                                                                                                                                                                                                                                          File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......xh.B<...<...<...wq..;...wq......wq..6...,.W.>...,...5...,...-...,.......wq..;...<.......w...%...w...=...Rich<...........PE..d..
                                                                                                                                                                                                                                                          Icon Hash:b69399a991adabf2
                                                                                                                                                                                                                                                          Entrypoint:0x14000c380
                                                                                                                                                                                                                                                          Entrypoint Section:.text
                                                                                                                                                                                                                                                          Digitally signed:false
                                                                                                                                                                                                                                                          Imagebase:0x140000000
                                                                                                                                                                                                                                                          Subsystem:windows cui
                                                                                                                                                                                                                                                          Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                                                                                                                                                                                                                          DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
                                                                                                                                                                                                                                                          Time Stamp:0x67508787 [Wed Dec 4 16:47:03 2024 UTC]
                                                                                                                                                                                                                                                          TLS Callbacks:
                                                                                                                                                                                                                                                          CLR (.Net) Version:
                                                                                                                                                                                                                                                          OS Version Major:6
                                                                                                                                                                                                                                                          OS Version Minor:0
                                                                                                                                                                                                                                                          File Version Major:6
                                                                                                                                                                                                                                                          File Version Minor:0
                                                                                                                                                                                                                                                          Subsystem Version Major:6
                                                                                                                                                                                                                                                          Subsystem Version Minor:0
                                                                                                                                                                                                                                                          Import Hash:a06f302f71edd380da3d5bf4a6d94ebd
                                                                                                                                                                                                                                                          Instruction
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          sub esp, 28h
                                                                                                                                                                                                                                                          call 00007F5654DEB44Ch
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          add esp, 28h
                                                                                                                                                                                                                                                          jmp 00007F5654DEB05Fh
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          sub esp, 28h
                                                                                                                                                                                                                                                          call 00007F5654DEB7D8h
                                                                                                                                                                                                                                                          test eax, eax
                                                                                                                                                                                                                                                          je 00007F5654DEB213h
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          mov eax, dword ptr [00000030h]
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          mov ecx, dword ptr [eax+08h]
                                                                                                                                                                                                                                                          jmp 00007F5654DEB1F7h
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          cmp ecx, eax
                                                                                                                                                                                                                                                          je 00007F5654DEB206h
                                                                                                                                                                                                                                                          xor eax, eax
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          cmpxchg dword ptr [000381ACh], ecx
                                                                                                                                                                                                                                                          jne 00007F5654DEB1E0h
                                                                                                                                                                                                                                                          xor al, al
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          add esp, 28h
                                                                                                                                                                                                                                                          ret
                                                                                                                                                                                                                                                          mov al, 01h
                                                                                                                                                                                                                                                          jmp 00007F5654DEB1E9h
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          sub esp, 28h
                                                                                                                                                                                                                                                          test ecx, ecx
                                                                                                                                                                                                                                                          jne 00007F5654DEB1F9h
                                                                                                                                                                                                                                                          mov byte ptr [00038195h], 00000001h
                                                                                                                                                                                                                                                          call 00007F5654DEA935h
                                                                                                                                                                                                                                                          call 00007F5654DEBBF0h
                                                                                                                                                                                                                                                          test al, al
                                                                                                                                                                                                                                                          jne 00007F5654DEB1F6h
                                                                                                                                                                                                                                                          xor al, al
                                                                                                                                                                                                                                                          jmp 00007F5654DEB206h
                                                                                                                                                                                                                                                          call 00007F5654DFA0FFh
                                                                                                                                                                                                                                                          test al, al
                                                                                                                                                                                                                                                          jne 00007F5654DEB1FBh
                                                                                                                                                                                                                                                          xor ecx, ecx
                                                                                                                                                                                                                                                          call 00007F5654DEBC00h
                                                                                                                                                                                                                                                          jmp 00007F5654DEB1DCh
                                                                                                                                                                                                                                                          mov al, 01h
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          add esp, 28h
                                                                                                                                                                                                                                                          ret
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          int3
                                                                                                                                                                                                                                                          inc eax
                                                                                                                                                                                                                                                          push ebx
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          sub esp, 20h
                                                                                                                                                                                                                                                          cmp byte ptr [0003815Ch], 00000000h
                                                                                                                                                                                                                                                          mov ebx, ecx
                                                                                                                                                                                                                                                          jne 00007F5654DEB259h
                                                                                                                                                                                                                                                          cmp ecx, 01h
                                                                                                                                                                                                                                                          jnbe 00007F5654DEB25Ch
                                                                                                                                                                                                                                                          call 00007F5654DEB74Eh
                                                                                                                                                                                                                                                          test eax, eax
                                                                                                                                                                                                                                                          je 00007F5654DEB21Ah
                                                                                                                                                                                                                                                          test ebx, ebx
                                                                                                                                                                                                                                                          jne 00007F5654DEB216h
                                                                                                                                                                                                                                                          dec eax
                                                                                                                                                                                                                                                          lea ecx, dword ptr [00038146h]
                                                                                                                                                                                                                                                          call 00007F5654DF9EF2h
                                                                                                                                                                                                                                                          NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_IMPORT0x3e9ec0x50.rdata
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_RESOURCE0x490000x17ac.rsrc
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x460000x22bc.pdata
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_BASERELOC0x4b0000x768.reloc
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_DEBUG0x3bfb00x1c.rdata
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x3be700x140.rdata
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_IAT0x2d0000x400.rdata
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                                                                                                                          NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                                                                                                          .text0x10000x2b1700x2b200420661550c659f884db561712e500aaeFalse0.5455615942028985data6.498595774489571IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                          .rdata0x2d0000x128020x12a00c82520b0ceb20b5b71b38d6dbbf70905False0.5229524958053692data5.7684175629756655IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                          .data0x400000x54080xe00aff56347f897785154c53727472c548dFalse0.13504464285714285data1.8315705466577277IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                          .pdata0x460000x22bc0x24002411a276649fc67a0a93227155911735False0.4740668402777778data5.334571311334213IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                          .rsrc0x490000x17ac0x18000efdd11b33410f19e8318079a0238d84False0.85791015625data7.601500797656929IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                          .reloc0x4b0000x7680x80042d6242177dbae8e11ed5d64b87d0d48False0.5576171875data5.268722219019965IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                          NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                                                                                                                                          RT_ICON0x491480x348PNG image data, 16 x 16, 8-bit/color RGB, non-interlaced1.013095238095238
                                                                                                                                                                                                                                                          RT_ICON0x494900x666PNG image data, 24 x 24, 8-bit/color RGB, non-interlaced1.0067155067155067
                                                                                                                                                                                                                                                          RT_ICON0x49af80x774PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced1.0057651991614256
                                                                                                                                                                                                                                                          RT_GROUP_ICON0x4a26c0x30data0.8958333333333334
                                                                                                                                                                                                                                                          RT_MANIFEST0x4a29c0x50dXML 1.0 document, ASCII text0.4694508894044857
                                                                                                                                                                                                                                                          DLLImport
                                                                                                                                                                                                                                                          USER32.dllTranslateMessage, ShutdownBlockReasonCreate, GetWindowThreadProcessId, SetWindowLongPtrW, GetWindowLongPtrW, MsgWaitForMultipleObjects, ShowWindow, DestroyWindow, CreateWindowExW, RegisterClassW, DefWindowProcW, PeekMessageW, DispatchMessageW, GetMessageW
                                                                                                                                                                                                                                                          KERNEL32.dllGetTimeZoneInformation, GetProcessHeap, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCPInfo, GetOEMCP, GetACP, IsValidCodePage, GetStringTypeW, FormatMessageW, GetLastError, GetModuleFileNameW, LoadLibraryExW, SetDllDirectoryW, CreateSymbolicLinkW, GetProcAddress, CreateDirectoryW, GetCommandLineW, GetEnvironmentVariableW, ExpandEnvironmentStringsW, DeleteFileW, FindClose, FindFirstFileW, FindNextFileW, HeapSize, RemoveDirectoryW, GetTempPathW, CloseHandle, QueryPerformanceCounter, QueryPerformanceFrequency, WaitForSingleObject, Sleep, GetCurrentProcess, GetCurrentProcessId, TerminateProcess, GetExitCodeProcess, CreateProcessW, GetStartupInfoW, FreeLibrary, LocalFree, SetConsoleCtrlHandler, GetConsoleWindow, K32EnumProcessModules, K32GetModuleFileNameExW, CreateFileW, FindFirstFileExW, GetFinalPathNameByHandleW, MultiByteToWideChar, WideCharToMultiByte, GetFileAttributesExW, HeapReAlloc, WriteConsoleW, SetEndOfFile, GetDriveTypeW, IsDebuggerPresent, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsProcessorFeaturePresent, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, GetModuleHandleW, RtlUnwindEx, SetLastError, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, EncodePointer, RaiseException, RtlPcToFileHeader, GetFileInformationByHandle, GetFileType, PeekNamedPipe, SystemTimeToTzSpecificLocalTime, FileTimeToSystemTime, ReadFile, GetFullPathNameW, SetStdHandle, GetStdHandle, WriteFile, ExitProcess, GetModuleHandleExW, GetCommandLineA, HeapFree, GetConsoleMode, ReadConsoleW, SetFilePointerEx, GetConsoleOutputCP, GetFileSizeEx, HeapAlloc, FlsAlloc, FlsGetValue, FlsSetValue, FlsFree, CompareStringW, LCMapStringW, GetCurrentDirectoryW, FlushFileBuffers, SetEnvironmentVariableW
                                                                                                                                                                                                                                                          ADVAPI32.dllConvertSidToStringSidW, GetTokenInformation, OpenProcessToken, ConvertStringSecurityDescriptorToSecurityDescriptorW
                                                                                                                                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:29.151478052 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:29.151524067 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:29.151762962 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:29.152662992 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:29.152676105 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.691881895 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.692586899 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.692600965 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.693619967 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.693702936 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.695022106 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.695147991 CET44349735149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.695163012 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.695215940 CET49735443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.697551012 CET49737443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.697607994 CET44349737149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.697684050 CET49737443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.698029041 CET49737443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:30.698045015 CET44349737149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:32.089220047 CET44349737149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:32.089804888 CET49737443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:32.089827061 CET44349737149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:32.090857029 CET44349737149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:32.090950966 CET49737443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:32.092247009 CET49737443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:32.092379093 CET44349737149.154.167.220192.168.2.4
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:32.092385054 CET49737443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:32.092456102 CET49737443192.168.2.4149.154.167.220
                                                                                                                                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:29.010663986 CET6332053192.168.2.41.1.1.1
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:29.149070978 CET53633201.1.1.1192.168.2.4
                                                                                                                                                                                                                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:29.010663986 CET192.168.2.41.1.1.10x85deStandard query (0)api.telegram.orgA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                          Dec 5, 2024 11:38:29.149070978 CET1.1.1.1192.168.2.40x85deNo error (0)api.telegram.org149.154.167.220A (IP address)IN (0x0001)false

                                                                                                                                                                                                                                                          Click to jump to process

                                                                                                                                                                                                                                                          Click to jump to process

                                                                                                                                                                                                                                                          Click to dive into process behavior distribution

                                                                                                                                                                                                                                                          Click to jump to process

                                                                                                                                                                                                                                                          Target ID:0
                                                                                                                                                                                                                                                          Start time:05:38:07
                                                                                                                                                                                                                                                          Start date:05/12/2024
                                                                                                                                                                                                                                                          Path:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:"C:\Users\user\Desktop\ROh2ijuEpr.exe"
                                                                                                                                                                                                                                                          Imagebase:0x7ff762a80000
                                                                                                                                                                                                                                                          File size:63'538'768 bytes
                                                                                                                                                                                                                                                          MD5 hash:37C4774A4906C4344C5F55D019033718
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Reputation:low
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:1
                                                                                                                                                                                                                                                          Start time:05:38:08
                                                                                                                                                                                                                                                          Start date:05/12/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff7699e0000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Reputation:high
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:3
                                                                                                                                                                                                                                                          Start time:05:38:23
                                                                                                                                                                                                                                                          Start date:05/12/2024
                                                                                                                                                                                                                                                          Path:C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:"C:\Users\user\Desktop\ROh2ijuEpr.exe"
                                                                                                                                                                                                                                                          Imagebase:0x7ff762a80000
                                                                                                                                                                                                                                                          File size:63'538'768 bytes
                                                                                                                                                                                                                                                          MD5 hash:37C4774A4906C4344C5F55D019033718
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Reputation:low
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Reset < >

                                                                                                                                                                                                                                                            Execution Graph

                                                                                                                                                                                                                                                            Execution Coverage:9.5%
                                                                                                                                                                                                                                                            Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                                                                            Signature Coverage:16.8%
                                                                                                                                                                                                                                                            Total number of Nodes:2000
                                                                                                                                                                                                                                                            Total number of Limit Nodes:51
                                                                                                                                                                                                                                                            execution_graph 20927 7ff762a9acd0 20930 7ff762a9ac48 20927->20930 20937 7ff762aa1548 EnterCriticalSection 20930->20937 20938 7ff762a9bed0 20939 7ff762a9beea 20938->20939 20940 7ff762a9bed5 20938->20940 20944 7ff762a9bef0 20940->20944 20945 7ff762a9bf32 20944->20945 20946 7ff762a9bf3a 20944->20946 20948 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20945->20948 20947 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20946->20947 20949 7ff762a9bf47 20947->20949 20948->20946 20950 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20949->20950 20951 7ff762a9bf54 20950->20951 20952 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20951->20952 20953 7ff762a9bf61 20952->20953 20954 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20953->20954 20955 7ff762a9bf6e 20954->20955 20956 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20955->20956 20957 7ff762a9bf7b 20956->20957 20958 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20957->20958 20959 7ff762a9bf88 20958->20959 20960 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20959->20960 20961 7ff762a9bf95 20960->20961 20962 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20961->20962 20963 7ff762a9bfa5 20962->20963 20964 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20963->20964 20965 7ff762a9bfb5 20964->20965 20970 7ff762a9bd9c 20965->20970 20984 7ff762aa1548 EnterCriticalSection 20970->20984 20986 7ff762aa26d0 21004 7ff762aa1548 EnterCriticalSection 20986->21004 21332 7ff762aabe53 21333 7ff762aabe63 21332->21333 21336 7ff762a962e8 LeaveCriticalSection 21333->21336 21005 7ff762a8accc 21007 7ff762a8a0d3 21005->21007 21008 7ff762a8a156 21005->21008 21006 7ff762a8b350 12 API calls 21006->21008 21007->21006 21007->21008 20285 7ff762aa1b38 20286 7ff762aa1b5c 20285->20286 20289 7ff762aa1b6c 20285->20289 20287 7ff762a95e48 _get_daylight 11 API calls 20286->20287 20288 7ff762aa1b61 20287->20288 20290 7ff762aa1e4c 20289->20290 20291 7ff762aa1b8e 20289->20291 20292 7ff762a95e48 _get_daylight 11 API calls 20290->20292 20293 7ff762aa1baf 20291->20293 20416 7ff762aa21f4 20291->20416 20294 7ff762aa1e51 20292->20294 20297 7ff762aa1c21 20293->20297 20300 7ff762aa1bd5 20293->20300 20309 7ff762aa1c15 20293->20309 20296 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20294->20296 20296->20288 20299 7ff762aa1be4 20297->20299 20302 7ff762a9fe04 _get_daylight 11 API calls 20297->20302 20298 7ff762aa1cce 20304 7ff762aa1d3d 20298->20304 20308 7ff762aa1ceb 20298->20308 20305 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20299->20305 20431 7ff762a9a5fc 20300->20431 20306 7ff762aa1c37 20302->20306 20304->20299 20318 7ff762aa464c 40 API calls 20304->20318 20305->20288 20310 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20306->20310 20313 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20308->20313 20309->20298 20309->20299 20437 7ff762aa839c 20309->20437 20317 7ff762aa1c45 20310->20317 20311 7ff762aa1bdf 20314 7ff762a95e48 _get_daylight 11 API calls 20311->20314 20312 7ff762aa1bfd 20312->20309 20316 7ff762aa21f4 45 API calls 20312->20316 20315 7ff762aa1cf4 20313->20315 20314->20299 20327 7ff762aa1cf9 20315->20327 20473 7ff762aa464c 20315->20473 20316->20309 20317->20299 20317->20309 20320 7ff762a9fe04 _get_daylight 11 API calls 20317->20320 20319 7ff762aa1d7a 20318->20319 20322 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20319->20322 20321 7ff762aa1c67 20320->20321 20324 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20321->20324 20325 7ff762aa1d84 20322->20325 20324->20309 20325->20299 20325->20327 20326 7ff762aa1e40 20329 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20326->20329 20327->20326 20331 7ff762a9fe04 _get_daylight 11 API calls 20327->20331 20328 7ff762aa1d25 20330 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20328->20330 20329->20288 20330->20327 20332 7ff762aa1dc8 20331->20332 20333 7ff762aa1dd0 20332->20333 20334 7ff762aa1dd9 20332->20334 20336 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20333->20336 20335 7ff762a9b3ac __std_exception_copy 37 API calls 20334->20335 20338 7ff762aa1de8 20335->20338 20337 7ff762aa1dd7 20336->20337 20343 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20337->20343 20339 7ff762aa1df0 20338->20339 20340 7ff762aa1e7b 20338->20340 20482 7ff762aa84b4 20339->20482 20342 7ff762a9b844 _isindst 17 API calls 20340->20342 20345 7ff762aa1e8f 20342->20345 20343->20288 20348 7ff762aa1eb8 20345->20348 20353 7ff762aa1ec8 20345->20353 20346 7ff762aa1e38 20349 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20346->20349 20347 7ff762aa1e17 20350 7ff762a95e48 _get_daylight 11 API calls 20347->20350 20351 7ff762a95e48 _get_daylight 11 API calls 20348->20351 20349->20326 20352 7ff762aa1e1c 20350->20352 20375 7ff762aa1ebd 20351->20375 20355 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20352->20355 20354 7ff762aa21ab 20353->20354 20356 7ff762aa1eea 20353->20356 20357 7ff762a95e48 _get_daylight 11 API calls 20354->20357 20355->20337 20358 7ff762aa1f07 20356->20358 20501 7ff762aa22dc 20356->20501 20359 7ff762aa21b0 20357->20359 20362 7ff762aa1f7b 20358->20362 20364 7ff762aa1f2f 20358->20364 20370 7ff762aa1f6f 20358->20370 20361 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20359->20361 20361->20375 20366 7ff762aa1fa3 20362->20366 20371 7ff762a9fe04 _get_daylight 11 API calls 20362->20371 20383 7ff762aa1f3e 20362->20383 20363 7ff762aa202e 20373 7ff762aa204b 20363->20373 20384 7ff762aa209e 20363->20384 20516 7ff762a9a638 20364->20516 20368 7ff762a9fe04 _get_daylight 11 API calls 20366->20368 20366->20370 20366->20383 20374 7ff762aa1fc5 20368->20374 20369 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20369->20375 20370->20363 20370->20383 20522 7ff762aa825c 20370->20522 20376 7ff762aa1f95 20371->20376 20379 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20373->20379 20380 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20374->20380 20381 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20376->20381 20377 7ff762aa1f57 20377->20370 20386 7ff762aa22dc 45 API calls 20377->20386 20378 7ff762aa1f39 20382 7ff762a95e48 _get_daylight 11 API calls 20378->20382 20385 7ff762aa2054 20379->20385 20380->20370 20381->20366 20382->20383 20383->20369 20384->20383 20387 7ff762aa464c 40 API calls 20384->20387 20390 7ff762aa464c 40 API calls 20385->20390 20393 7ff762aa205a 20385->20393 20386->20370 20388 7ff762aa20dc 20387->20388 20389 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20388->20389 20391 7ff762aa20e6 20389->20391 20394 7ff762aa2086 20390->20394 20391->20383 20391->20393 20392 7ff762aa219f 20395 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20392->20395 20393->20392 20397 7ff762a9fe04 _get_daylight 11 API calls 20393->20397 20396 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20394->20396 20395->20375 20396->20393 20398 7ff762aa212b 20397->20398 20399 7ff762aa2133 20398->20399 20400 7ff762aa213c 20398->20400 20401 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20399->20401 20402 7ff762aa16e4 37 API calls 20400->20402 20403 7ff762aa213a 20401->20403 20404 7ff762aa214a 20402->20404 20410 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20403->20410 20405 7ff762aa21df 20404->20405 20406 7ff762aa2152 SetEnvironmentVariableW 20404->20406 20409 7ff762a9b844 _isindst 17 API calls 20405->20409 20407 7ff762aa2176 20406->20407 20408 7ff762aa2197 20406->20408 20412 7ff762a95e48 _get_daylight 11 API calls 20407->20412 20411 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20408->20411 20413 7ff762aa21f3 20409->20413 20410->20375 20411->20392 20414 7ff762aa217b 20412->20414 20415 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20414->20415 20415->20403 20417 7ff762aa2229 20416->20417 20424 7ff762aa2211 20416->20424 20418 7ff762a9fe04 _get_daylight 11 API calls 20417->20418 20427 7ff762aa224d 20418->20427 20419 7ff762aa22d2 20421 7ff762a9b40c __FrameHandler3::FrameUnwindToEmptyState 45 API calls 20419->20421 20420 7ff762aa22ae 20423 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20420->20423 20422 7ff762aa22d8 20421->20422 20423->20424 20424->20293 20425 7ff762a9fe04 _get_daylight 11 API calls 20425->20427 20426 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20426->20427 20427->20419 20427->20420 20427->20425 20427->20426 20428 7ff762a9b3ac __std_exception_copy 37 API calls 20427->20428 20429 7ff762aa22bd 20427->20429 20428->20427 20430 7ff762a9b844 _isindst 17 API calls 20429->20430 20430->20419 20432 7ff762a9a615 20431->20432 20433 7ff762a9a60c 20431->20433 20432->20311 20432->20312 20433->20432 20546 7ff762a9a0d4 20433->20546 20438 7ff762aa74c4 20437->20438 20439 7ff762aa83a9 20437->20439 20440 7ff762aa74d1 20438->20440 20446 7ff762aa7507 20438->20446 20441 7ff762a95e8c 45 API calls 20439->20441 20444 7ff762a95e48 _get_daylight 11 API calls 20440->20444 20459 7ff762aa7478 20440->20459 20443 7ff762aa83dd 20441->20443 20442 7ff762aa7531 20445 7ff762a95e48 _get_daylight 11 API calls 20442->20445 20447 7ff762aa83e2 20443->20447 20451 7ff762aa83f3 20443->20451 20455 7ff762aa840a 20443->20455 20448 7ff762aa74db 20444->20448 20449 7ff762aa7536 20445->20449 20446->20442 20450 7ff762aa7556 20446->20450 20447->20309 20452 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 20448->20452 20454 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 20449->20454 20460 7ff762a95e8c 45 API calls 20450->20460 20466 7ff762aa7541 20450->20466 20456 7ff762a95e48 _get_daylight 11 API calls 20451->20456 20453 7ff762aa74e6 20452->20453 20453->20309 20454->20466 20457 7ff762aa8426 20455->20457 20458 7ff762aa8414 20455->20458 20461 7ff762aa83f8 20456->20461 20464 7ff762aa8437 20457->20464 20465 7ff762aa844e 20457->20465 20463 7ff762a95e48 _get_daylight 11 API calls 20458->20463 20459->20309 20460->20466 20462 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 20461->20462 20462->20447 20467 7ff762aa8419 20463->20467 20763 7ff762aa7514 20464->20763 20772 7ff762aaa1bc 20465->20772 20466->20309 20470 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 20467->20470 20470->20447 20472 7ff762a95e48 _get_daylight 11 API calls 20472->20447 20474 7ff762aa468b 20473->20474 20475 7ff762aa466e 20473->20475 20477 7ff762aa4695 20474->20477 20812 7ff762aa8ea8 20474->20812 20475->20474 20476 7ff762aa467c 20475->20476 20478 7ff762a95e48 _get_daylight 11 API calls 20476->20478 20819 7ff762aa8ee4 20477->20819 20481 7ff762aa4681 memcpy_s 20478->20481 20481->20328 20483 7ff762a95e8c 45 API calls 20482->20483 20484 7ff762aa851a 20483->20484 20487 7ff762aa8528 20484->20487 20831 7ff762aa0190 20484->20831 20834 7ff762a96468 20487->20834 20489 7ff762aa8614 20492 7ff762aa8625 20489->20492 20494 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20489->20494 20490 7ff762a95e8c 45 API calls 20491 7ff762aa8597 20490->20491 20495 7ff762aa0190 5 API calls 20491->20495 20497 7ff762aa85a0 20491->20497 20493 7ff762aa1e13 20492->20493 20496 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20492->20496 20493->20346 20493->20347 20494->20492 20495->20497 20496->20493 20498 7ff762a96468 14 API calls 20497->20498 20499 7ff762aa85fb 20498->20499 20499->20489 20500 7ff762aa8603 SetEnvironmentVariableW 20499->20500 20500->20489 20502 7ff762aa22ff 20501->20502 20503 7ff762aa231c 20501->20503 20502->20358 20504 7ff762a9fe04 _get_daylight 11 API calls 20503->20504 20511 7ff762aa2340 20504->20511 20505 7ff762aa23c4 20507 7ff762a9b40c __FrameHandler3::FrameUnwindToEmptyState 45 API calls 20505->20507 20506 7ff762aa23a1 20508 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20506->20508 20509 7ff762aa23ca 20507->20509 20508->20502 20510 7ff762a9fe04 _get_daylight 11 API calls 20510->20511 20511->20505 20511->20506 20511->20510 20512 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20511->20512 20513 7ff762aa16e4 37 API calls 20511->20513 20514 7ff762aa23b0 20511->20514 20512->20511 20513->20511 20515 7ff762a9b844 _isindst 17 API calls 20514->20515 20515->20505 20517 7ff762a9a648 20516->20517 20521 7ff762a9a651 20516->20521 20518 7ff762a9a148 40 API calls 20517->20518 20517->20521 20519 7ff762a9a65a 20518->20519 20520 7ff762a9a508 12 API calls 20519->20520 20519->20521 20520->20521 20521->20377 20521->20378 20523 7ff762aa8269 20522->20523 20527 7ff762aa8296 20522->20527 20524 7ff762aa826e 20523->20524 20523->20527 20525 7ff762a95e48 _get_daylight 11 API calls 20524->20525 20526 7ff762aa8273 20525->20526 20529 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 20526->20529 20528 7ff762aa82da 20527->20528 20530 7ff762aa82f9 20527->20530 20544 7ff762aa82ce __crtLCMapStringW 20527->20544 20531 7ff762a95e48 _get_daylight 11 API calls 20528->20531 20532 7ff762aa827e 20529->20532 20533 7ff762aa8315 20530->20533 20534 7ff762aa8303 20530->20534 20535 7ff762aa82df 20531->20535 20532->20370 20537 7ff762a95e8c 45 API calls 20533->20537 20536 7ff762a95e48 _get_daylight 11 API calls 20534->20536 20538 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 20535->20538 20539 7ff762aa8308 20536->20539 20540 7ff762aa8322 20537->20540 20538->20544 20541 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 20539->20541 20540->20544 20856 7ff762aa9d78 20540->20856 20541->20544 20544->20370 20545 7ff762a95e48 _get_daylight 11 API calls 20545->20544 20547 7ff762a9a0ed 20546->20547 20556 7ff762a9a0e9 20546->20556 20569 7ff762aa3860 20547->20569 20552 7ff762a9a0ff 20555 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20552->20555 20553 7ff762a9a10b 20595 7ff762a9a1b8 20553->20595 20555->20556 20556->20432 20561 7ff762a9a428 20556->20561 20558 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20559 7ff762a9a132 20558->20559 20560 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20559->20560 20560->20556 20562 7ff762a9a451 20561->20562 20567 7ff762a9a46a 20561->20567 20562->20432 20563 7ff762aa1a58 WideCharToMultiByte 20563->20567 20564 7ff762a9fe04 _get_daylight 11 API calls 20564->20567 20565 7ff762a9a4fa 20566 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20565->20566 20566->20562 20567->20562 20567->20563 20567->20564 20567->20565 20568 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20567->20568 20568->20567 20570 7ff762a9a0f2 20569->20570 20571 7ff762aa386d 20569->20571 20575 7ff762aa3b9c GetEnvironmentStringsW 20570->20575 20614 7ff762a9c124 20571->20614 20576 7ff762a9a0f7 20575->20576 20577 7ff762aa3bcc 20575->20577 20576->20552 20576->20553 20577->20577 20578 7ff762aa1a58 WideCharToMultiByte 20577->20578 20579 7ff762aa3c1d 20578->20579 20580 7ff762aa3c24 FreeEnvironmentStringsW 20579->20580 20581 7ff762a9e6c4 _fread_nolock 12 API calls 20579->20581 20580->20576 20582 7ff762aa3c37 20581->20582 20583 7ff762aa3c3f 20582->20583 20584 7ff762aa3c48 20582->20584 20585 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20583->20585 20586 7ff762aa1a58 WideCharToMultiByte 20584->20586 20587 7ff762aa3c46 20585->20587 20588 7ff762aa3c6b 20586->20588 20587->20580 20589 7ff762aa3c6f 20588->20589 20590 7ff762aa3c79 20588->20590 20591 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20589->20591 20592 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20590->20592 20593 7ff762aa3c77 FreeEnvironmentStringsW 20591->20593 20592->20593 20593->20576 20596 7ff762a9a1dd 20595->20596 20597 7ff762a9fe04 _get_daylight 11 API calls 20596->20597 20610 7ff762a9a213 20597->20610 20598 7ff762a9a21b 20599 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20598->20599 20600 7ff762a9a113 20599->20600 20600->20558 20601 7ff762a9a28e 20602 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20601->20602 20602->20600 20603 7ff762a9fe04 _get_daylight 11 API calls 20603->20610 20604 7ff762a9a27d 20605 7ff762a9a3e4 11 API calls 20604->20605 20607 7ff762a9a285 20605->20607 20606 7ff762a9b3ac __std_exception_copy 37 API calls 20606->20610 20608 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20607->20608 20608->20598 20609 7ff762a9a2b3 20611 7ff762a9b844 _isindst 17 API calls 20609->20611 20610->20598 20610->20601 20610->20603 20610->20604 20610->20606 20610->20609 20612 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20610->20612 20613 7ff762a9a2c6 20611->20613 20612->20610 20615 7ff762a9c150 FlsSetValue 20614->20615 20616 7ff762a9c135 FlsGetValue 20614->20616 20617 7ff762a9c142 20615->20617 20619 7ff762a9c15d 20615->20619 20616->20617 20618 7ff762a9c14a 20616->20618 20620 7ff762a9c148 20617->20620 20621 7ff762a9b40c __FrameHandler3::FrameUnwindToEmptyState 45 API calls 20617->20621 20618->20615 20622 7ff762a9fe04 _get_daylight 11 API calls 20619->20622 20634 7ff762aa3534 20620->20634 20623 7ff762a9c1c5 20621->20623 20624 7ff762a9c16c 20622->20624 20625 7ff762a9c18a FlsSetValue 20624->20625 20626 7ff762a9c17a FlsSetValue 20624->20626 20628 7ff762a9c196 FlsSetValue 20625->20628 20629 7ff762a9c1a8 20625->20629 20627 7ff762a9c183 20626->20627 20630 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20627->20630 20628->20627 20631 7ff762a9bdfc _get_daylight 11 API calls 20629->20631 20630->20617 20632 7ff762a9c1b0 20631->20632 20633 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20632->20633 20633->20620 20657 7ff762aa37a4 20634->20657 20636 7ff762aa3569 20672 7ff762aa3234 20636->20672 20639 7ff762aa3586 20639->20570 20640 7ff762a9e6c4 _fread_nolock 12 API calls 20641 7ff762aa3597 20640->20641 20642 7ff762aa359f 20641->20642 20644 7ff762aa35ae 20641->20644 20643 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20642->20643 20643->20639 20644->20644 20679 7ff762aa38dc 20644->20679 20647 7ff762aa36aa 20648 7ff762a95e48 _get_daylight 11 API calls 20647->20648 20650 7ff762aa36af 20648->20650 20649 7ff762aa3705 20653 7ff762aa376c 20649->20653 20690 7ff762aa3064 20649->20690 20651 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20650->20651 20651->20639 20652 7ff762aa36c4 20652->20649 20654 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20652->20654 20656 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20653->20656 20654->20649 20656->20639 20658 7ff762aa37c7 20657->20658 20659 7ff762aa37d1 20658->20659 20705 7ff762aa1548 EnterCriticalSection 20658->20705 20662 7ff762aa3843 20659->20662 20664 7ff762a9b40c __FrameHandler3::FrameUnwindToEmptyState 45 API calls 20659->20664 20662->20636 20666 7ff762aa385b 20664->20666 20667 7ff762aa38b2 20666->20667 20669 7ff762a9c124 50 API calls 20666->20669 20667->20636 20670 7ff762aa389c 20669->20670 20671 7ff762aa3534 65 API calls 20670->20671 20671->20667 20673 7ff762a95e8c 45 API calls 20672->20673 20674 7ff762aa3248 20673->20674 20675 7ff762aa3254 GetOEMCP 20674->20675 20676 7ff762aa3266 20674->20676 20678 7ff762aa327b 20675->20678 20677 7ff762aa326b GetACP 20676->20677 20676->20678 20677->20678 20678->20639 20678->20640 20680 7ff762aa3234 47 API calls 20679->20680 20681 7ff762aa3909 20680->20681 20682 7ff762aa3a5f 20681->20682 20683 7ff762aa3946 IsValidCodePage 20681->20683 20689 7ff762aa3960 memcpy_s 20681->20689 20684 7ff762a8bb10 _log10_special 8 API calls 20682->20684 20683->20682 20685 7ff762aa3957 20683->20685 20686 7ff762aa36a1 20684->20686 20687 7ff762aa3986 GetCPInfo 20685->20687 20685->20689 20686->20647 20686->20652 20687->20682 20687->20689 20706 7ff762aa334c 20689->20706 20762 7ff762aa1548 EnterCriticalSection 20690->20762 20707 7ff762aa3389 GetCPInfo 20706->20707 20708 7ff762aa347f 20706->20708 20707->20708 20710 7ff762aa339c 20707->20710 20709 7ff762a8bb10 _log10_special 8 API calls 20708->20709 20711 7ff762aa351e 20709->20711 20712 7ff762aa40b0 48 API calls 20710->20712 20711->20682 20713 7ff762aa3413 20712->20713 20717 7ff762aa8df4 20713->20717 20716 7ff762aa8df4 54 API calls 20716->20708 20718 7ff762a95e8c 45 API calls 20717->20718 20719 7ff762aa8e19 20718->20719 20722 7ff762aa8ac0 20719->20722 20723 7ff762aa8b01 20722->20723 20724 7ff762aa0b10 _fread_nolock MultiByteToWideChar 20723->20724 20729 7ff762aa8b4b 20724->20729 20725 7ff762aa8dc9 20727 7ff762a8bb10 _log10_special 8 API calls 20725->20727 20726 7ff762aa8c81 20726->20725 20732 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20726->20732 20728 7ff762aa3446 20727->20728 20728->20716 20729->20725 20729->20726 20730 7ff762a9e6c4 _fread_nolock 12 API calls 20729->20730 20731 7ff762aa8b83 20729->20731 20730->20731 20731->20726 20733 7ff762aa0b10 _fread_nolock MultiByteToWideChar 20731->20733 20732->20725 20734 7ff762aa8bf6 20733->20734 20734->20726 20753 7ff762aa0350 20734->20753 20737 7ff762aa8c41 20737->20726 20739 7ff762aa0350 __crtLCMapStringW 6 API calls 20737->20739 20738 7ff762aa8c92 20740 7ff762a9e6c4 _fread_nolock 12 API calls 20738->20740 20741 7ff762aa8d64 20738->20741 20743 7ff762aa8cb0 20738->20743 20739->20726 20740->20743 20741->20726 20742 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20741->20742 20742->20726 20743->20726 20744 7ff762aa0350 __crtLCMapStringW 6 API calls 20743->20744 20745 7ff762aa8d30 20744->20745 20745->20741 20746 7ff762aa8d50 20745->20746 20747 7ff762aa8d66 20745->20747 20748 7ff762aa1a58 WideCharToMultiByte 20746->20748 20749 7ff762aa1a58 WideCharToMultiByte 20747->20749 20750 7ff762aa8d5e 20748->20750 20749->20750 20750->20741 20751 7ff762aa8d7e 20750->20751 20751->20726 20752 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20751->20752 20752->20726 20754 7ff762a9ff7c __crtLCMapStringW 5 API calls 20753->20754 20755 7ff762aa038e 20754->20755 20756 7ff762aa0396 20755->20756 20759 7ff762aa043c 20755->20759 20756->20726 20756->20737 20756->20738 20758 7ff762aa03ff LCMapStringW 20758->20756 20760 7ff762a9ff7c __crtLCMapStringW 5 API calls 20759->20760 20761 7ff762aa046a __crtLCMapStringW 20760->20761 20761->20758 20764 7ff762aa7531 20763->20764 20765 7ff762aa7548 20763->20765 20766 7ff762a95e48 _get_daylight 11 API calls 20764->20766 20765->20764 20768 7ff762aa7556 20765->20768 20767 7ff762aa7536 20766->20767 20769 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 20767->20769 20770 7ff762a95e8c 45 API calls 20768->20770 20771 7ff762aa7541 20768->20771 20769->20771 20770->20771 20771->20447 20773 7ff762a95e8c 45 API calls 20772->20773 20774 7ff762aaa1e1 20773->20774 20777 7ff762aa9e38 20774->20777 20779 7ff762aa9e86 20777->20779 20778 7ff762a8bb10 _log10_special 8 API calls 20780 7ff762aa8475 20778->20780 20781 7ff762aa9f0d 20779->20781 20783 7ff762aa9ef8 GetCPInfo 20779->20783 20787 7ff762aa9f11 20779->20787 20780->20447 20780->20472 20782 7ff762aa0b10 _fread_nolock MultiByteToWideChar 20781->20782 20781->20787 20784 7ff762aa9fa5 20782->20784 20783->20781 20783->20787 20785 7ff762a9e6c4 _fread_nolock 12 API calls 20784->20785 20786 7ff762aa9fdc 20784->20786 20784->20787 20785->20786 20786->20787 20788 7ff762aa0b10 _fread_nolock MultiByteToWideChar 20786->20788 20787->20778 20789 7ff762aaa04a 20788->20789 20790 7ff762aaa12c 20789->20790 20791 7ff762aa0b10 _fread_nolock MultiByteToWideChar 20789->20791 20790->20787 20792 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20790->20792 20793 7ff762aaa070 20791->20793 20792->20787 20793->20790 20794 7ff762a9e6c4 _fread_nolock 12 API calls 20793->20794 20795 7ff762aaa09d 20793->20795 20794->20795 20795->20790 20796 7ff762aa0b10 _fread_nolock MultiByteToWideChar 20795->20796 20797 7ff762aaa114 20796->20797 20798 7ff762aaa134 20797->20798 20799 7ff762aaa11a 20797->20799 20806 7ff762aa01d4 20798->20806 20799->20790 20802 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20799->20802 20802->20790 20803 7ff762aaa173 20803->20787 20805 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20803->20805 20804 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20804->20803 20805->20787 20807 7ff762a9ff7c __crtLCMapStringW 5 API calls 20806->20807 20808 7ff762aa0212 20807->20808 20809 7ff762aa021a 20808->20809 20810 7ff762aa043c __crtLCMapStringW 5 API calls 20808->20810 20809->20803 20809->20804 20811 7ff762aa0283 CompareStringW 20810->20811 20811->20809 20813 7ff762aa8eb1 20812->20813 20814 7ff762aa8eca HeapSize 20812->20814 20815 7ff762a95e48 _get_daylight 11 API calls 20813->20815 20816 7ff762aa8eb6 20815->20816 20817 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 20816->20817 20818 7ff762aa8ec1 20817->20818 20818->20477 20820 7ff762aa8f03 20819->20820 20821 7ff762aa8ef9 20819->20821 20823 7ff762aa8f08 20820->20823 20829 7ff762aa8f0f _get_daylight 20820->20829 20822 7ff762a9e6c4 _fread_nolock 12 API calls 20821->20822 20828 7ff762aa8f01 20822->20828 20826 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20823->20826 20824 7ff762aa8f42 HeapReAlloc 20824->20828 20824->20829 20825 7ff762aa8f15 20827 7ff762a95e48 _get_daylight 11 API calls 20825->20827 20826->20828 20827->20828 20828->20481 20829->20824 20829->20825 20830 7ff762aa4800 _get_daylight 2 API calls 20829->20830 20830->20829 20832 7ff762a9ff7c __crtLCMapStringW 5 API calls 20831->20832 20833 7ff762aa01b0 20832->20833 20833->20487 20835 7ff762a96492 20834->20835 20836 7ff762a964b6 20834->20836 20840 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20835->20840 20843 7ff762a964a1 20835->20843 20837 7ff762a96510 20836->20837 20838 7ff762a964bb 20836->20838 20839 7ff762aa0b10 _fread_nolock MultiByteToWideChar 20837->20839 20841 7ff762a964d0 20838->20841 20838->20843 20844 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20838->20844 20851 7ff762a9652c 20839->20851 20840->20843 20845 7ff762a9e6c4 _fread_nolock 12 API calls 20841->20845 20842 7ff762a96533 GetLastError 20846 7ff762a95dbc _fread_nolock 11 API calls 20842->20846 20843->20489 20843->20490 20844->20841 20845->20843 20849 7ff762a96540 20846->20849 20847 7ff762a9656e 20847->20843 20848 7ff762aa0b10 _fread_nolock MultiByteToWideChar 20847->20848 20852 7ff762a965b2 20848->20852 20853 7ff762a95e48 _get_daylight 11 API calls 20849->20853 20850 7ff762a96561 20855 7ff762a9e6c4 _fread_nolock 12 API calls 20850->20855 20851->20842 20851->20847 20851->20850 20854 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20851->20854 20852->20842 20852->20843 20853->20843 20854->20850 20855->20847 20857 7ff762aa9da1 __crtLCMapStringW 20856->20857 20858 7ff762aa835e 20857->20858 20859 7ff762aa01d4 6 API calls 20857->20859 20858->20544 20858->20545 20859->20858 20877 7ff762aa2920 20888 7ff762aa8654 20877->20888 20889 7ff762aa8661 20888->20889 20890 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20889->20890 20892 7ff762aa867d 20889->20892 20890->20889 20891 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 20891->20892 20892->20891 20893 7ff762aa2929 20892->20893 20894 7ff762aa1548 EnterCriticalSection 20893->20894 16925 7ff762a8b0a0 16926 7ff762a8b0ce 16925->16926 16927 7ff762a8b0b5 16925->16927 16927->16926 16930 7ff762a9e6c4 16927->16930 16931 7ff762a9e70f 16930->16931 16932 7ff762a9e6d3 _get_daylight 16930->16932 16940 7ff762a95e48 16931->16940 16932->16931 16933 7ff762a9e6f6 HeapAlloc 16932->16933 16937 7ff762aa4800 16932->16937 16933->16932 16935 7ff762a8b12e 16933->16935 16943 7ff762aa4840 16937->16943 16949 7ff762a9c1c8 GetLastError 16940->16949 16942 7ff762a95e51 16942->16935 16948 7ff762aa1548 EnterCriticalSection 16943->16948 16950 7ff762a9c209 FlsSetValue 16949->16950 16955 7ff762a9c1ec 16949->16955 16951 7ff762a9c1f9 SetLastError 16950->16951 16952 7ff762a9c21b 16950->16952 16951->16942 16966 7ff762a9fe04 16952->16966 16955->16950 16955->16951 16957 7ff762a9c248 FlsSetValue 16959 7ff762a9c254 FlsSetValue 16957->16959 16960 7ff762a9c266 16957->16960 16958 7ff762a9c238 FlsSetValue 16961 7ff762a9c241 16958->16961 16959->16961 16979 7ff762a9bdfc 16960->16979 16973 7ff762a9b464 16961->16973 16971 7ff762a9fe15 _get_daylight 16966->16971 16967 7ff762a9fe66 16970 7ff762a95e48 _get_daylight 10 API calls 16967->16970 16968 7ff762a9fe4a HeapAlloc 16969 7ff762a9c22a 16968->16969 16968->16971 16969->16957 16969->16958 16970->16969 16971->16967 16971->16968 16972 7ff762aa4800 _get_daylight 2 API calls 16971->16972 16972->16971 16974 7ff762a9b498 16973->16974 16975 7ff762a9b469 RtlFreeHeap 16973->16975 16974->16951 16975->16974 16976 7ff762a9b484 GetLastError 16975->16976 16977 7ff762a9b491 Concurrency::details::SchedulerProxy::DeleteThis 16976->16977 16978 7ff762a95e48 _get_daylight 9 API calls 16977->16978 16978->16974 16984 7ff762a9bcd4 16979->16984 16996 7ff762aa1548 EnterCriticalSection 16984->16996 17380 7ff762a9a899 17392 7ff762a9b358 17380->17392 17393 7ff762a9c050 __FrameHandler3::FrameUnwindToEmptyState 45 API calls 17392->17393 17394 7ff762a9b361 17393->17394 17395 7ff762a9b40c __FrameHandler3::FrameUnwindToEmptyState 45 API calls 17394->17395 17396 7ff762a9b381 17395->17396 21063 7ff762a8989b 21064 7ff762a898a1 21063->21064 21065 7ff762a8b350 12 API calls 21064->21065 21066 7ff762a8a156 21064->21066 21065->21066 21074 7ff762a8c110 21075 7ff762a8c120 21074->21075 21091 7ff762a9aae0 21075->21091 21077 7ff762a8c12c 21097 7ff762a8c418 21077->21097 21079 7ff762a8c6fc 7 API calls 21081 7ff762a8c1c5 21079->21081 21080 7ff762a8c144 _RTC_Initialize 21089 7ff762a8c199 21080->21089 21102 7ff762a8c5c8 21080->21102 21083 7ff762a8c159 21105 7ff762a99f50 21083->21105 21089->21079 21090 7ff762a8c1b5 21089->21090 21092 7ff762a9aaf1 21091->21092 21093 7ff762a9aaf9 21092->21093 21094 7ff762a95e48 _get_daylight 11 API calls 21092->21094 21093->21077 21095 7ff762a9ab08 21094->21095 21096 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 21095->21096 21096->21093 21098 7ff762a8c429 21097->21098 21101 7ff762a8c42e __scrt_acquire_startup_lock 21097->21101 21099 7ff762a8c6fc 7 API calls 21098->21099 21098->21101 21100 7ff762a8c4a2 21099->21100 21101->21080 21130 7ff762a8c58c 21102->21130 21104 7ff762a8c5d1 21104->21083 21106 7ff762a99f70 21105->21106 21107 7ff762a8c165 21105->21107 21108 7ff762a99f78 21106->21108 21109 7ff762a99f8e GetModuleFileNameW 21106->21109 21107->21089 21129 7ff762a8c69c InitializeSListHead 21107->21129 21110 7ff762a95e48 _get_daylight 11 API calls 21108->21110 21113 7ff762a99fb9 21109->21113 21111 7ff762a99f7d 21110->21111 21112 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 21111->21112 21112->21107 21145 7ff762a99ef0 21113->21145 21116 7ff762a9a001 21117 7ff762a95e48 _get_daylight 11 API calls 21116->21117 21118 7ff762a9a006 21117->21118 21119 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 21118->21119 21119->21107 21120 7ff762a9a019 21121 7ff762a9a03b 21120->21121 21123 7ff762a9a080 21120->21123 21124 7ff762a9a067 21120->21124 21122 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 21121->21122 21122->21107 21126 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 21123->21126 21125 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 21124->21125 21127 7ff762a9a070 21125->21127 21126->21121 21128 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 21127->21128 21128->21107 21131 7ff762a8c5a6 21130->21131 21133 7ff762a8c59f 21130->21133 21134 7ff762a9b16c 21131->21134 21133->21104 21137 7ff762a9ada8 21134->21137 21144 7ff762aa1548 EnterCriticalSection 21137->21144 21146 7ff762a99f08 21145->21146 21150 7ff762a99f40 21145->21150 21147 7ff762a9fe04 _get_daylight 11 API calls 21146->21147 21146->21150 21148 7ff762a99f36 21147->21148 21149 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 21148->21149 21149->21150 21150->21116 21150->21120 21594 7ff762a96280 21595 7ff762a9628b 21594->21595 21603 7ff762aa0514 21595->21603 21616 7ff762aa1548 EnterCriticalSection 21603->21616 17397 7ff762aa0bfc 17398 7ff762aa0dee 17397->17398 17400 7ff762aa0c3e _isindst 17397->17400 17399 7ff762a95e48 _get_daylight 11 API calls 17398->17399 17417 7ff762aa0dde 17399->17417 17400->17398 17403 7ff762aa0cbe _isindst 17400->17403 17401 7ff762a8bb10 _log10_special 8 API calls 17402 7ff762aa0e09 17401->17402 17418 7ff762aa7404 17403->17418 17408 7ff762aa0e1a 17410 7ff762a9b844 _isindst 17 API calls 17408->17410 17412 7ff762aa0e2e 17410->17412 17415 7ff762aa0d1b 17415->17417 17442 7ff762aa7448 17415->17442 17417->17401 17419 7ff762aa0cdc 17418->17419 17420 7ff762aa7413 17418->17420 17424 7ff762aa6808 17419->17424 17449 7ff762aa1548 EnterCriticalSection 17420->17449 17425 7ff762aa6811 17424->17425 17426 7ff762aa0cf1 17424->17426 17427 7ff762a95e48 _get_daylight 11 API calls 17425->17427 17426->17408 17430 7ff762aa6838 17426->17430 17428 7ff762aa6816 17427->17428 17429 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 17428->17429 17429->17426 17431 7ff762aa6841 17430->17431 17432 7ff762aa0d02 17430->17432 17433 7ff762a95e48 _get_daylight 11 API calls 17431->17433 17432->17408 17436 7ff762aa6868 17432->17436 17434 7ff762aa6846 17433->17434 17435 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 17434->17435 17435->17432 17437 7ff762aa6871 17436->17437 17438 7ff762aa0d13 17436->17438 17439 7ff762a95e48 _get_daylight 11 API calls 17437->17439 17438->17408 17438->17415 17440 7ff762aa6876 17439->17440 17441 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 17440->17441 17441->17438 17450 7ff762aa1548 EnterCriticalSection 17442->17450 17451 7ff762a8c1fc 17472 7ff762a8c3dc 17451->17472 17454 7ff762a8c353 17639 7ff762a8c6fc IsProcessorFeaturePresent 17454->17639 17455 7ff762a8c21d __scrt_acquire_startup_lock 17457 7ff762a8c35d 17455->17457 17463 7ff762a8c23b __scrt_release_startup_lock 17455->17463 17458 7ff762a8c6fc 7 API calls 17457->17458 17460 7ff762a8c368 __FrameHandler3::FrameUnwindToEmptyState 17458->17460 17459 7ff762a8c260 17461 7ff762a8c2e6 17480 7ff762a9a6b8 17461->17480 17463->17459 17463->17461 17628 7ff762a9aa64 17463->17628 17465 7ff762a8c2eb 17486 7ff762a81000 17465->17486 17470 7ff762a8c30f 17470->17460 17635 7ff762a8c560 17470->17635 17473 7ff762a8c3e4 17472->17473 17474 7ff762a8c3f0 __scrt_dllmain_crt_thread_attach 17473->17474 17475 7ff762a8c215 17474->17475 17476 7ff762a8c3fd 17474->17476 17475->17454 17475->17455 17646 7ff762a9b30c 17476->17646 17481 7ff762a9a6c8 17480->17481 17485 7ff762a9a6dd 17480->17485 17481->17485 17689 7ff762a9a148 17481->17689 17485->17465 17487 7ff762a82b80 17486->17487 17751 7ff762a963c0 17487->17751 17489 7ff762a82bbc 17758 7ff762a82a70 17489->17758 17493 7ff762a8bb10 _log10_special 8 API calls 17495 7ff762a830ec 17493->17495 17633 7ff762a8c84c GetModuleHandleW 17495->17633 17496 7ff762a82bfd 17918 7ff762a81c60 17496->17918 17497 7ff762a82cdb 17927 7ff762a839d0 17497->17927 17500 7ff762a82c1c 17830 7ff762a87e70 17500->17830 17503 7ff762a82d2a 17950 7ff762a81e50 17503->17950 17505 7ff762a82c4f 17513 7ff762a82c7b __std_exception_destroy 17505->17513 17922 7ff762a87fe0 17505->17922 17507 7ff762a82d1d 17508 7ff762a82d45 17507->17508 17509 7ff762a82d22 17507->17509 17511 7ff762a81c60 49 API calls 17508->17511 17946 7ff762a8f5a4 17509->17946 17514 7ff762a82d64 17511->17514 17515 7ff762a87e70 14 API calls 17513->17515 17522 7ff762a82c9e __std_exception_destroy 17513->17522 17519 7ff762a81930 115 API calls 17514->17519 17515->17522 17517 7ff762a82dcc 17518 7ff762a87fe0 40 API calls 17517->17518 17520 7ff762a82dd8 17518->17520 17521 7ff762a82d8e 17519->17521 17523 7ff762a87fe0 40 API calls 17520->17523 17521->17500 17524 7ff762a82d9e 17521->17524 17528 7ff762a82cce __std_exception_destroy 17522->17528 17961 7ff762a87f80 17522->17961 17525 7ff762a82de4 17523->17525 17526 7ff762a81e50 81 API calls 17524->17526 17527 7ff762a87fe0 40 API calls 17525->17527 17620 7ff762a82bc9 __std_exception_destroy 17526->17620 17527->17528 17529 7ff762a87e70 14 API calls 17528->17529 17530 7ff762a82e04 17529->17530 17531 7ff762a82ef9 17530->17531 17532 7ff762a82e29 __std_exception_destroy 17530->17532 17533 7ff762a81e50 81 API calls 17531->17533 17534 7ff762a87f80 40 API calls 17532->17534 17546 7ff762a82e6c 17532->17546 17533->17620 17534->17546 17535 7ff762a8303a 17539 7ff762a87e70 14 API calls 17535->17539 17536 7ff762a83033 17968 7ff762a885b0 17536->17968 17540 7ff762a8304f __std_exception_destroy 17539->17540 17541 7ff762a8308a 17540->17541 17542 7ff762a83187 17540->17542 17543 7ff762a8311a 17541->17543 17544 7ff762a83094 17541->17544 17975 7ff762a838f0 17542->17975 17548 7ff762a87e70 14 API calls 17543->17548 17843 7ff762a885c0 17544->17843 17546->17535 17546->17536 17551 7ff762a83126 17548->17551 17549 7ff762a83195 17552 7ff762a831ab 17549->17552 17553 7ff762a831b7 17549->17553 17554 7ff762a830a5 17551->17554 17558 7ff762a83133 17551->17558 17978 7ff762a83a40 17552->17978 17556 7ff762a81c60 49 API calls 17553->17556 17561 7ff762a81e50 81 API calls 17554->17561 17568 7ff762a8310e __std_exception_destroy 17556->17568 17562 7ff762a81c60 49 API calls 17558->17562 17559 7ff762a8320a 17893 7ff762a88950 17559->17893 17561->17620 17564 7ff762a83151 17562->17564 17567 7ff762a83158 17564->17567 17564->17568 17565 7ff762a831ed SetDllDirectoryW LoadLibraryExW 17565->17559 17566 7ff762a8321d SetDllDirectoryW 17571 7ff762a832a1 17566->17571 17572 7ff762a83250 17566->17572 17569 7ff762a81e50 81 API calls 17567->17569 17568->17559 17568->17565 17569->17620 17573 7ff762a83433 17571->17573 17575 7ff762a83362 17571->17575 17574 7ff762a87e70 14 API calls 17572->17574 17576 7ff762a8343e 17573->17576 17582 7ff762a83445 17573->17582 17581 7ff762a8325c __std_exception_destroy 17574->17581 17898 7ff762a82780 17575->17898 17578 7ff762a885b0 5 API calls 17576->17578 17580 7ff762a83443 17578->17580 17580->17582 17583 7ff762a83339 17581->17583 17587 7ff762a83295 17581->17587 18055 7ff762a82720 17582->18055 17587->17571 17981 7ff762a86200 17587->17981 17620->17493 17629 7ff762a9aa9c 17628->17629 17630 7ff762a9aa7b 17628->17630 17631 7ff762a9b358 45 API calls 17629->17631 17630->17461 17632 7ff762a9aaa1 17631->17632 17634 7ff762a8c85d 17633->17634 17634->17470 17637 7ff762a8c571 17635->17637 17636 7ff762a8c326 17636->17459 17637->17636 17638 7ff762a8ce18 7 API calls 17637->17638 17638->17636 17640 7ff762a8c722 memcpy_s __FrameHandler3::FrameUnwindToEmptyState 17639->17640 17641 7ff762a8c741 RtlCaptureContext RtlLookupFunctionEntry 17640->17641 17642 7ff762a8c7a6 memcpy_s 17641->17642 17643 7ff762a8c76a RtlVirtualUnwind 17641->17643 17644 7ff762a8c7d8 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 17642->17644 17643->17642 17645 7ff762a8c826 __FrameHandler3::FrameUnwindToEmptyState 17644->17645 17645->17457 17647 7ff762aa471c 17646->17647 17648 7ff762a8c402 17647->17648 17656 7ff762a9d420 17647->17656 17648->17475 17650 7ff762a8ce18 17648->17650 17651 7ff762a8ce20 17650->17651 17652 7ff762a8ce2a 17650->17652 17668 7ff762a8d1b4 17651->17668 17652->17475 17667 7ff762aa1548 EnterCriticalSection 17656->17667 17669 7ff762a8ce25 17668->17669 17670 7ff762a8d1c3 17668->17670 17672 7ff762a8d220 17669->17672 17676 7ff762a8d3f0 17670->17676 17673 7ff762a8d24b 17672->17673 17674 7ff762a8d24f 17673->17674 17675 7ff762a8d22e DeleteCriticalSection 17673->17675 17674->17652 17675->17673 17680 7ff762a8d258 17676->17680 17681 7ff762a8d29c __vcrt_InitializeCriticalSectionEx 17680->17681 17687 7ff762a8d342 TlsFree 17680->17687 17682 7ff762a8d2ca LoadLibraryExW 17681->17682 17683 7ff762a8d389 GetProcAddress 17681->17683 17681->17687 17688 7ff762a8d30d LoadLibraryExW 17681->17688 17684 7ff762a8d369 17682->17684 17685 7ff762a8d2eb GetLastError 17682->17685 17683->17687 17684->17683 17686 7ff762a8d380 FreeLibrary 17684->17686 17685->17681 17686->17683 17688->17681 17688->17684 17690 7ff762a9a161 17689->17690 17697 7ff762a9a15d 17689->17697 17710 7ff762aa3cac GetEnvironmentStringsW 17690->17710 17693 7ff762a9a17a 17717 7ff762a9a2c8 17693->17717 17694 7ff762a9a16e 17695 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17694->17695 17695->17697 17697->17485 17702 7ff762a9a508 17697->17702 17699 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17700 7ff762a9a1a1 17699->17700 17701 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17700->17701 17701->17697 17703 7ff762a9a52b 17702->17703 17704 7ff762a9a542 17702->17704 17703->17485 17704->17703 17705 7ff762a9fe04 _get_daylight 11 API calls 17704->17705 17706 7ff762a9a5b6 17704->17706 17707 7ff762aa0b10 MultiByteToWideChar _fread_nolock 17704->17707 17709 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17704->17709 17705->17704 17708 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17706->17708 17707->17704 17708->17703 17709->17704 17711 7ff762aa3cd0 17710->17711 17712 7ff762a9a166 17710->17712 17713 7ff762a9e6c4 _fread_nolock 12 API calls 17711->17713 17712->17693 17712->17694 17714 7ff762aa3d07 memcpy_s 17713->17714 17715 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17714->17715 17716 7ff762aa3d27 FreeEnvironmentStringsW 17715->17716 17716->17712 17718 7ff762a9a2f0 17717->17718 17719 7ff762a9fe04 _get_daylight 11 API calls 17718->17719 17730 7ff762a9a32b 17719->17730 17720 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17721 7ff762a9a182 17720->17721 17721->17699 17722 7ff762a9a3ad 17723 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17722->17723 17723->17721 17724 7ff762a9fe04 _get_daylight 11 API calls 17724->17730 17725 7ff762a9a39c 17745 7ff762a9a3e4 17725->17745 17729 7ff762a9a3d0 17734 7ff762a9b844 _isindst 17 API calls 17729->17734 17730->17722 17730->17724 17730->17725 17730->17729 17732 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17730->17732 17733 7ff762a9a333 17730->17733 17736 7ff762aa16e4 17730->17736 17731 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17731->17733 17732->17730 17733->17720 17735 7ff762a9a3e2 17734->17735 17737 7ff762aa16f1 17736->17737 17738 7ff762aa16fb 17736->17738 17737->17738 17743 7ff762aa1717 17737->17743 17739 7ff762a95e48 _get_daylight 11 API calls 17738->17739 17740 7ff762aa1703 17739->17740 17742 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 17740->17742 17741 7ff762aa170f 17741->17730 17742->17741 17743->17741 17744 7ff762a95e48 _get_daylight 11 API calls 17743->17744 17744->17740 17746 7ff762a9a3e9 17745->17746 17750 7ff762a9a3a4 17745->17750 17747 7ff762a9a412 17746->17747 17748 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17746->17748 17749 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17747->17749 17748->17746 17749->17750 17750->17731 17754 7ff762aa06f0 17751->17754 17752 7ff762aa0743 17753 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 17752->17753 17757 7ff762aa076c 17753->17757 17754->17752 17755 7ff762aa0796 17754->17755 18068 7ff762aa05c8 17755->18068 17757->17489 18076 7ff762a8be10 17758->18076 17761 7ff762a82aab GetLastError 18083 7ff762a82310 17761->18083 17762 7ff762a82ad0 18078 7ff762a88840 FindFirstFileExW 17762->18078 17765 7ff762a82ac6 17770 7ff762a8bb10 _log10_special 8 API calls 17765->17770 17767 7ff762a82b3d 18113 7ff762a88a00 17767->18113 17768 7ff762a82ae3 18100 7ff762a888c0 CreateFileW 17768->18100 17773 7ff762a82b75 17770->17773 17772 7ff762a82b4b 17772->17765 17778 7ff762a81f30 78 API calls 17772->17778 17773->17620 17780 7ff762a81930 17773->17780 17775 7ff762a82b0c __vcrt_InitializeCriticalSectionEx 17775->17767 17776 7ff762a82af4 18103 7ff762a81f30 17776->18103 17778->17765 17781 7ff762a839d0 108 API calls 17780->17781 17782 7ff762a81965 17781->17782 17783 7ff762a81c23 17782->17783 17785 7ff762a873d0 83 API calls 17782->17785 17784 7ff762a8bb10 _log10_special 8 API calls 17783->17784 17786 7ff762a81c3e 17784->17786 17787 7ff762a819ab 17785->17787 17786->17496 17786->17497 17829 7ff762a819e3 17787->17829 18489 7ff762a8fc2c 17787->18489 17788 7ff762a8f5a4 74 API calls 17788->17783 17790 7ff762a819c5 17791 7ff762a819c9 17790->17791 17792 7ff762a819e8 17790->17792 17793 7ff762a95e48 _get_daylight 11 API calls 17791->17793 18493 7ff762a8f8f4 17792->18493 17795 7ff762a819ce 17793->17795 18496 7ff762a82020 17795->18496 17798 7ff762a81a06 17800 7ff762a95e48 _get_daylight 11 API calls 17798->17800 17799 7ff762a81a25 17802 7ff762a81a3c 17799->17802 17803 7ff762a81a5b 17799->17803 17801 7ff762a81a0b 17800->17801 17804 7ff762a82020 87 API calls 17801->17804 17805 7ff762a95e48 _get_daylight 11 API calls 17802->17805 17806 7ff762a81c60 49 API calls 17803->17806 17804->17829 17807 7ff762a81a41 17805->17807 17808 7ff762a81a72 17806->17808 17809 7ff762a82020 87 API calls 17807->17809 17810 7ff762a81c60 49 API calls 17808->17810 17809->17829 17811 7ff762a81abd 17810->17811 17812 7ff762a8fc2c 73 API calls 17811->17812 17813 7ff762a81ae1 17812->17813 17814 7ff762a81af6 17813->17814 17815 7ff762a81b15 17813->17815 17816 7ff762a95e48 _get_daylight 11 API calls 17814->17816 17817 7ff762a8f8f4 _fread_nolock 53 API calls 17815->17817 17818 7ff762a81afb 17816->17818 17819 7ff762a81b2a 17817->17819 17820 7ff762a82020 87 API calls 17818->17820 17821 7ff762a81b30 17819->17821 17822 7ff762a81b4f 17819->17822 17820->17829 17823 7ff762a95e48 _get_daylight 11 API calls 17821->17823 18511 7ff762a8f668 17822->18511 17825 7ff762a81b35 17823->17825 17827 7ff762a82020 87 API calls 17825->17827 17827->17829 17828 7ff762a81e50 81 API calls 17828->17829 17829->17788 17831 7ff762a87e7a 17830->17831 17832 7ff762a88950 2 API calls 17831->17832 17833 7ff762a87e99 GetEnvironmentVariableW 17832->17833 17834 7ff762a87eb6 ExpandEnvironmentStringsW 17833->17834 17835 7ff762a87f02 17833->17835 17834->17835 17836 7ff762a87ed8 17834->17836 17837 7ff762a8bb10 _log10_special 8 API calls 17835->17837 17838 7ff762a88a00 2 API calls 17836->17838 17839 7ff762a87f14 17837->17839 17840 7ff762a87eea 17838->17840 17839->17505 17841 7ff762a8bb10 _log10_special 8 API calls 17840->17841 17842 7ff762a87efa 17841->17842 17842->17505 17844 7ff762a885d5 17843->17844 18775 7ff762a87bb0 GetCurrentProcess OpenProcessToken 17844->18775 17847 7ff762a87bb0 7 API calls 17848 7ff762a88601 17847->17848 17849 7ff762a88634 17848->17849 17850 7ff762a8861a 17848->17850 17852 7ff762a81d50 48 API calls 17849->17852 17851 7ff762a81d50 48 API calls 17850->17851 17853 7ff762a88632 17851->17853 17854 7ff762a88647 LocalFree LocalFree 17852->17854 17853->17854 17855 7ff762a88663 17854->17855 17858 7ff762a8866f 17854->17858 18785 7ff762a82220 17855->18785 17857 7ff762a8bb10 _log10_special 8 API calls 17859 7ff762a83099 17857->17859 17858->17857 17859->17554 17860 7ff762a87ca0 17859->17860 17861 7ff762a87cb8 17860->17861 17862 7ff762a87cdc 17861->17862 17863 7ff762a87d3a GetTempPathW GetCurrentProcessId 17861->17863 17894 7ff762a88996 17893->17894 17895 7ff762a88972 MultiByteToWideChar 17893->17895 17896 7ff762a889b3 MultiByteToWideChar 17894->17896 17897 7ff762a889ac __std_exception_destroy 17894->17897 17895->17894 17895->17897 17896->17897 17897->17566 17899 7ff762a8278e memcpy_s 17898->17899 17919 7ff762a81c85 17918->17919 17920 7ff762a958c4 49 API calls 17919->17920 17921 7ff762a81ca8 17920->17921 17921->17500 17923 7ff762a88950 2 API calls 17922->17923 17924 7ff762a87ff4 17923->17924 17925 7ff762a99174 38 API calls 17924->17925 17926 7ff762a88006 __std_exception_destroy 17925->17926 17926->17513 17928 7ff762a839dc 17927->17928 17929 7ff762a88950 2 API calls 17928->17929 17930 7ff762a83a04 17929->17930 17931 7ff762a88950 2 API calls 17930->17931 17932 7ff762a83a17 17931->17932 19272 7ff762a96f54 17932->19272 17935 7ff762a8bb10 _log10_special 8 API calls 17936 7ff762a82ceb 17935->17936 17936->17503 17937 7ff762a873d0 17936->17937 17938 7ff762a873f4 17937->17938 17939 7ff762a8fc2c 73 API calls 17938->17939 17944 7ff762a874cb __std_exception_destroy 17938->17944 17940 7ff762a87410 17939->17940 17940->17944 19663 7ff762a98804 17940->19663 17942 7ff762a8fc2c 73 API calls 17945 7ff762a87425 17942->17945 17943 7ff762a8f8f4 _fread_nolock 53 API calls 17943->17945 17944->17507 17945->17942 17945->17943 17945->17944 17947 7ff762a8f5d4 17946->17947 19678 7ff762a8f380 17947->19678 17949 7ff762a8f5ed 17949->17503 17951 7ff762a8be10 17950->17951 17952 7ff762a81e74 GetCurrentProcessId 17951->17952 17953 7ff762a81c60 49 API calls 17952->17953 17954 7ff762a81ec5 17953->17954 17955 7ff762a958c4 49 API calls 17954->17955 17956 7ff762a81f02 17955->17956 17957 7ff762a81cc0 80 API calls 17956->17957 17958 7ff762a81f0c 17957->17958 17959 7ff762a8bb10 _log10_special 8 API calls 17958->17959 17960 7ff762a81f1c 17959->17960 17960->17620 17962 7ff762a88950 2 API calls 17961->17962 17963 7ff762a87f9c 17962->17963 17964 7ff762a88950 2 API calls 17963->17964 17965 7ff762a87fac 17964->17965 17966 7ff762a99174 38 API calls 17965->17966 17967 7ff762a87fba __std_exception_destroy 17966->17967 17967->17517 17969 7ff762a88510 GetConsoleWindow 17968->17969 17970 7ff762a83038 17969->17970 17971 7ff762a8852a GetCurrentProcessId GetWindowThreadProcessId 17969->17971 17970->17535 17971->17970 17972 7ff762a88549 17971->17972 17972->17970 17973 7ff762a88551 ShowWindow 17972->17973 17973->17970 17974 7ff762a88560 Sleep 17973->17974 17974->17970 17974->17973 17976 7ff762a81c60 49 API calls 17975->17976 17977 7ff762a8390d 17976->17977 17977->17549 17979 7ff762a81c60 49 API calls 17978->17979 17980 7ff762a83a70 17979->17980 17980->17568 17980->17980 19795 7ff762a857a0 18055->19795 18075 7ff762a962dc EnterCriticalSection 18068->18075 18077 7ff762a82a7c GetModuleFileNameW 18076->18077 18077->17761 18077->17762 18079 7ff762a8887f FindClose 18078->18079 18080 7ff762a88892 18078->18080 18079->18080 18081 7ff762a8bb10 _log10_special 8 API calls 18080->18081 18082 7ff762a82ada 18081->18082 18082->17767 18082->17768 18084 7ff762a8be10 18083->18084 18085 7ff762a82330 GetCurrentProcessId 18084->18085 18118 7ff762a81d50 18085->18118 18087 7ff762a8237b 18122 7ff762a95b18 18087->18122 18090 7ff762a81d50 48 API calls 18091 7ff762a823eb FormatMessageW 18090->18091 18093 7ff762a82436 18091->18093 18094 7ff762a82424 18091->18094 18140 7ff762a81e00 18093->18140 18095 7ff762a81d50 48 API calls 18094->18095 18095->18093 18098 7ff762a8bb10 _log10_special 8 API calls 18099 7ff762a82464 18098->18099 18099->17765 18101 7ff762a88900 GetFinalPathNameByHandleW CloseHandle 18100->18101 18102 7ff762a82af0 18100->18102 18101->18102 18102->17775 18102->17776 18104 7ff762a81f54 18103->18104 18105 7ff762a81d50 48 API calls 18104->18105 18106 7ff762a81fa5 18105->18106 18107 7ff762a95b18 48 API calls 18106->18107 18108 7ff762a81fe3 18107->18108 18109 7ff762a81e00 78 API calls 18108->18109 18110 7ff762a82001 18109->18110 18111 7ff762a8bb10 _log10_special 8 API calls 18110->18111 18112 7ff762a82011 18111->18112 18112->17765 18114 7ff762a88a2a WideCharToMultiByte 18113->18114 18115 7ff762a88a55 18113->18115 18114->18115 18117 7ff762a88a6b __std_exception_destroy 18114->18117 18116 7ff762a88a72 WideCharToMultiByte 18115->18116 18115->18117 18116->18117 18117->17772 18119 7ff762a81d75 18118->18119 18120 7ff762a95b18 48 API calls 18119->18120 18121 7ff762a81d98 18120->18121 18121->18087 18124 7ff762a95b72 18122->18124 18123 7ff762a95b97 18125 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18123->18125 18124->18123 18126 7ff762a95bd3 18124->18126 18128 7ff762a95bc1 18125->18128 18144 7ff762a92e08 18126->18144 18130 7ff762a8bb10 _log10_special 8 API calls 18128->18130 18129 7ff762a95cb4 18131 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18129->18131 18132 7ff762a823bb 18130->18132 18131->18128 18132->18090 18134 7ff762a95cda 18134->18129 18135 7ff762a95ce4 18134->18135 18138 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18135->18138 18136 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18136->18128 18137 7ff762a95c80 18137->18129 18139 7ff762a95c89 18137->18139 18138->18128 18139->18136 18141 7ff762a81e26 18140->18141 18474 7ff762a957a0 18141->18474 18143 7ff762a81e3c 18143->18098 18145 7ff762a92e46 18144->18145 18146 7ff762a92e36 18144->18146 18147 7ff762a92e4f 18145->18147 18148 7ff762a92e7d 18145->18148 18151 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18146->18151 18149 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18147->18149 18148->18146 18150 7ff762a92e75 18148->18150 18155 7ff762a94450 18148->18155 18188 7ff762a935a0 18148->18188 18225 7ff762a92390 18148->18225 18149->18150 18150->18129 18150->18134 18150->18137 18150->18139 18151->18150 18156 7ff762a94492 18155->18156 18157 7ff762a94503 18155->18157 18158 7ff762a94498 18156->18158 18159 7ff762a9452d 18156->18159 18160 7ff762a94508 18157->18160 18161 7ff762a9455c 18157->18161 18162 7ff762a944cc 18158->18162 18163 7ff762a9449d 18158->18163 18248 7ff762a9132c 18159->18248 18164 7ff762a9450a 18160->18164 18165 7ff762a9453d 18160->18165 18167 7ff762a94573 18161->18167 18169 7ff762a94566 18161->18169 18173 7ff762a9456b 18161->18173 18170 7ff762a944a3 18162->18170 18162->18173 18163->18167 18163->18170 18168 7ff762a944ac 18164->18168 18177 7ff762a94519 18164->18177 18255 7ff762a90f1c 18165->18255 18262 7ff762a95158 18167->18262 18184 7ff762a9459c 18168->18184 18228 7ff762a94c04 18168->18228 18169->18159 18169->18173 18170->18168 18176 7ff762a944de 18170->18176 18183 7ff762a944c7 18170->18183 18173->18184 18266 7ff762a9173c 18173->18266 18176->18184 18238 7ff762a94f40 18176->18238 18177->18159 18178 7ff762a9451e 18177->18178 18178->18184 18244 7ff762a95004 18178->18244 18180 7ff762a8bb10 _log10_special 8 API calls 18181 7ff762a94896 18180->18181 18181->18148 18183->18184 18187 7ff762a94788 18183->18187 18273 7ff762a95270 18183->18273 18184->18180 18187->18184 18279 7ff762a9fad0 18187->18279 18189 7ff762a935c4 18188->18189 18190 7ff762a935ae 18188->18190 18191 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18189->18191 18192 7ff762a93604 18189->18192 18190->18192 18193 7ff762a94492 18190->18193 18194 7ff762a94503 18190->18194 18191->18192 18192->18148 18195 7ff762a94498 18193->18195 18196 7ff762a9452d 18193->18196 18197 7ff762a94508 18194->18197 18198 7ff762a9455c 18194->18198 18199 7ff762a944cc 18195->18199 18200 7ff762a9449d 18195->18200 18203 7ff762a9132c 38 API calls 18196->18203 18201 7ff762a9450a 18197->18201 18202 7ff762a9453d 18197->18202 18204 7ff762a94573 18198->18204 18206 7ff762a94566 18198->18206 18210 7ff762a9456b 18198->18210 18207 7ff762a944a3 18199->18207 18199->18210 18200->18204 18200->18207 18205 7ff762a944ac 18201->18205 18214 7ff762a94519 18201->18214 18208 7ff762a90f1c 38 API calls 18202->18208 18221 7ff762a944c7 18203->18221 18211 7ff762a95158 45 API calls 18204->18211 18209 7ff762a94c04 47 API calls 18205->18209 18224 7ff762a9459c 18205->18224 18206->18196 18206->18210 18207->18205 18212 7ff762a944de 18207->18212 18207->18221 18208->18221 18209->18221 18213 7ff762a9173c 38 API calls 18210->18213 18210->18224 18211->18221 18215 7ff762a94f40 46 API calls 18212->18215 18212->18224 18213->18221 18214->18196 18216 7ff762a9451e 18214->18216 18215->18221 18219 7ff762a95004 37 API calls 18216->18219 18216->18224 18217 7ff762a8bb10 _log10_special 8 API calls 18218 7ff762a94896 18217->18218 18218->18148 18219->18221 18220 7ff762a95270 45 API calls 18223 7ff762a94788 18220->18223 18221->18220 18221->18223 18221->18224 18222 7ff762a9fad0 46 API calls 18222->18223 18223->18222 18223->18224 18224->18217 18457 7ff762a905a0 18225->18457 18229 7ff762a94c2a 18228->18229 18291 7ff762a90158 18229->18291 18234 7ff762a94d6f 18236 7ff762a95270 45 API calls 18234->18236 18237 7ff762a94dfd 18234->18237 18235 7ff762a95270 45 API calls 18235->18234 18236->18237 18237->18183 18241 7ff762a94f75 18238->18241 18239 7ff762a94fba 18239->18183 18240 7ff762a94f93 18243 7ff762a9fad0 46 API calls 18240->18243 18241->18239 18241->18240 18242 7ff762a95270 45 API calls 18241->18242 18242->18240 18243->18239 18246 7ff762a95025 18244->18246 18245 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18247 7ff762a95056 18245->18247 18246->18245 18246->18247 18247->18183 18250 7ff762a9135f 18248->18250 18249 7ff762a9138e 18254 7ff762a913cb 18249->18254 18427 7ff762a90200 18249->18427 18250->18249 18252 7ff762a9144b 18250->18252 18253 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18252->18253 18253->18254 18254->18183 18256 7ff762a90f4f 18255->18256 18257 7ff762a90f7e 18256->18257 18259 7ff762a9103b 18256->18259 18258 7ff762a90200 12 API calls 18257->18258 18261 7ff762a90fbb 18257->18261 18258->18261 18260 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18259->18260 18260->18261 18261->18183 18263 7ff762a9519b 18262->18263 18265 7ff762a9519f __crtLCMapStringW 18263->18265 18435 7ff762a951f4 18263->18435 18265->18183 18267 7ff762a9176f 18266->18267 18268 7ff762a9179e 18267->18268 18270 7ff762a9185b 18267->18270 18269 7ff762a90200 12 API calls 18268->18269 18272 7ff762a917db 18268->18272 18269->18272 18271 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18270->18271 18271->18272 18272->18183 18274 7ff762a95287 18273->18274 18439 7ff762a9ea80 18274->18439 18280 7ff762a9fb0f 18279->18280 18282 7ff762a9fb01 18279->18282 18280->18187 18281 7ff762a9fb2f 18284 7ff762a9fb40 18281->18284 18285 7ff762a9fb67 18281->18285 18282->18280 18282->18281 18283 7ff762a95270 45 API calls 18282->18283 18283->18281 18447 7ff762aa1310 18284->18447 18285->18280 18287 7ff762a9fbf2 18285->18287 18289 7ff762a9fb91 18285->18289 18288 7ff762aa0b10 _fread_nolock MultiByteToWideChar 18287->18288 18288->18280 18289->18280 18450 7ff762aa0b10 18289->18450 18292 7ff762a9017e 18291->18292 18293 7ff762a9018f 18291->18293 18299 7ff762a9f638 18292->18299 18293->18292 18294 7ff762a9e6c4 _fread_nolock 12 API calls 18293->18294 18295 7ff762a901bc 18294->18295 18296 7ff762a901d0 18295->18296 18297 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18295->18297 18298 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18296->18298 18297->18296 18298->18292 18300 7ff762a9f655 18299->18300 18301 7ff762a9f688 18299->18301 18302 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18300->18302 18301->18300 18303 7ff762a9f6ba 18301->18303 18311 7ff762a94d4d 18302->18311 18304 7ff762a9f7cd 18303->18304 18316 7ff762a9f702 18303->18316 18305 7ff762a9f8bf 18304->18305 18307 7ff762a9f885 18304->18307 18309 7ff762a9f854 18304->18309 18312 7ff762a9f817 18304->18312 18313 7ff762a9f80d 18304->18313 18354 7ff762a9eb24 18305->18354 18347 7ff762a9eebc 18307->18347 18340 7ff762a9f19c 18309->18340 18311->18234 18311->18235 18330 7ff762a9f3cc 18312->18330 18313->18307 18315 7ff762a9f812 18313->18315 18315->18309 18315->18312 18316->18311 18321 7ff762a9b3ac 18316->18321 18319 7ff762a9b844 _isindst 17 API calls 18320 7ff762a9f91c 18319->18320 18322 7ff762a9b3c3 18321->18322 18323 7ff762a9b3b9 18321->18323 18324 7ff762a95e48 _get_daylight 11 API calls 18322->18324 18323->18322 18325 7ff762a9b3de 18323->18325 18329 7ff762a9b3ca 18324->18329 18326 7ff762a9b3d6 18325->18326 18328 7ff762a95e48 _get_daylight 11 API calls 18325->18328 18326->18311 18326->18319 18327 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 18327->18326 18328->18329 18329->18327 18363 7ff762aa531c 18330->18363 18334 7ff762a9f474 18335 7ff762a9f478 18334->18335 18336 7ff762a9f4c9 18334->18336 18337 7ff762a9f494 18334->18337 18335->18311 18416 7ff762a9efb8 18336->18416 18412 7ff762a9f274 18337->18412 18341 7ff762aa531c 38 API calls 18340->18341 18342 7ff762a9f1e6 18341->18342 18343 7ff762aa4d64 37 API calls 18342->18343 18344 7ff762a9f236 18343->18344 18345 7ff762a9f23a 18344->18345 18346 7ff762a9f274 45 API calls 18344->18346 18345->18311 18346->18345 18348 7ff762aa531c 38 API calls 18347->18348 18349 7ff762a9ef07 18348->18349 18350 7ff762aa4d64 37 API calls 18349->18350 18351 7ff762a9ef5f 18350->18351 18352 7ff762a9ef63 18351->18352 18353 7ff762a9efb8 45 API calls 18351->18353 18352->18311 18353->18352 18355 7ff762a9eb69 18354->18355 18356 7ff762a9eb9c 18354->18356 18357 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18355->18357 18358 7ff762a9ebb4 18356->18358 18360 7ff762a9ec35 18356->18360 18362 7ff762a9eb95 memcpy_s 18357->18362 18359 7ff762a9eebc 46 API calls 18358->18359 18359->18362 18361 7ff762a95270 45 API calls 18360->18361 18360->18362 18361->18362 18362->18311 18364 7ff762aa536f fegetenv 18363->18364 18365 7ff762aa909c 37 API calls 18364->18365 18370 7ff762aa53c2 18365->18370 18366 7ff762aa53ef 18369 7ff762a9b3ac __std_exception_copy 37 API calls 18366->18369 18367 7ff762aa54b2 18368 7ff762aa909c 37 API calls 18367->18368 18371 7ff762aa54dc 18368->18371 18372 7ff762aa546d 18369->18372 18370->18367 18373 7ff762aa53dd 18370->18373 18374 7ff762aa548c 18370->18374 18375 7ff762aa909c 37 API calls 18371->18375 18376 7ff762aa6594 18372->18376 18382 7ff762aa5475 18372->18382 18373->18366 18373->18367 18377 7ff762a9b3ac __std_exception_copy 37 API calls 18374->18377 18378 7ff762aa54ed 18375->18378 18380 7ff762a9b844 _isindst 17 API calls 18376->18380 18377->18372 18379 7ff762aa9290 20 API calls 18378->18379 18389 7ff762aa5556 memcpy_s 18379->18389 18381 7ff762aa65a9 18380->18381 18383 7ff762a8bb10 _log10_special 8 API calls 18382->18383 18384 7ff762a9f419 18383->18384 18408 7ff762aa4d64 18384->18408 18385 7ff762aa58ff memcpy_s 18386 7ff762aa5597 memcpy_s 18402 7ff762aa5edb memcpy_s 18386->18402 18403 7ff762aa59f3 memcpy_s 18386->18403 18387 7ff762aa5c3f 18388 7ff762aa4e80 37 API calls 18387->18388 18394 7ff762aa6357 18388->18394 18389->18385 18389->18386 18392 7ff762a95e48 _get_daylight 11 API calls 18389->18392 18390 7ff762aa5beb 18390->18387 18391 7ff762aa65ac memcpy_s 37 API calls 18390->18391 18391->18387 18393 7ff762aa59d0 18392->18393 18395 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 18393->18395 18397 7ff762aa65ac memcpy_s 37 API calls 18394->18397 18401 7ff762aa63b2 18394->18401 18395->18386 18396 7ff762aa6538 18398 7ff762aa909c 37 API calls 18396->18398 18397->18401 18398->18382 18399 7ff762a95e48 11 API calls _get_daylight 18399->18402 18400 7ff762a95e48 11 API calls _get_daylight 18400->18403 18401->18396 18404 7ff762aa4e80 37 API calls 18401->18404 18407 7ff762aa65ac memcpy_s 37 API calls 18401->18407 18402->18387 18402->18390 18402->18399 18405 7ff762a9b824 37 API calls _invalid_parameter_noinfo 18402->18405 18403->18390 18403->18400 18406 7ff762a9b824 37 API calls _invalid_parameter_noinfo 18403->18406 18404->18401 18405->18402 18406->18403 18407->18401 18409 7ff762aa4d83 18408->18409 18410 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18409->18410 18411 7ff762aa4dae memcpy_s 18409->18411 18410->18411 18411->18334 18413 7ff762a9f2a0 memcpy_s 18412->18413 18414 7ff762a95270 45 API calls 18413->18414 18415 7ff762a9f35a memcpy_s 18413->18415 18414->18415 18415->18335 18417 7ff762a9eff3 18416->18417 18420 7ff762a9f040 memcpy_s 18416->18420 18418 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18417->18418 18419 7ff762a9f01f 18418->18419 18419->18335 18421 7ff762a9f0ab 18420->18421 18423 7ff762a95270 45 API calls 18420->18423 18422 7ff762a9b3ac __std_exception_copy 37 API calls 18421->18422 18426 7ff762a9f0ed memcpy_s 18422->18426 18423->18421 18424 7ff762a9b844 _isindst 17 API calls 18425 7ff762a9f198 18424->18425 18426->18424 18428 7ff762a90237 18427->18428 18434 7ff762a90226 18427->18434 18429 7ff762a9e6c4 _fread_nolock 12 API calls 18428->18429 18428->18434 18430 7ff762a90268 18429->18430 18431 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18430->18431 18433 7ff762a9027c 18430->18433 18431->18433 18432 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18432->18434 18433->18432 18434->18254 18436 7ff762a95212 18435->18436 18437 7ff762a9521a 18435->18437 18438 7ff762a95270 45 API calls 18436->18438 18437->18265 18438->18437 18440 7ff762a952af 18439->18440 18441 7ff762a9ea99 18439->18441 18443 7ff762a9eaec 18440->18443 18441->18440 18442 7ff762aa4574 45 API calls 18441->18442 18442->18440 18444 7ff762a9eb05 18443->18444 18446 7ff762a952bf 18443->18446 18445 7ff762aa38c0 45 API calls 18444->18445 18444->18446 18445->18446 18446->18187 18453 7ff762aa7ff8 18447->18453 18452 7ff762aa0b19 MultiByteToWideChar 18450->18452 18456 7ff762aa805c 18453->18456 18454 7ff762a8bb10 _log10_special 8 API calls 18455 7ff762aa132d 18454->18455 18455->18280 18456->18454 18458 7ff762a905d5 18457->18458 18459 7ff762a905e7 18457->18459 18460 7ff762a95e48 _get_daylight 11 API calls 18458->18460 18461 7ff762a905f5 18459->18461 18466 7ff762a90631 18459->18466 18462 7ff762a905da 18460->18462 18464 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18461->18464 18463 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 18462->18463 18470 7ff762a905e5 18463->18470 18464->18470 18465 7ff762a909ad 18468 7ff762a95e48 _get_daylight 11 API calls 18465->18468 18465->18470 18466->18465 18467 7ff762a95e48 _get_daylight 11 API calls 18466->18467 18469 7ff762a909a2 18467->18469 18471 7ff762a90c41 18468->18471 18473 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 18469->18473 18470->18148 18472 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 18471->18472 18472->18470 18473->18465 18475 7ff762a957ca 18474->18475 18476 7ff762a95802 18475->18476 18478 7ff762a95835 18475->18478 18477 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18476->18477 18480 7ff762a9582b 18477->18480 18481 7ff762a900d8 18478->18481 18480->18143 18488 7ff762a962dc EnterCriticalSection 18481->18488 18490 7ff762a8fc5c 18489->18490 18517 7ff762a8f9bc 18490->18517 18492 7ff762a8fc75 18492->17790 18529 7ff762a8f914 18493->18529 18497 7ff762a8be10 18496->18497 18498 7ff762a82040 GetCurrentProcessId 18497->18498 18499 7ff762a81c60 49 API calls 18498->18499 18500 7ff762a8208b 18499->18500 18543 7ff762a958c4 18500->18543 18504 7ff762a820ec 18505 7ff762a81c60 49 API calls 18504->18505 18506 7ff762a82106 18505->18506 18583 7ff762a81cc0 18506->18583 18509 7ff762a8bb10 _log10_special 8 API calls 18510 7ff762a82120 18509->18510 18510->17829 18512 7ff762a8f671 18511->18512 18513 7ff762a81b69 18511->18513 18514 7ff762a95e48 _get_daylight 11 API calls 18512->18514 18513->17828 18513->17829 18515 7ff762a8f676 18514->18515 18516 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 18515->18516 18516->18513 18518 7ff762a8fa26 18517->18518 18519 7ff762a8f9e6 18517->18519 18518->18519 18521 7ff762a8fa32 18518->18521 18520 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18519->18520 18527 7ff762a8fa0d 18520->18527 18528 7ff762a962dc EnterCriticalSection 18521->18528 18527->18492 18530 7ff762a81a00 18529->18530 18531 7ff762a8f93e 18529->18531 18530->17798 18530->17799 18531->18530 18532 7ff762a8f98a 18531->18532 18533 7ff762a8f94d memcpy_s 18531->18533 18542 7ff762a962dc EnterCriticalSection 18532->18542 18535 7ff762a95e48 _get_daylight 11 API calls 18533->18535 18537 7ff762a8f962 18535->18537 18539 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 18537->18539 18539->18530 18547 7ff762a9591e 18543->18547 18544 7ff762a95943 18545 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18544->18545 18560 7ff762a9596d 18545->18560 18546 7ff762a9597f 18594 7ff762a927b8 18546->18594 18547->18544 18547->18546 18549 7ff762a95a5c 18550 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18549->18550 18550->18560 18551 7ff762a8bb10 _log10_special 8 API calls 18553 7ff762a820ca 18551->18553 18561 7ff762a960a0 18553->18561 18554 7ff762a95a80 18554->18549 18557 7ff762a95a8a 18554->18557 18555 7ff762a95a31 18558 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18555->18558 18556 7ff762a95a28 18556->18549 18556->18555 18559 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18557->18559 18558->18560 18559->18560 18560->18551 18562 7ff762a9c1c8 _get_daylight 11 API calls 18561->18562 18563 7ff762a960b7 18562->18563 18564 7ff762a960bf 18563->18564 18565 7ff762a9fe04 _get_daylight 11 API calls 18563->18565 18567 7ff762a960f7 18563->18567 18564->18504 18566 7ff762a960ec 18565->18566 18568 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18566->18568 18567->18564 18732 7ff762a9fe8c 18567->18732 18568->18567 18571 7ff762a9b844 _isindst 17 API calls 18572 7ff762a9613c 18571->18572 18573 7ff762a9fe04 _get_daylight 11 API calls 18572->18573 18574 7ff762a96189 18573->18574 18575 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18574->18575 18576 7ff762a96197 18575->18576 18577 7ff762a9fe04 _get_daylight 11 API calls 18576->18577 18581 7ff762a961c1 18576->18581 18578 7ff762a961b3 18577->18578 18580 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 18578->18580 18580->18581 18582 7ff762a961ca 18581->18582 18741 7ff762aa02e0 18581->18741 18582->18504 18584 7ff762a81ccc 18583->18584 18585 7ff762a88950 2 API calls 18584->18585 18586 7ff762a81cf4 18585->18586 18587 7ff762a81cfe 18586->18587 18588 7ff762a81d19 18586->18588 18590 7ff762a81e00 78 API calls 18587->18590 18756 7ff762a81db0 18588->18756 18591 7ff762a81d17 18590->18591 18592 7ff762a8bb10 _log10_special 8 API calls 18591->18592 18593 7ff762a81d40 18592->18593 18593->18509 18595 7ff762a927f6 18594->18595 18596 7ff762a927e6 18594->18596 18597 7ff762a927ff 18595->18597 18604 7ff762a9282d 18595->18604 18600 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18596->18600 18598 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18597->18598 18599 7ff762a92825 18598->18599 18599->18549 18599->18554 18599->18555 18599->18556 18600->18599 18601 7ff762a95270 45 API calls 18601->18604 18603 7ff762a92adc 18606 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18603->18606 18604->18596 18604->18599 18604->18601 18604->18603 18608 7ff762a93b88 18604->18608 18634 7ff762a93268 18604->18634 18664 7ff762a92300 18604->18664 18606->18596 18609 7ff762a93bca 18608->18609 18610 7ff762a93c3d 18608->18610 18611 7ff762a93bd0 18609->18611 18612 7ff762a93c67 18609->18612 18613 7ff762a93c42 18610->18613 18614 7ff762a93c97 18610->18614 18621 7ff762a93bd5 18611->18621 18626 7ff762a93ca6 18611->18626 18681 7ff762a91128 18612->18681 18615 7ff762a93c44 18613->18615 18616 7ff762a93c77 18613->18616 18614->18612 18614->18626 18632 7ff762a93c00 18614->18632 18618 7ff762a93be5 18615->18618 18624 7ff762a93c53 18615->18624 18688 7ff762a90d18 18616->18688 18625 7ff762a93cd5 18618->18625 18667 7ff762a949b0 18618->18667 18621->18618 18622 7ff762a93c18 18621->18622 18621->18632 18622->18625 18677 7ff762a94e6c 18622->18677 18624->18612 18628 7ff762a93c58 18624->18628 18629 7ff762a8bb10 _log10_special 8 API calls 18625->18629 18626->18625 18695 7ff762a91538 18626->18695 18628->18625 18631 7ff762a95004 37 API calls 18628->18631 18630 7ff762a93f6b 18629->18630 18630->18604 18631->18632 18632->18625 18702 7ff762a9f920 18632->18702 18635 7ff762a93273 18634->18635 18636 7ff762a93289 18634->18636 18637 7ff762a932c7 18635->18637 18639 7ff762a93bca 18635->18639 18640 7ff762a93c3d 18635->18640 18636->18637 18638 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18636->18638 18637->18604 18638->18637 18641 7ff762a93bd0 18639->18641 18642 7ff762a93c67 18639->18642 18643 7ff762a93c42 18640->18643 18648 7ff762a93c97 18640->18648 18649 7ff762a93ca6 18641->18649 18650 7ff762a93bd5 18641->18650 18644 7ff762a91128 38 API calls 18642->18644 18645 7ff762a93c77 18643->18645 18647 7ff762a93c44 18643->18647 18662 7ff762a93c00 18644->18662 18651 7ff762a90d18 38 API calls 18645->18651 18646 7ff762a93be5 18652 7ff762a949b0 47 API calls 18646->18652 18663 7ff762a93cd5 18646->18663 18647->18646 18655 7ff762a93c53 18647->18655 18648->18642 18648->18649 18648->18662 18654 7ff762a91538 38 API calls 18649->18654 18649->18663 18650->18646 18653 7ff762a93c18 18650->18653 18650->18662 18651->18662 18652->18662 18656 7ff762a94e6c 47 API calls 18653->18656 18653->18663 18654->18662 18655->18642 18657 7ff762a93c58 18655->18657 18656->18662 18659 7ff762a95004 37 API calls 18657->18659 18657->18663 18658 7ff762a8bb10 _log10_special 8 API calls 18660 7ff762a93f6b 18658->18660 18659->18662 18660->18604 18661 7ff762a9f920 47 API calls 18661->18662 18662->18661 18662->18663 18663->18658 18715 7ff762a902ec 18664->18715 18669 7ff762a949d2 18667->18669 18668 7ff762a90158 12 API calls 18670 7ff762a94a1a 18668->18670 18669->18668 18671 7ff762a9f638 46 API calls 18670->18671 18672 7ff762a94aed 18671->18672 18673 7ff762a95270 45 API calls 18672->18673 18674 7ff762a94b0f 18672->18674 18673->18674 18675 7ff762a95270 45 API calls 18674->18675 18676 7ff762a94b98 18674->18676 18675->18676 18676->18632 18678 7ff762a94e84 18677->18678 18680 7ff762a94eec 18677->18680 18679 7ff762a9f920 47 API calls 18678->18679 18678->18680 18679->18680 18680->18632 18683 7ff762a9115b 18681->18683 18682 7ff762a9118a 18684 7ff762a90158 12 API calls 18682->18684 18687 7ff762a911c7 18682->18687 18683->18682 18685 7ff762a91247 18683->18685 18684->18687 18686 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18685->18686 18686->18687 18687->18632 18689 7ff762a90d4b 18688->18689 18690 7ff762a90d7a 18689->18690 18692 7ff762a90e37 18689->18692 18691 7ff762a90158 12 API calls 18690->18691 18694 7ff762a90db7 18690->18694 18691->18694 18693 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18692->18693 18693->18694 18694->18632 18696 7ff762a9156b 18695->18696 18697 7ff762a9159a 18696->18697 18699 7ff762a91657 18696->18699 18698 7ff762a90158 12 API calls 18697->18698 18701 7ff762a915d7 18697->18701 18698->18701 18700 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18699->18700 18700->18701 18701->18632 18703 7ff762a9f948 18702->18703 18704 7ff762a9f98d 18703->18704 18705 7ff762a95270 45 API calls 18703->18705 18707 7ff762a9f94d memcpy_s 18703->18707 18711 7ff762a9f976 memcpy_s 18703->18711 18704->18707 18704->18711 18712 7ff762aa1a58 18704->18712 18705->18704 18706 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18706->18707 18707->18632 18711->18706 18711->18707 18713 7ff762aa1a7c WideCharToMultiByte 18712->18713 18716 7ff762a90319 18715->18716 18717 7ff762a9032b 18715->18717 18718 7ff762a95e48 _get_daylight 11 API calls 18716->18718 18719 7ff762a90338 18717->18719 18723 7ff762a90375 18717->18723 18720 7ff762a9031e 18718->18720 18722 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18719->18722 18721 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 18720->18721 18727 7ff762a90329 18721->18727 18722->18727 18724 7ff762a9041e 18723->18724 18725 7ff762a95e48 _get_daylight 11 API calls 18723->18725 18726 7ff762a95e48 _get_daylight 11 API calls 18724->18726 18724->18727 18728 7ff762a90413 18725->18728 18729 7ff762a904c8 18726->18729 18727->18604 18730 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 18728->18730 18731 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 18729->18731 18730->18724 18731->18727 18736 7ff762a9fea9 18732->18736 18733 7ff762a9feae 18734 7ff762a9611d 18733->18734 18735 7ff762a95e48 _get_daylight 11 API calls 18733->18735 18734->18564 18734->18571 18737 7ff762a9feb8 18735->18737 18736->18733 18736->18734 18739 7ff762a9fef8 18736->18739 18738 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 18737->18738 18738->18734 18739->18734 18740 7ff762a95e48 _get_daylight 11 API calls 18739->18740 18740->18737 18746 7ff762a9ff7c 18741->18746 18744 7ff762aa0335 InitializeCriticalSectionAndSpinCount 18745 7ff762aa031b 18744->18745 18745->18581 18747 7ff762a9ffd9 18746->18747 18749 7ff762a9ffd4 __vcrt_InitializeCriticalSectionEx 18746->18749 18747->18744 18747->18745 18748 7ff762aa0009 LoadLibraryExW 18751 7ff762aa00de 18748->18751 18752 7ff762aa002e GetLastError 18748->18752 18749->18747 18749->18748 18750 7ff762aa00fe GetProcAddress 18749->18750 18755 7ff762aa0068 LoadLibraryExW 18749->18755 18750->18747 18754 7ff762aa010f 18750->18754 18751->18750 18752->18749 18754->18747 18755->18749 18755->18751 18757 7ff762a81dd6 18756->18757 18760 7ff762a9567c 18757->18760 18761 7ff762a956a6 18760->18761 18762 7ff762a956de 18761->18762 18764 7ff762a95711 18761->18764 18763 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 18762->18763 18766 7ff762a95707 18763->18766 18767 7ff762a90118 18764->18767 18774 7ff762a962dc EnterCriticalSection 18767->18774 18776 7ff762a87c73 __std_exception_destroy 18775->18776 18777 7ff762a87bf1 GetTokenInformation 18775->18777 18780 7ff762a87c8c 18776->18780 18781 7ff762a87c86 CloseHandle 18776->18781 18778 7ff762a87c1d 18777->18778 18779 7ff762a87c12 GetLastError 18777->18779 18778->18776 18782 7ff762a87c39 GetTokenInformation 18778->18782 18779->18776 18779->18778 18780->17847 18781->18780 18782->18776 18783 7ff762a87c5c 18782->18783 18783->18776 18784 7ff762a87c66 ConvertSidToStringSidW 18783->18784 18784->18776 18786 7ff762a8be10 18785->18786 18787 7ff762a82244 GetCurrentProcessId 18786->18787 18788 7ff762a81d50 48 API calls 18787->18788 18789 7ff762a82295 18788->18789 19273 7ff762a96e88 19272->19273 19274 7ff762a96eae 19273->19274 19277 7ff762a96ee1 19273->19277 19275 7ff762a95e48 _get_daylight 11 API calls 19274->19275 19276 7ff762a96eb3 19275->19276 19278 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 19276->19278 19279 7ff762a96ef4 19277->19279 19280 7ff762a96ee7 19277->19280 19290 7ff762a83a26 19278->19290 19291 7ff762a9bb30 19279->19291 19281 7ff762a95e48 _get_daylight 11 API calls 19280->19281 19281->19290 19290->17935 19304 7ff762aa1548 EnterCriticalSection 19291->19304 19664 7ff762a98834 19663->19664 19667 7ff762a98310 19664->19667 19666 7ff762a9884d 19666->17945 19668 7ff762a9835a 19667->19668 19669 7ff762a9832b 19667->19669 19677 7ff762a962dc EnterCriticalSection 19668->19677 19670 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 19669->19670 19672 7ff762a9834b 19670->19672 19672->19666 19679 7ff762a8f3c9 19678->19679 19680 7ff762a8f39b 19678->19680 19687 7ff762a8f3bb 19679->19687 19688 7ff762a962dc EnterCriticalSection 19679->19688 19681 7ff762a9b758 _invalid_parameter_noinfo 37 API calls 19680->19681 19681->19687 19687->17949 21651 7ff762aac06e 21652 7ff762aac087 21651->21652 21653 7ff762aac07d 21651->21653 21655 7ff762aa15a8 LeaveCriticalSection 21653->21655 21656 7ff762a8a26d 21658 7ff762a8a272 21656->21658 21657 7ff762a8b350 12 API calls 21662 7ff762a8a156 21657->21662 21658->21658 21663 7ff762a8a3da 21658->21663 21665 7ff762a89f43 21658->21665 21666 7ff762a8b470 21658->21666 21660 7ff762a8b470 12 API calls 21661 7ff762a8a6e8 21660->21661 21664 7ff762a8b470 12 API calls 21661->21664 21663->21660 21663->21665 21664->21665 21665->21657 21665->21662 21673 7ff762a8b4c0 21666->21673 21669 7ff762a8b579 21670 7ff762a8bb10 _log10_special 8 API calls 21669->21670 21671 7ff762a8b7b8 21670->21671 21671->21663 21672 7ff762a8ba07 21674 7ff762a8bf74 21672->21674 21673->21669 21673->21672 21677 7ff762a8bf88 IsProcessorFeaturePresent 21674->21677 21678 7ff762a8bf9f 21677->21678 21683 7ff762a8c028 RtlCaptureContext RtlLookupFunctionEntry 21678->21683 21684 7ff762a8c058 RtlVirtualUnwind 21683->21684 21685 7ff762a8bfb3 21683->21685 21684->21685 21686 7ff762a8be60 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 21685->21686 16998 7ff762a965e4 16999 7ff762a9661b 16998->16999 17000 7ff762a965fe 16998->17000 16999->17000 17001 7ff762a9662e CreateFileW 16999->17001 17049 7ff762a95e28 17000->17049 17004 7ff762a96662 17001->17004 17005 7ff762a96698 17001->17005 17023 7ff762a96738 GetFileType 17004->17023 17055 7ff762a96bc0 17005->17055 17006 7ff762a95e48 _get_daylight 11 API calls 17009 7ff762a9660b 17006->17009 17052 7ff762a9b824 17009->17052 17013 7ff762a96677 CloseHandle 17019 7ff762a96616 17013->17019 17014 7ff762a9668d CloseHandle 17014->17019 17015 7ff762a966a1 17076 7ff762a95dbc 17015->17076 17016 7ff762a966cc 17081 7ff762a96980 17016->17081 17022 7ff762a966ab 17022->17019 17024 7ff762a96843 17023->17024 17025 7ff762a96786 17023->17025 17027 7ff762a9684b 17024->17027 17028 7ff762a9686d 17024->17028 17026 7ff762a967b2 GetFileInformationByHandle 17025->17026 17030 7ff762a96abc 21 API calls 17025->17030 17031 7ff762a967db 17026->17031 17032 7ff762a9685e GetLastError 17026->17032 17027->17032 17033 7ff762a9684f 17027->17033 17029 7ff762a96890 PeekNamedPipe 17028->17029 17047 7ff762a9682e 17028->17047 17029->17047 17038 7ff762a967a0 17030->17038 17035 7ff762a96980 51 API calls 17031->17035 17034 7ff762a95dbc _fread_nolock 11 API calls 17032->17034 17036 7ff762a95e48 _get_daylight 11 API calls 17033->17036 17034->17047 17039 7ff762a967e6 17035->17039 17036->17047 17038->17026 17038->17047 17098 7ff762a968e0 17039->17098 17043 7ff762a968e0 10 API calls 17044 7ff762a96805 17043->17044 17045 7ff762a968e0 10 API calls 17044->17045 17046 7ff762a96816 17045->17046 17046->17047 17048 7ff762a95e48 _get_daylight 11 API calls 17046->17048 17105 7ff762a8bb10 17047->17105 17048->17047 17050 7ff762a9c1c8 _get_daylight 11 API calls 17049->17050 17051 7ff762a95e31 17050->17051 17051->17006 17119 7ff762a9b6bc 17052->17119 17054 7ff762a9b83d 17054->17019 17056 7ff762a96bf6 17055->17056 17057 7ff762a95e48 _get_daylight 11 API calls 17056->17057 17071 7ff762a96c8e __std_exception_destroy 17056->17071 17059 7ff762a96c08 17057->17059 17058 7ff762a8bb10 _log10_special 8 API calls 17060 7ff762a9669d 17058->17060 17061 7ff762a95e48 _get_daylight 11 API calls 17059->17061 17060->17015 17060->17016 17062 7ff762a96c10 17061->17062 17171 7ff762a98d44 17062->17171 17064 7ff762a96c25 17065 7ff762a96c37 17064->17065 17066 7ff762a96c2d 17064->17066 17068 7ff762a95e48 _get_daylight 11 API calls 17065->17068 17067 7ff762a95e48 _get_daylight 11 API calls 17066->17067 17069 7ff762a96c32 17067->17069 17070 7ff762a96c3c 17068->17070 17069->17071 17075 7ff762a96c80 GetDriveTypeW 17069->17075 17070->17071 17072 7ff762a95e48 _get_daylight 11 API calls 17070->17072 17071->17058 17073 7ff762a96c46 17072->17073 17074 7ff762a98d44 45 API calls 17073->17074 17074->17069 17075->17071 17077 7ff762a9c1c8 _get_daylight 11 API calls 17076->17077 17078 7ff762a95dc9 Concurrency::details::SchedulerProxy::DeleteThis 17077->17078 17079 7ff762a9c1c8 _get_daylight 11 API calls 17078->17079 17080 7ff762a95deb 17079->17080 17080->17022 17083 7ff762a969a8 17081->17083 17082 7ff762a966d9 17091 7ff762a96abc 17082->17091 17083->17082 17265 7ff762aa0994 17083->17265 17085 7ff762a96a3c 17085->17082 17086 7ff762aa0994 51 API calls 17085->17086 17087 7ff762a96a4f 17086->17087 17087->17082 17088 7ff762aa0994 51 API calls 17087->17088 17089 7ff762a96a62 17088->17089 17089->17082 17090 7ff762aa0994 51 API calls 17089->17090 17090->17082 17092 7ff762a96ad6 17091->17092 17093 7ff762a96b0d 17092->17093 17095 7ff762a96ae6 17092->17095 17094 7ff762aa0828 21 API calls 17093->17094 17096 7ff762a96af6 17094->17096 17095->17096 17097 7ff762a95dbc _fread_nolock 11 API calls 17095->17097 17096->17022 17097->17096 17099 7ff762a96909 FileTimeToSystemTime 17098->17099 17100 7ff762a968fc 17098->17100 17101 7ff762a9691d SystemTimeToTzSpecificLocalTime 17099->17101 17102 7ff762a96904 17099->17102 17100->17099 17100->17102 17101->17102 17103 7ff762a8bb10 _log10_special 8 API calls 17102->17103 17104 7ff762a967f5 17103->17104 17104->17043 17108 7ff762a8bb19 17105->17108 17106 7ff762a8bea0 IsProcessorFeaturePresent 17109 7ff762a8beb8 17106->17109 17107 7ff762a8bb24 17107->17013 17107->17014 17108->17106 17108->17107 17114 7ff762a8c098 RtlCaptureContext 17109->17114 17115 7ff762a8c0b2 RtlLookupFunctionEntry 17114->17115 17116 7ff762a8becb 17115->17116 17117 7ff762a8c0c8 RtlVirtualUnwind 17115->17117 17118 7ff762a8be60 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 17116->17118 17117->17115 17117->17116 17120 7ff762a9b6e7 17119->17120 17123 7ff762a9b758 17120->17123 17122 7ff762a9b70e 17122->17054 17133 7ff762a9b4a0 17123->17133 17127 7ff762a9b793 17127->17122 17134 7ff762a9b4f7 17133->17134 17135 7ff762a9b4bc GetLastError 17133->17135 17134->17127 17139 7ff762a9b50c 17134->17139 17136 7ff762a9b4cc 17135->17136 17146 7ff762a9c290 17136->17146 17140 7ff762a9b540 17139->17140 17141 7ff762a9b528 GetLastError SetLastError 17139->17141 17140->17127 17142 7ff762a9b844 IsProcessorFeaturePresent 17140->17142 17141->17140 17143 7ff762a9b857 17142->17143 17163 7ff762a9b558 17143->17163 17147 7ff762a9c2af FlsGetValue 17146->17147 17148 7ff762a9c2ca FlsSetValue 17146->17148 17150 7ff762a9c2c4 17147->17150 17151 7ff762a9b4e7 SetLastError 17147->17151 17149 7ff762a9c2d7 17148->17149 17148->17151 17152 7ff762a9fe04 _get_daylight 11 API calls 17149->17152 17150->17148 17151->17134 17153 7ff762a9c2e6 17152->17153 17154 7ff762a9c304 FlsSetValue 17153->17154 17155 7ff762a9c2f4 FlsSetValue 17153->17155 17157 7ff762a9c310 FlsSetValue 17154->17157 17158 7ff762a9c322 17154->17158 17156 7ff762a9c2fd 17155->17156 17159 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17156->17159 17157->17156 17160 7ff762a9bdfc _get_daylight 11 API calls 17158->17160 17159->17151 17161 7ff762a9c32a 17160->17161 17162 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17161->17162 17162->17151 17164 7ff762a9b592 memcpy_s __FrameHandler3::FrameUnwindToEmptyState 17163->17164 17165 7ff762a9b5ba RtlCaptureContext RtlLookupFunctionEntry 17164->17165 17166 7ff762a9b5f4 RtlVirtualUnwind 17165->17166 17167 7ff762a9b62a IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 17165->17167 17166->17167 17168 7ff762a9b67c __FrameHandler3::FrameUnwindToEmptyState 17167->17168 17169 7ff762a8bb10 _log10_special 8 API calls 17168->17169 17170 7ff762a9b69b GetCurrentProcess TerminateProcess 17169->17170 17172 7ff762a98d60 17171->17172 17173 7ff762a98dce 17171->17173 17172->17173 17175 7ff762a98d65 17172->17175 17208 7ff762aa1a30 17173->17208 17176 7ff762a98d9a 17175->17176 17177 7ff762a98d7d 17175->17177 17191 7ff762a98b88 GetFullPathNameW 17176->17191 17183 7ff762a98b14 GetFullPathNameW 17177->17183 17182 7ff762a98d92 __std_exception_destroy 17182->17064 17184 7ff762a98b50 17183->17184 17185 7ff762a98b3a GetLastError 17183->17185 17188 7ff762a98b4c 17184->17188 17189 7ff762a95e48 _get_daylight 11 API calls 17184->17189 17186 7ff762a95dbc _fread_nolock 11 API calls 17185->17186 17187 7ff762a98b47 17186->17187 17190 7ff762a95e48 _get_daylight 11 API calls 17187->17190 17188->17182 17189->17188 17190->17188 17192 7ff762a98bbb GetLastError 17191->17192 17197 7ff762a98bd1 __std_exception_destroy 17191->17197 17193 7ff762a95dbc _fread_nolock 11 API calls 17192->17193 17194 7ff762a98bc8 17193->17194 17195 7ff762a95e48 _get_daylight 11 API calls 17194->17195 17196 7ff762a98bcd 17195->17196 17199 7ff762a98c60 17196->17199 17197->17196 17198 7ff762a98c2b GetFullPathNameW 17197->17198 17198->17192 17198->17196 17200 7ff762a98cd4 memcpy_s 17199->17200 17201 7ff762a98c89 memcpy_s 17199->17201 17200->17182 17201->17200 17202 7ff762a98cbd 17201->17202 17204 7ff762a98cf6 17201->17204 17203 7ff762a95e48 _get_daylight 11 API calls 17202->17203 17207 7ff762a98cc2 17203->17207 17204->17200 17206 7ff762a95e48 _get_daylight 11 API calls 17204->17206 17205 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 17205->17200 17206->17207 17207->17205 17211 7ff762aa1840 17208->17211 17212 7ff762aa1882 17211->17212 17213 7ff762aa186b 17211->17213 17215 7ff762aa1886 17212->17215 17216 7ff762aa18a7 17212->17216 17214 7ff762a95e48 _get_daylight 11 API calls 17213->17214 17218 7ff762aa1870 17214->17218 17237 7ff762aa19ac 17215->17237 17249 7ff762aa0828 17216->17249 17222 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 17218->17222 17220 7ff762aa18ac 17226 7ff762aa1951 17220->17226 17231 7ff762aa18d3 17220->17231 17236 7ff762aa187b __std_exception_destroy 17222->17236 17223 7ff762aa188f 17224 7ff762a95e28 _fread_nolock 11 API calls 17223->17224 17225 7ff762aa1894 17224->17225 17228 7ff762a95e48 _get_daylight 11 API calls 17225->17228 17226->17213 17229 7ff762aa1959 17226->17229 17227 7ff762a8bb10 _log10_special 8 API calls 17230 7ff762aa19a1 17227->17230 17228->17218 17232 7ff762a98b14 13 API calls 17229->17232 17230->17182 17233 7ff762a98b88 14 API calls 17231->17233 17232->17236 17234 7ff762aa1917 17233->17234 17235 7ff762a98c60 37 API calls 17234->17235 17234->17236 17235->17236 17236->17227 17238 7ff762aa19f6 17237->17238 17239 7ff762aa19c6 17237->17239 17241 7ff762aa1a01 GetDriveTypeW 17238->17241 17242 7ff762aa19e1 17238->17242 17240 7ff762a95e28 _fread_nolock 11 API calls 17239->17240 17243 7ff762aa19cb 17240->17243 17241->17242 17245 7ff762a8bb10 _log10_special 8 API calls 17242->17245 17244 7ff762a95e48 _get_daylight 11 API calls 17243->17244 17246 7ff762aa19d6 17244->17246 17247 7ff762aa188b 17245->17247 17248 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 17246->17248 17247->17220 17247->17223 17248->17242 17263 7ff762aab740 17249->17263 17251 7ff762aa085e GetCurrentDirectoryW 17252 7ff762aa0875 17251->17252 17253 7ff762aa089c 17251->17253 17256 7ff762a8bb10 _log10_special 8 API calls 17252->17256 17254 7ff762a9fe04 _get_daylight 11 API calls 17253->17254 17255 7ff762aa08ab 17254->17255 17257 7ff762aa08c4 17255->17257 17258 7ff762aa08b5 GetCurrentDirectoryW 17255->17258 17259 7ff762aa0909 17256->17259 17261 7ff762a95e48 _get_daylight 11 API calls 17257->17261 17258->17257 17260 7ff762aa08c9 17258->17260 17259->17220 17262 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17260->17262 17261->17260 17262->17252 17264 7ff762aab730 17263->17264 17264->17251 17264->17264 17266 7ff762aa09a1 17265->17266 17267 7ff762aa09c5 17265->17267 17266->17267 17268 7ff762aa09a6 17266->17268 17269 7ff762aa09ff 17267->17269 17272 7ff762aa0a1e 17267->17272 17270 7ff762a95e48 _get_daylight 11 API calls 17268->17270 17271 7ff762a95e48 _get_daylight 11 API calls 17269->17271 17273 7ff762aa09ab 17270->17273 17274 7ff762aa0a04 17271->17274 17282 7ff762a95e8c 17272->17282 17276 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 17273->17276 17277 7ff762a9b824 _invalid_parameter_noinfo 37 API calls 17274->17277 17278 7ff762aa09b6 17276->17278 17279 7ff762aa0a0f 17277->17279 17278->17085 17279->17085 17280 7ff762aa0a2b 17280->17279 17281 7ff762aa174c 51 API calls 17280->17281 17281->17280 17283 7ff762a95eb0 17282->17283 17284 7ff762a95eab 17282->17284 17283->17284 17290 7ff762a9c050 GetLastError 17283->17290 17284->17280 17291 7ff762a9c091 FlsSetValue 17290->17291 17292 7ff762a9c074 FlsGetValue 17290->17292 17294 7ff762a9c0a3 17291->17294 17310 7ff762a9c081 17291->17310 17293 7ff762a9c08b 17292->17293 17292->17310 17293->17291 17296 7ff762a9fe04 _get_daylight 11 API calls 17294->17296 17295 7ff762a9c0fd SetLastError 17297 7ff762a95ecb 17295->17297 17298 7ff762a9c11d 17295->17298 17299 7ff762a9c0b2 17296->17299 17312 7ff762a9ea4c 17297->17312 17320 7ff762a9b40c 17298->17320 17301 7ff762a9c0d0 FlsSetValue 17299->17301 17302 7ff762a9c0c0 FlsSetValue 17299->17302 17303 7ff762a9c0dc FlsSetValue 17301->17303 17304 7ff762a9c0ee 17301->17304 17306 7ff762a9c0c9 17302->17306 17303->17306 17307 7ff762a9bdfc _get_daylight 11 API calls 17304->17307 17308 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17306->17308 17309 7ff762a9c0f6 17307->17309 17308->17310 17311 7ff762a9b464 Concurrency::details::SchedulerProxy::DeleteThis 11 API calls 17309->17311 17310->17295 17311->17295 17313 7ff762a95eee 17312->17313 17314 7ff762a9ea61 17312->17314 17316 7ff762a9eab8 17313->17316 17314->17313 17364 7ff762aa4574 17314->17364 17317 7ff762a9eae0 17316->17317 17318 7ff762a9eacd 17316->17318 17317->17284 17318->17317 17377 7ff762aa38c0 17318->17377 17329 7ff762aa48c0 17320->17329 17355 7ff762aa4878 17329->17355 17360 7ff762aa1548 EnterCriticalSection 17355->17360 17365 7ff762a9c050 __FrameHandler3::FrameUnwindToEmptyState 45 API calls 17364->17365 17366 7ff762aa4583 17365->17366 17367 7ff762aa45ce 17366->17367 17376 7ff762aa1548 EnterCriticalSection 17366->17376 17367->17313 17378 7ff762a9c050 __FrameHandler3::FrameUnwindToEmptyState 45 API calls 17377->17378 17379 7ff762aa38c9 17378->17379 20212 7ff762aabfd9 20215 7ff762a962e8 LeaveCriticalSection 20212->20215 20084 7ff762a8addc 20086 7ff762a8a0da 20084->20086 20085 7ff762a8a156 20086->20085 20088 7ff762a8b350 20086->20088 20089 7ff762a8b373 20088->20089 20090 7ff762a8b391 memcpy_s 20088->20090 20091 7ff762a9e6c4 12 API calls 20089->20091 20090->20085 20091->20090

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 0 7ff762a88020-7ff762a88166 call 7ff762a8be10 call 7ff762a88950 SetConsoleCtrlHandler GetStartupInfoW call 7ff762a96260 call 7ff762a9b384 call 7ff762a99658 call 7ff762a96260 call 7ff762a9b384 call 7ff762a99658 call 7ff762a96260 call 7ff762a9b384 call 7ff762a99658 GetCommandLineW CreateProcessW 23 7ff762a88168-7ff762a88188 GetLastError call 7ff762a82310 0->23 24 7ff762a8818d-7ff762a881c9 RegisterClassW 0->24 31 7ff762a88479-7ff762a8849f call 7ff762a8bb10 23->31 26 7ff762a881d1-7ff762a88225 CreateWindowExW 24->26 27 7ff762a881cb GetLastError 24->27 29 7ff762a8822f-7ff762a88234 ShowWindow 26->29 30 7ff762a88227-7ff762a8822d GetLastError 26->30 27->26 32 7ff762a8823a-7ff762a8824a WaitForSingleObject 29->32 30->32 34 7ff762a882c8-7ff762a882cf 32->34 35 7ff762a8824c 32->35 36 7ff762a882d1-7ff762a882e1 WaitForSingleObject 34->36 37 7ff762a88312-7ff762a88319 34->37 39 7ff762a88250-7ff762a88253 35->39 40 7ff762a882e7-7ff762a882f7 TerminateProcess 36->40 41 7ff762a88438-7ff762a88442 36->41 42 7ff762a8831f-7ff762a88335 QueryPerformanceFrequency QueryPerformanceCounter 37->42 43 7ff762a88400-7ff762a88419 GetMessageW 37->43 44 7ff762a88255 GetLastError 39->44 45 7ff762a8825b-7ff762a88262 39->45 48 7ff762a882ff-7ff762a8830d WaitForSingleObject 40->48 49 7ff762a882f9 GetLastError 40->49 46 7ff762a88451-7ff762a88475 GetExitCodeProcess CloseHandle * 2 41->46 47 7ff762a88444-7ff762a8844a DestroyWindow 41->47 50 7ff762a88340-7ff762a88378 MsgWaitForMultipleObjects PeekMessageW 42->50 52 7ff762a8842f-7ff762a88436 43->52 53 7ff762a8841b-7ff762a88429 TranslateMessage DispatchMessageW 43->53 44->45 45->36 51 7ff762a88264-7ff762a88281 PeekMessageW 45->51 46->31 47->46 48->41 49->48 54 7ff762a883b3-7ff762a883ba 50->54 55 7ff762a8837a 50->55 56 7ff762a88283-7ff762a882b4 TranslateMessage DispatchMessageW PeekMessageW 51->56 57 7ff762a882b6-7ff762a882c6 WaitForSingleObject 51->57 52->41 52->43 53->52 54->43 59 7ff762a883bc-7ff762a883e5 QueryPerformanceCounter 54->59 58 7ff762a88380-7ff762a883b1 TranslateMessage DispatchMessageW PeekMessageW 55->58 56->56 56->57 57->34 57->39 58->54 58->58 59->50 60 7ff762a883eb-7ff762a883f2 59->60 60->41 61 7ff762a883f4-7ff762a883f8 60->61 61->43
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorLastMessage$ObjectProcessSingleWait$CloseCreateHandlePeekWindow_invalid_parameter_noinfo$ByteCharClassCodeCommandConsoleCtrlCurrentDestroyDispatchExitFormatHandlerInfoLineMultiRegisterStartupTerminateTranslateWide
                                                                                                                                                                                                                                                            • String ID: CreateProcessW$Failed to create child process!$PyInstaller Onefile Hidden Window$PyInstallerOnefileHiddenWindow
                                                                                                                                                                                                                                                            • API String ID: 4208240515-3165540532
                                                                                                                                                                                                                                                            • Opcode ID: 40a2b2c96db5062fbaff54aa02804a1320958b809a954de9be60782f8870c354
                                                                                                                                                                                                                                                            • Instruction ID: 64de1f0d4fcd45b5778a2d52e52ac658603cb241d308391908483847e02a9e2c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 40a2b2c96db5062fbaff54aa02804a1320958b809a954de9be60782f8870c354
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 57D16332A08E82C6EF90AF74E850AA9B760FF44B98F804235DE5D46A94DFFCD545C760

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 505 7ff762aa6e70-7ff762aa6eab call 7ff762aa67f8 call 7ff762aa6800 call 7ff762aa6868 512 7ff762aa6eb1-7ff762aa6ebc call 7ff762aa6808 505->512 513 7ff762aa70d5-7ff762aa7121 call 7ff762a9b844 call 7ff762aa67f8 call 7ff762aa6800 call 7ff762aa6868 505->513 512->513 518 7ff762aa6ec2-7ff762aa6ecc 512->518 540 7ff762aa725f-7ff762aa72cd call 7ff762a9b844 call 7ff762aa27e8 513->540 541 7ff762aa7127-7ff762aa7132 call 7ff762aa6808 513->541 520 7ff762aa6eee-7ff762aa6ef2 518->520 521 7ff762aa6ece-7ff762aa6ed1 518->521 524 7ff762aa6ef5-7ff762aa6efd 520->524 523 7ff762aa6ed4-7ff762aa6edf 521->523 526 7ff762aa6ee1-7ff762aa6ee8 523->526 527 7ff762aa6eea-7ff762aa6eec 523->527 524->524 528 7ff762aa6eff-7ff762aa6f12 call 7ff762a9e6c4 524->528 526->523 526->527 527->520 530 7ff762aa6f1b-7ff762aa6f29 527->530 535 7ff762aa6f14-7ff762aa6f16 call 7ff762a9b464 528->535 536 7ff762aa6f2a-7ff762aa6f36 call 7ff762a9b464 528->536 535->530 547 7ff762aa6f3d-7ff762aa6f45 536->547 559 7ff762aa72cf-7ff762aa72d6 540->559 560 7ff762aa72db-7ff762aa72de 540->560 541->540 548 7ff762aa7138-7ff762aa7143 call 7ff762aa6838 541->548 547->547 550 7ff762aa6f47-7ff762aa6f58 call 7ff762aa16e4 547->550 548->540 557 7ff762aa7149-7ff762aa716c call 7ff762a9b464 GetTimeZoneInformation 548->557 550->513 558 7ff762aa6f5e-7ff762aa6fb4 call 7ff762aab740 * 4 call 7ff762aa6d8c 550->558 572 7ff762aa7172-7ff762aa7193 557->572 573 7ff762aa7234-7ff762aa725e call 7ff762aa67f0 call 7ff762aa67e0 call 7ff762aa67e8 557->573 618 7ff762aa6fb6-7ff762aa6fba 558->618 563 7ff762aa736b-7ff762aa736e 559->563 564 7ff762aa72e0 560->564 565 7ff762aa7315-7ff762aa7328 call 7ff762a9e6c4 560->565 566 7ff762aa72e3 call 7ff762aa70ec 563->566 568 7ff762aa7374-7ff762aa737c call 7ff762aa6e70 563->568 564->566 581 7ff762aa7333-7ff762aa734e call 7ff762aa27e8 565->581 582 7ff762aa732a 565->582 577 7ff762aa72e8-7ff762aa7314 call 7ff762a9b464 call 7ff762a8bb10 566->577 568->577 578 7ff762aa7195-7ff762aa719b 572->578 579 7ff762aa719e-7ff762aa71a5 572->579 578->579 587 7ff762aa71a7-7ff762aa71af 579->587 588 7ff762aa71b9 579->588 599 7ff762aa7350-7ff762aa7353 581->599 600 7ff762aa7355-7ff762aa7367 call 7ff762a9b464 581->600 589 7ff762aa732c-7ff762aa7331 call 7ff762a9b464 582->589 587->588 596 7ff762aa71b1-7ff762aa71b7 587->596 594 7ff762aa71bb-7ff762aa722f call 7ff762aab740 * 4 call 7ff762aa3dcc call 7ff762aa7384 * 2 588->594 589->564 594->573 596->594 599->589 600->563 620 7ff762aa6fc0-7ff762aa6fc4 618->620 621 7ff762aa6fbc 618->621 620->618 623 7ff762aa6fc6-7ff762aa6feb call 7ff762a97b18 620->623 621->620 629 7ff762aa6fee-7ff762aa6ff2 623->629 631 7ff762aa7001-7ff762aa7005 629->631 632 7ff762aa6ff4-7ff762aa6fff 629->632 631->629 632->631 634 7ff762aa7007-7ff762aa700b 632->634 635 7ff762aa708c-7ff762aa7090 634->635 636 7ff762aa700d-7ff762aa7035 call 7ff762a97b18 634->636 639 7ff762aa7092-7ff762aa7094 635->639 640 7ff762aa7097-7ff762aa70a4 635->640 645 7ff762aa7053-7ff762aa7057 636->645 646 7ff762aa7037 636->646 639->640 641 7ff762aa70bf-7ff762aa70ce call 7ff762aa67f0 call 7ff762aa67e0 640->641 642 7ff762aa70a6-7ff762aa70bc call 7ff762aa6d8c 640->642 641->513 642->641 645->635 651 7ff762aa7059-7ff762aa7077 call 7ff762a97b18 645->651 649 7ff762aa703a-7ff762aa7041 646->649 649->645 652 7ff762aa7043-7ff762aa7051 649->652 657 7ff762aa7083-7ff762aa708a 651->657 652->645 652->649 657->635 658 7ff762aa7079-7ff762aa707d 657->658 658->635 659 7ff762aa707f 658->659 659->657
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • _get_daylight.LIBCMT ref: 00007FF762AA6EB5
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762AA6808: _invalid_parameter_noinfo.LIBCMT ref: 00007FF762AA681C
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A9B464: RtlFreeHeap.NTDLL(?,?,?,00007FF762AA3F92,?,?,?,00007FF762AA3FCF,?,?,00000000,00007FF762AA4495,?,?,?,00007FF762AA43C7), ref: 00007FF762A9B47A
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A9B464: GetLastError.KERNEL32(?,?,?,00007FF762AA3F92,?,?,?,00007FF762AA3FCF,?,?,00000000,00007FF762AA4495,?,?,?,00007FF762AA43C7), ref: 00007FF762A9B484
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A9B844: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF762A9B823,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9B84D
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A9B844: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF762A9B823,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9B872
                                                                                                                                                                                                                                                            • _get_daylight.LIBCMT ref: 00007FF762AA6EA4
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762AA6868: _invalid_parameter_noinfo.LIBCMT ref: 00007FF762AA687C
                                                                                                                                                                                                                                                            • _get_daylight.LIBCMT ref: 00007FF762AA711A
                                                                                                                                                                                                                                                            • _get_daylight.LIBCMT ref: 00007FF762AA712B
                                                                                                                                                                                                                                                            • _get_daylight.LIBCMT ref: 00007FF762AA713C
                                                                                                                                                                                                                                                            • GetTimeZoneInformation.KERNELBASE(?,?,?,?,?,?,?,?,?,00000000,?,00007FF762AA737C), ref: 00007FF762AA7163
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _get_daylight$_invalid_parameter_noinfo$CurrentErrorFeatureFreeHeapInformationLastPresentProcessProcessorTimeZone
                                                                                                                                                                                                                                                            • String ID: Eastern Standard Time$Eastern Summer Time
                                                                                                                                                                                                                                                            • API String ID: 4070488512-239921721
                                                                                                                                                                                                                                                            • Opcode ID: 1cc6d2bc0113d7e20a77d6be4757883c424c8a6b3909b765b0ec1a4afa43a119
                                                                                                                                                                                                                                                            • Instruction ID: baee8b8a18a5fc39c462e1ff7714697e98e36ce2bc8f419b71551ec5a210de0e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1cc6d2bc0113d7e20a77d6be4757883c424c8a6b3909b765b0ec1a4afa43a119
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9BD18026A18242C5EFE0BF26D8519B9E751EF44B94F804135EE0D47B99DEFCE441CBA0

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 719 7ff762aa7bd4-7ff762aa7c47 call 7ff762aa7908 722 7ff762aa7c61-7ff762aa7c6b call 7ff762a9945c 719->722 723 7ff762aa7c49-7ff762aa7c52 call 7ff762a95e28 719->723 729 7ff762aa7c86-7ff762aa7cef CreateFileW 722->729 730 7ff762aa7c6d-7ff762aa7c84 call 7ff762a95e28 call 7ff762a95e48 722->730 728 7ff762aa7c55-7ff762aa7c5c call 7ff762a95e48 723->728 743 7ff762aa7fa2-7ff762aa7fc2 728->743 731 7ff762aa7cf1-7ff762aa7cf7 729->731 732 7ff762aa7d6c-7ff762aa7d77 GetFileType 729->732 730->728 735 7ff762aa7d39-7ff762aa7d67 GetLastError call 7ff762a95dbc 731->735 736 7ff762aa7cf9-7ff762aa7cfd 731->736 738 7ff762aa7dca-7ff762aa7dd1 732->738 739 7ff762aa7d79-7ff762aa7db4 GetLastError call 7ff762a95dbc CloseHandle 732->739 735->728 736->735 741 7ff762aa7cff-7ff762aa7d37 CreateFileW 736->741 746 7ff762aa7dd3-7ff762aa7dd7 738->746 747 7ff762aa7dd9-7ff762aa7ddc 738->747 739->728 754 7ff762aa7dba-7ff762aa7dc5 call 7ff762a95e48 739->754 741->732 741->735 748 7ff762aa7de2-7ff762aa7e37 call 7ff762a99374 746->748 747->748 749 7ff762aa7dde 747->749 757 7ff762aa7e56-7ff762aa7e87 call 7ff762aa7688 748->757 758 7ff762aa7e39-7ff762aa7e45 call 7ff762aa7b10 748->758 749->748 754->728 765 7ff762aa7e89-7ff762aa7e8b 757->765 766 7ff762aa7e8d-7ff762aa7ecf 757->766 758->757 764 7ff762aa7e47 758->764 767 7ff762aa7e49-7ff762aa7e51 call 7ff762a9b9c8 764->767 765->767 768 7ff762aa7ef1-7ff762aa7efc 766->768 769 7ff762aa7ed1-7ff762aa7ed5 766->769 767->743 771 7ff762aa7fa0 768->771 772 7ff762aa7f02-7ff762aa7f06 768->772 769->768 770 7ff762aa7ed7-7ff762aa7eec 769->770 770->768 771->743 772->771 774 7ff762aa7f0c-7ff762aa7f51 CloseHandle CreateFileW 772->774 776 7ff762aa7f53-7ff762aa7f81 GetLastError call 7ff762a95dbc call 7ff762a9959c 774->776 777 7ff762aa7f86-7ff762aa7f9b 774->777 776->777 777->771
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1617910340-0
                                                                                                                                                                                                                                                            • Opcode ID: f7d25cc6398c99507331e2d119a18c280b6cb5988aed80ed714a7f2df808d279
                                                                                                                                                                                                                                                            • Instruction ID: 1e5abbd3833abcd1512cef039a3801bc757cfbd3cd616dadb5ab32fa3d2afe2f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f7d25cc6398c99507331e2d119a18c280b6cb5988aed80ed714a7f2df808d279
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A4C1E332B28A42C5EF90EF65C880ABD7761EB48B98B501235DE1E5BBD8CFB8D411C750

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileFind$DirectoryRemove$CloseDeleteFirstNext
                                                                                                                                                                                                                                                            • String ID: %s\*
                                                                                                                                                                                                                                                            • API String ID: 1057558799-766152087
                                                                                                                                                                                                                                                            • Opcode ID: 33e10a2293b6f66987fc751628de3762a02ba3a339ba911e57677f2f560f8a7f
                                                                                                                                                                                                                                                            • Instruction ID: c6a0e0edded10e0b9014de964185dfb8d8de27f0b5918f81837c364a8ddae8f9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 33e10a2293b6f66987fc751628de3762a02ba3a339ba911e57677f2f560f8a7f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: FB413025B0CA42C1EFE0AB24A844AB9A361FF98754FD00632DD9E47694DFFCD546C760
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: invalid bit length repeat$invalid code -- missing end-of-block$invalid code lengths set$invalid distance code$invalid distance too far back$invalid distances set$invalid literal/length code$invalid literal/lengths set$too many length or distance symbols
                                                                                                                                                                                                                                                            • API String ID: 0-2665694366
                                                                                                                                                                                                                                                            • Opcode ID: 4827148dd37d06b9a23a2cb7d22b3f776e5342dd5831b168843cb21776e0705c
                                                                                                                                                                                                                                                            • Instruction ID: f8756d9cd7b9c1010e9acf779f9048859397fe3998752ab89c8de876dff5102b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4827148dd37d06b9a23a2cb7d22b3f776e5342dd5831b168843cb21776e0705c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3052F572A146A68BEB949F14C458F7E7BAAFB44340F418139EA4A877C1DFBCD840CB11

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 1196 7ff762aa70ec-7ff762aa7121 call 7ff762aa67f8 call 7ff762aa6800 call 7ff762aa6868 1203 7ff762aa725f-7ff762aa72cd call 7ff762a9b844 call 7ff762aa27e8 1196->1203 1204 7ff762aa7127-7ff762aa7132 call 7ff762aa6808 1196->1204 1216 7ff762aa72cf-7ff762aa72d6 1203->1216 1217 7ff762aa72db-7ff762aa72de 1203->1217 1204->1203 1209 7ff762aa7138-7ff762aa7143 call 7ff762aa6838 1204->1209 1209->1203 1215 7ff762aa7149-7ff762aa716c call 7ff762a9b464 GetTimeZoneInformation 1209->1215 1227 7ff762aa7172-7ff762aa7193 1215->1227 1228 7ff762aa7234-7ff762aa725e call 7ff762aa67f0 call 7ff762aa67e0 call 7ff762aa67e8 1215->1228 1219 7ff762aa736b-7ff762aa736e 1216->1219 1220 7ff762aa72e0 1217->1220 1221 7ff762aa7315-7ff762aa7328 call 7ff762a9e6c4 1217->1221 1222 7ff762aa72e3 call 7ff762aa70ec 1219->1222 1224 7ff762aa7374-7ff762aa737c call 7ff762aa6e70 1219->1224 1220->1222 1235 7ff762aa7333-7ff762aa734e call 7ff762aa27e8 1221->1235 1236 7ff762aa732a 1221->1236 1231 7ff762aa72e8-7ff762aa7314 call 7ff762a9b464 call 7ff762a8bb10 1222->1231 1224->1231 1232 7ff762aa7195-7ff762aa719b 1227->1232 1233 7ff762aa719e-7ff762aa71a5 1227->1233 1232->1233 1239 7ff762aa71a7-7ff762aa71af 1233->1239 1240 7ff762aa71b9 1233->1240 1250 7ff762aa7350-7ff762aa7353 1235->1250 1251 7ff762aa7355-7ff762aa7367 call 7ff762a9b464 1235->1251 1241 7ff762aa732c-7ff762aa7331 call 7ff762a9b464 1236->1241 1239->1240 1247 7ff762aa71b1-7ff762aa71b7 1239->1247 1245 7ff762aa71bb-7ff762aa722f call 7ff762aab740 * 4 call 7ff762aa3dcc call 7ff762aa7384 * 2 1240->1245 1241->1220 1245->1228 1247->1245 1250->1241 1251->1219
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • _get_daylight.LIBCMT ref: 00007FF762AA711A
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762AA6868: _invalid_parameter_noinfo.LIBCMT ref: 00007FF762AA687C
                                                                                                                                                                                                                                                            • _get_daylight.LIBCMT ref: 00007FF762AA712B
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762AA6808: _invalid_parameter_noinfo.LIBCMT ref: 00007FF762AA681C
                                                                                                                                                                                                                                                            • _get_daylight.LIBCMT ref: 00007FF762AA713C
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762AA6838: _invalid_parameter_noinfo.LIBCMT ref: 00007FF762AA684C
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A9B464: RtlFreeHeap.NTDLL(?,?,?,00007FF762AA3F92,?,?,?,00007FF762AA3FCF,?,?,00000000,00007FF762AA4495,?,?,?,00007FF762AA43C7), ref: 00007FF762A9B47A
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A9B464: GetLastError.KERNEL32(?,?,?,00007FF762AA3F92,?,?,?,00007FF762AA3FCF,?,?,00000000,00007FF762AA4495,?,?,?,00007FF762AA43C7), ref: 00007FF762A9B484
                                                                                                                                                                                                                                                            • GetTimeZoneInformation.KERNELBASE(?,?,?,?,?,?,?,?,?,00000000,?,00007FF762AA737C), ref: 00007FF762AA7163
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _get_daylight_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
                                                                                                                                                                                                                                                            • String ID: Eastern Standard Time$Eastern Summer Time
                                                                                                                                                                                                                                                            • API String ID: 3458911817-239921721
                                                                                                                                                                                                                                                            • Opcode ID: fce0b41cc66c7972387442f4a259984a91ef9247f86000003104344bdc7b7ed6
                                                                                                                                                                                                                                                            • Instruction ID: 38c7b58e4e28ff7ec34928dd06cbbd30b6ed1d238027ac375766a738b9cc2c41
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fce0b41cc66c7972387442f4a259984a91ef9247f86000003104344bdc7b7ed6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7B515026A18642C6EFD0EF25D8809A9E761BF48744F804135EE4D47B65DFFCE405CBA0
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: $header crc mismatch$unknown header flags set
                                                                                                                                                                                                                                                            • API String ID: 0-1127688429
                                                                                                                                                                                                                                                            • Opcode ID: b4bf022b898153f2a381bcd878a50a5d3c06b36ca84da26d2d0edcb3d1e551c0
                                                                                                                                                                                                                                                            • Instruction ID: 3042422b8ad97a0951d9c6834ad7d53a1d3c9c140996004ef04a9707599c9b48
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b4bf022b898153f2a381bcd878a50a5d3c06b36ca84da26d2d0edcb3d1e551c0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 68F18172A183D68AEBE5AB14C188E3ABAA9EF44740F458538DE4907791DFFCE840C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Find$CloseFileFirst
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2295610775-0
                                                                                                                                                                                                                                                            • Opcode ID: c8bb1e00aee5117eaed99adb2432ba14ac7573cdfbb2fa81c580c042f8a510df
                                                                                                                                                                                                                                                            • Instruction ID: 20c57f1a02fce89bb7a5b43a1a5323e2dcfbc337d7b2086a9509702143c2ef8e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c8bb1e00aee5117eaed99adb2432ba14ac7573cdfbb2fa81c580c042f8a510df
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 72F06866A18646C6FBE09B60B459B66B350FF847A4F844335DEAE42AD4DFFCD009CB10
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: incorrect header check$invalid window size
                                                                                                                                                                                                                                                            • API String ID: 0-900081337
                                                                                                                                                                                                                                                            • Opcode ID: 8c4c8a6a705a7cf803fa5291bdc529627e531fe0bdcc095ab807ab19af6e2c49
                                                                                                                                                                                                                                                            • Instruction ID: cf229028ba42bb1302e8f30eb0fbed62819441a8c6edbfcd6eded166da7b6061
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8c4c8a6a705a7cf803fa5291bdc529627e531fe0bdcc095ab807ab19af6e2c49
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 61919672A182C6CBEBE49A14C448E3ABAA9FF44350F518139DE4A467C5DFBCE940CB11
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorFileLastModuleName
                                                                                                                                                                                                                                                            • String ID: Could not create temporary directory!$Could not load PyInstaller's embedded PKG archive from the executable (%s)$Could not side-load PyInstaller's PKG archive from external file (%s)$Failed to convert DLL search path!$Failed to initialize security descriptor for temporary directory!$Failed to load Tcl/Tk shared libraries for splash screen!$Failed to load splash screen resources!$Failed to remove temporary directory: %s$Failed to start splash screen!$Failed to unpack splash screen dependencies from PKG archive!$Invalid value in _PYI_PARENT_PROCESS_LEVEL: %s$MEI$PYINSTALLER_RESET_ENVIRONMENT$PYINSTALLER_STRICT_UNPACK_MODE$PYINSTALLER_SUPPRESS_SPLASH_SCREEN$Path exceeds PYI_PATH_MAX limit.$Py_GIL_DISABLED$VCRUNTIME140.dll$_PYI_APPLICATION_HOME_DIR$_PYI_APPLICATION_HOME_DIR not set for onefile child process!$_PYI_ARCHIVE_FILE$_PYI_PARENT_PROCESS_LEVEL$_PYI_SPLASH_IPC$hide-early$hide-late$minimize-early$minimize-late$pkg$pyi-contents-directory$pyi-hide-console$pyi-python-flag$pyi-runtime-tmpdir
                                                                                                                                                                                                                                                            • API String ID: 2776309574-3325264605
                                                                                                                                                                                                                                                            • Opcode ID: a9777e47e98eae9a3161dd2ba0debb3e1757f8e314b5e351b91e19d85db55502
                                                                                                                                                                                                                                                            • Instruction ID: 0209b71196b7997057d6a63c30d0245b23abee0407367805cdd925bdd4c4055d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a9777e47e98eae9a3161dd2ba0debb3e1757f8e314b5e351b91e19d85db55502
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 19428B21E0C682D0FFE5BB21D815AF9E691AF54780FC44032DE9E466D6EEECE548C360

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 357 7ff762a81930-7ff762a8196b call 7ff762a839d0 360 7ff762a81c2e-7ff762a81c52 call 7ff762a8bb10 357->360 361 7ff762a81971-7ff762a819b1 call 7ff762a873d0 357->361 366 7ff762a81c1b-7ff762a81c1e call 7ff762a8f5a4 361->366 367 7ff762a819b7-7ff762a819c7 call 7ff762a8fc2c 361->367 371 7ff762a81c23-7ff762a81c2b 366->371 372 7ff762a819c9-7ff762a819e3 call 7ff762a95e48 call 7ff762a82020 367->372 373 7ff762a819e8-7ff762a81a04 call 7ff762a8f8f4 367->373 371->360 372->366 379 7ff762a81a06-7ff762a81a20 call 7ff762a95e48 call 7ff762a82020 373->379 380 7ff762a81a25-7ff762a81a3a call 7ff762a95e68 373->380 379->366 386 7ff762a81a3c-7ff762a81a56 call 7ff762a95e48 call 7ff762a82020 380->386 387 7ff762a81a5b-7ff762a81ae5 call 7ff762a81c60 * 2 call 7ff762a8fc2c call 7ff762a95e84 380->387 386->366 401 7ff762a81aea-7ff762a81af4 387->401 402 7ff762a81af6-7ff762a81b10 call 7ff762a95e48 call 7ff762a82020 401->402 403 7ff762a81b15-7ff762a81b2e call 7ff762a8f8f4 401->403 402->366 409 7ff762a81b30-7ff762a81b4a call 7ff762a95e48 call 7ff762a82020 403->409 410 7ff762a81b4f-7ff762a81b6b call 7ff762a8f668 403->410 409->366 417 7ff762a81b7e-7ff762a81b8c 410->417 418 7ff762a81b6d-7ff762a81b79 call 7ff762a81e50 410->418 417->366 420 7ff762a81b92-7ff762a81b99 417->420 418->366 423 7ff762a81ba1-7ff762a81ba7 420->423 424 7ff762a81ba9-7ff762a81bb6 423->424 425 7ff762a81bc0-7ff762a81bcf 423->425 426 7ff762a81bd1-7ff762a81bda 424->426 425->425 425->426 427 7ff762a81bdc-7ff762a81bdf 426->427 428 7ff762a81bef 426->428 427->428 429 7ff762a81be1-7ff762a81be4 427->429 430 7ff762a81bf1-7ff762a81c04 428->430 429->428 431 7ff762a81be6-7ff762a81be9 429->431 432 7ff762a81c0d-7ff762a81c19 430->432 433 7ff762a81c06 430->433 431->428 434 7ff762a81beb-7ff762a81bed 431->434 432->366 432->423 433->432 434->430
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A873D0: _fread_nolock.LIBCMT ref: 00007FF762A8747A
                                                                                                                                                                                                                                                            • _fread_nolock.LIBCMT ref: 00007FF762A819FB
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A82020: GetCurrentProcessId.KERNEL32(?,?,?,?,00000000,00000000,?,00000000,00007FF762A81B4A), ref: 00007FF762A82070
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _fread_nolock$CurrentProcess
                                                                                                                                                                                                                                                            • String ID: Could not allocate buffer for TOC!$Could not allocate memory for archive structure!$Could not read full TOC!$Error on file.$Failed to read cookie!$Failed to seek to cookie position!$MEI$calloc$fread$fseek$malloc
                                                                                                                                                                                                                                                            • API String ID: 2397952137-3497178890
                                                                                                                                                                                                                                                            • Opcode ID: f375aa3b5ce52aa88104ef8fcd1bb848994f70b47b28a42eb294ac42c1195ff9
                                                                                                                                                                                                                                                            • Instruction ID: 9cdccab4bf7e56fc91621882ccb54258a177c061bf0799454fbd2a9d34c76cd1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f375aa3b5ce52aa88104ef8fcd1bb848994f70b47b28a42eb294ac42c1195ff9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3281AE71A08A86C5EFD0EB24D045AB9A3A1EF48784FD04036DE8D47B99DEFCE445CB60

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 435 7ff762a815e0-7ff762a815f1 436 7ff762a81617-7ff762a81631 call 7ff762a839d0 435->436 437 7ff762a815f3-7ff762a815fc call 7ff762a81030 435->437 444 7ff762a81633-7ff762a81661 call 7ff762a95e48 call 7ff762a82020 436->444 445 7ff762a81662-7ff762a8167c call 7ff762a839d0 436->445 442 7ff762a8160e-7ff762a81616 437->442 443 7ff762a815fe-7ff762a81609 call 7ff762a81e50 437->443 443->442 451 7ff762a8167e-7ff762a81693 call 7ff762a81e50 445->451 452 7ff762a81698-7ff762a816af call 7ff762a8fc2c 445->452 459 7ff762a81801-7ff762a81804 call 7ff762a8f5a4 451->459 460 7ff762a816d9-7ff762a816dd 452->460 461 7ff762a816b1-7ff762a816d4 call 7ff762a95e48 call 7ff762a82020 452->461 468 7ff762a81809-7ff762a8181b 459->468 462 7ff762a816f7-7ff762a81717 call 7ff762a95e84 460->462 463 7ff762a816df-7ff762a816eb call 7ff762a811f0 460->463 473 7ff762a817f9-7ff762a817fc call 7ff762a8f5a4 461->473 474 7ff762a81719-7ff762a8173c call 7ff762a95e48 call 7ff762a82020 462->474 475 7ff762a81741-7ff762a8174c 462->475 470 7ff762a816f0-7ff762a816f2 463->470 470->473 473->459 487 7ff762a817ef-7ff762a817f4 474->487 479 7ff762a817e2-7ff762a817ea call 7ff762a95e70 475->479 480 7ff762a81752-7ff762a81757 475->480 479->487 483 7ff762a81760-7ff762a81782 call 7ff762a8f8f4 480->483 490 7ff762a817ba-7ff762a817c6 call 7ff762a95e48 483->490 491 7ff762a81784-7ff762a8179c call 7ff762a90034 483->491 487->473 498 7ff762a817cd-7ff762a817d8 call 7ff762a82020 490->498 496 7ff762a8179e-7ff762a817a1 491->496 497 7ff762a817a5-7ff762a817b8 call 7ff762a95e48 491->497 496->483 499 7ff762a817a3 496->499 497->498 502 7ff762a817dd 498->502 499->502 502->479
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: Failed to create symbolic link %s!$Failed to extract %s: failed to allocate temporary buffer!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to open target file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$Failed to extract %s: failed to write data chunk!$fopen$fread$fseek$fwrite$malloc
                                                                                                                                                                                                                                                            • API String ID: 2050909247-1550345328
                                                                                                                                                                                                                                                            • Opcode ID: 5051b5233a7b01146263a4f7b3557eb1fe3b99dfb5c33cb6a56ad76ac64855a0
                                                                                                                                                                                                                                                            • Instruction ID: b9dd06409281afaec3c1da49dda9d4537c7038d5d2cfbbca47242e627a144c0b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5051b5233a7b01146263a4f7b3557eb1fe3b99dfb5c33cb6a56ad76ac64855a0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0051DF21B08A83C2EF90BB1198419B9A3A0BF44B94FD04136EE5C07B96DFFCE545C760

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetTempPathW.KERNEL32(FFFFFFFF,00000000,?,00007FF762A83101), ref: 00007FF762A87D44
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(?,00007FF762A83101), ref: 00007FF762A87D4A
                                                                                                                                                                                                                                                            • CreateDirectoryW.KERNELBASE(?,00007FF762A83101), ref: 00007FF762A87D8C
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A87E70: GetEnvironmentVariableW.KERNEL32(00007FF762A82C4F), ref: 00007FF762A87EA7
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A87E70: ExpandEnvironmentStringsW.KERNEL32 ref: 00007FF762A87EC9
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A99174: _invalid_parameter_noinfo.LIBCMT ref: 00007FF762A9918D
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Environment$CreateCurrentDirectoryExpandPathProcessStringsTempVariable_invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: LOADER: failed to set the TMP environment variable.$LOADER: length of teporary directory path exceeds maximum path length!$TMP$TMP$_MEI%d
                                                                                                                                                                                                                                                            • API String ID: 365913792-1339014028
                                                                                                                                                                                                                                                            • Opcode ID: 93349d7b9616cd7418fb1fb7d836f55c0d98c0562c0ac1a5b6313c198f173f9d
                                                                                                                                                                                                                                                            • Instruction ID: 9767917879e26091c9aa768da4af7ba05be658ab7c7376f5a604bb9640e159f2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 93349d7b9616cd7418fb1fb7d836f55c0d98c0562c0ac1a5b6313c198f173f9d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 17416B21B19642C4EFE4F7229955AB9A251AF897C0FD04031ED0D4B7A6EEFCE905CA60

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 782 7ff762a811f0-7ff762a8124d call 7ff762a8b340 785 7ff762a81277-7ff762a8128f call 7ff762a95e84 782->785 786 7ff762a8124f-7ff762a81276 call 7ff762a81e50 782->786 791 7ff762a812b4-7ff762a812c4 call 7ff762a95e84 785->791 792 7ff762a81291-7ff762a812af call 7ff762a95e48 call 7ff762a82020 785->792 798 7ff762a812e9-7ff762a812fb 791->798 799 7ff762a812c6-7ff762a812e4 call 7ff762a95e48 call 7ff762a82020 791->799 803 7ff762a81419-7ff762a8142e call 7ff762a8b020 call 7ff762a95e70 * 2 792->803 802 7ff762a81300-7ff762a81325 call 7ff762a8f8f4 798->802 799->803 809 7ff762a8132b-7ff762a81335 call 7ff762a8f668 802->809 810 7ff762a81411 802->810 819 7ff762a81433-7ff762a8144d 803->819 809->810 818 7ff762a8133b-7ff762a81347 809->818 810->803 820 7ff762a81350-7ff762a81378 call 7ff762a89780 818->820 823 7ff762a8137a-7ff762a8137d 820->823 824 7ff762a813f6-7ff762a8140c call 7ff762a81e50 820->824 825 7ff762a813f1 823->825 826 7ff762a8137f-7ff762a81389 823->826 824->810 825->824 828 7ff762a8138b-7ff762a81399 call 7ff762a90034 826->828 829 7ff762a813b4-7ff762a813b7 826->829 835 7ff762a8139e-7ff762a813a1 828->835 830 7ff762a813ca-7ff762a813cf 829->830 831 7ff762a813b9-7ff762a813c7 call 7ff762aab0a0 829->831 830->820 834 7ff762a813d5-7ff762a813d8 830->834 831->830 837 7ff762a813ec-7ff762a813ef 834->837 838 7ff762a813da-7ff762a813dd 834->838 839 7ff762a813a3-7ff762a813ad call 7ff762a8f668 835->839 840 7ff762a813af-7ff762a813b2 835->840 837->810 838->824 841 7ff762a813df-7ff762a813e7 838->841 839->830 839->840 840->824 841->802
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: 1.3.1$Failed to extract %s: decompression resulted in return code %d!$Failed to extract %s: failed to allocate temporary input buffer!$Failed to extract %s: failed to allocate temporary output buffer!$Failed to extract %s: inflateInit() failed with return code %d!$malloc
                                                                                                                                                                                                                                                            • API String ID: 2050909247-2813020118
                                                                                                                                                                                                                                                            • Opcode ID: cba81131777859bd24b40b19184175e0ff97f39e1f2717241654f826e9969730
                                                                                                                                                                                                                                                            • Instruction ID: 3f1b78f1634af4d99bcdff370af77eab22e9422f6a3c10268cd3a21c60dcf5ff
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cba81131777859bd24b40b19184175e0ff97f39e1f2717241654f826e9969730
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3251E262A08A82C5EFE0BB15A440BBAA291FF84794FD44135ED5D47BD5EEFCE801C750

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • FreeLibrary.KERNEL32(?,?,?,00007FF762AA0316,?,?,-00000018,00007FF762A9BC5B,?,?,?,00007FF762A9BB52,?,?,?,00007FF762A96EFE), ref: 00007FF762AA00F8
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,?,?,00007FF762AA0316,?,?,-00000018,00007FF762A9BC5B,?,?,?,00007FF762A9BB52,?,?,?,00007FF762A96EFE), ref: 00007FF762AA0104
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AddressFreeLibraryProc
                                                                                                                                                                                                                                                            • String ID: api-ms-$ext-ms-
                                                                                                                                                                                                                                                            • API String ID: 3013587201-537541572
                                                                                                                                                                                                                                                            • Opcode ID: d956f0b8ec152b18ca11aa0aed68125bebf2684d60339ba7369f52f17a1fcfe1
                                                                                                                                                                                                                                                            • Instruction ID: 649d171a3d09e9c3c3bcfe1c4dfc809445b60182191a59c10c8b5234ab231205
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d956f0b8ec152b18ca11aa0aed68125bebf2684d60339ba7369f52f17a1fcfe1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 07412621B19A02C1FFD5EB16A810BB5A391BF09BA0F854135DD0E87B94DEFDE845C360

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetModuleFileNameW.KERNEL32(?,00007FF762A82BC5), ref: 00007FF762A82AA1
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A82BC5), ref: 00007FF762A82AAB
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A82310: GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,00007FF762A82AC6,?,00007FF762A82BC5), ref: 00007FF762A82360
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A82310: FormatMessageW.KERNEL32(?,?,?,?,?,?,?,?,00007FF762A82AC6,?,00007FF762A82BC5), ref: 00007FF762A8241A
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentErrorFileFormatLastMessageModuleNameProcess
                                                                                                                                                                                                                                                            • String ID: Failed to convert executable path to UTF-8.$Failed to obtain executable path.$Failed to resolve full path to executable %ls.$GetModuleFileNameW$\\?\
                                                                                                                                                                                                                                                            • API String ID: 4002088556-2863816727
                                                                                                                                                                                                                                                            • Opcode ID: 093d1e49c6a3f32bbd7db28c580ca23961d52f0e240546522d41da137270d6a4
                                                                                                                                                                                                                                                            • Instruction ID: a4b40ac2ce78d5381e56b91b096a020cb695683fc068692abd230afe6ea539d3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 093d1e49c6a3f32bbd7db28c580ca23961d52f0e240546522d41da137270d6a4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 74218661B19582C1FFE0BB20E855BB6E250BF58784FC00132EE5D869E5EEECE504C760

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 1083 7ff762a9c95c-7ff762a9c982 1084 7ff762a9c984-7ff762a9c998 call 7ff762a95e28 call 7ff762a95e48 1083->1084 1085 7ff762a9c99d-7ff762a9c9a1 1083->1085 1103 7ff762a9cd8e 1084->1103 1087 7ff762a9cd77-7ff762a9cd83 call 7ff762a95e28 call 7ff762a95e48 1085->1087 1088 7ff762a9c9a7-7ff762a9c9ae 1085->1088 1105 7ff762a9cd89 call 7ff762a9b824 1087->1105 1088->1087 1090 7ff762a9c9b4-7ff762a9c9e2 1088->1090 1090->1087 1094 7ff762a9c9e8-7ff762a9c9ef 1090->1094 1095 7ff762a9c9f1-7ff762a9ca03 call 7ff762a95e28 call 7ff762a95e48 1094->1095 1096 7ff762a9ca08-7ff762a9ca0b 1094->1096 1095->1105 1101 7ff762a9ca11-7ff762a9ca17 1096->1101 1102 7ff762a9cd73-7ff762a9cd75 1096->1102 1101->1102 1107 7ff762a9ca1d-7ff762a9ca20 1101->1107 1106 7ff762a9cd91-7ff762a9cda8 1102->1106 1103->1106 1105->1103 1107->1095 1110 7ff762a9ca22-7ff762a9ca47 1107->1110 1112 7ff762a9ca7a-7ff762a9ca81 1110->1112 1113 7ff762a9ca49-7ff762a9ca4b 1110->1113 1114 7ff762a9ca83-7ff762a9caab call 7ff762a9e6c4 call 7ff762a9b464 * 2 1112->1114 1115 7ff762a9ca56-7ff762a9ca6d call 7ff762a95e28 call 7ff762a95e48 call 7ff762a9b824 1112->1115 1116 7ff762a9ca72-7ff762a9ca78 1113->1116 1117 7ff762a9ca4d-7ff762a9ca54 1113->1117 1146 7ff762a9cac8-7ff762a9caf3 call 7ff762a9d184 1114->1146 1147 7ff762a9caad-7ff762a9cac3 call 7ff762a95e48 call 7ff762a95e28 1114->1147 1144 7ff762a9cc00 1115->1144 1118 7ff762a9caf8-7ff762a9cb0f 1116->1118 1117->1115 1117->1116 1121 7ff762a9cb11-7ff762a9cb19 1118->1121 1122 7ff762a9cb8a-7ff762a9cb94 call 7ff762aa4b8c 1118->1122 1121->1122 1125 7ff762a9cb1b-7ff762a9cb1d 1121->1125 1133 7ff762a9cb9a-7ff762a9cbaf 1122->1133 1134 7ff762a9cc1e 1122->1134 1125->1122 1129 7ff762a9cb1f-7ff762a9cb35 1125->1129 1129->1122 1136 7ff762a9cb37-7ff762a9cb43 1129->1136 1133->1134 1138 7ff762a9cbb1-7ff762a9cbc3 GetConsoleMode 1133->1138 1142 7ff762a9cc23-7ff762a9cc43 ReadFile 1134->1142 1136->1122 1140 7ff762a9cb45-7ff762a9cb47 1136->1140 1138->1134 1143 7ff762a9cbc5-7ff762a9cbcd 1138->1143 1140->1122 1145 7ff762a9cb49-7ff762a9cb61 1140->1145 1148 7ff762a9cc49-7ff762a9cc51 1142->1148 1149 7ff762a9cd3d-7ff762a9cd46 GetLastError 1142->1149 1143->1142 1151 7ff762a9cbcf-7ff762a9cbf1 ReadConsoleW 1143->1151 1154 7ff762a9cc03-7ff762a9cc0d call 7ff762a9b464 1144->1154 1145->1122 1155 7ff762a9cb63-7ff762a9cb6f 1145->1155 1146->1118 1147->1144 1148->1149 1157 7ff762a9cc57 1148->1157 1152 7ff762a9cd63-7ff762a9cd66 1149->1152 1153 7ff762a9cd48-7ff762a9cd5e call 7ff762a95e48 call 7ff762a95e28 1149->1153 1160 7ff762a9cc12-7ff762a9cc1c 1151->1160 1161 7ff762a9cbf3 GetLastError 1151->1161 1165 7ff762a9cbf9-7ff762a9cbfb call 7ff762a95dbc 1152->1165 1166 7ff762a9cd6c-7ff762a9cd6e 1152->1166 1153->1144 1154->1106 1155->1122 1164 7ff762a9cb71-7ff762a9cb73 1155->1164 1158 7ff762a9cc5e-7ff762a9cc73 1157->1158 1158->1154 1168 7ff762a9cc75-7ff762a9cc80 1158->1168 1160->1158 1161->1165 1164->1122 1172 7ff762a9cb75-7ff762a9cb85 1164->1172 1165->1144 1166->1154 1174 7ff762a9cc82-7ff762a9cc9b call 7ff762a9c574 1168->1174 1175 7ff762a9cca7-7ff762a9ccaf 1168->1175 1172->1122 1183 7ff762a9cca0-7ff762a9cca2 1174->1183 1179 7ff762a9ccb1-7ff762a9ccc3 1175->1179 1180 7ff762a9cd2b-7ff762a9cd38 call 7ff762a9c3b4 1175->1180 1184 7ff762a9ccc5 1179->1184 1185 7ff762a9cd1e-7ff762a9cd26 1179->1185 1180->1183 1183->1154 1187 7ff762a9ccca-7ff762a9ccd1 1184->1187 1185->1154 1188 7ff762a9ccd3-7ff762a9ccd7 1187->1188 1189 7ff762a9cd0d-7ff762a9cd18 1187->1189 1190 7ff762a9ccf3 1188->1190 1191 7ff762a9ccd9-7ff762a9cce0 1188->1191 1189->1185 1193 7ff762a9ccf9-7ff762a9cd09 1190->1193 1191->1190 1192 7ff762a9cce2-7ff762a9cce6 1191->1192 1192->1190 1194 7ff762a9cce8-7ff762a9ccf1 1192->1194 1193->1187 1195 7ff762a9cd0b 1193->1195 1194->1193 1195->1185
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: e215fe86d7b0e6e2d08488d11c6944312657e99f94033e5188670243fcaba875
                                                                                                                                                                                                                                                            • Instruction ID: b5cd8617b4287ca5fe1b8e729424905f02e419d85b2470b6077fe63e742b9eec
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e215fe86d7b0e6e2d08488d11c6944312657e99f94033e5188670243fcaba875
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: FDC1B422D2CB86D1EF91AB169840ABDAB56AB89B80FA54131DE4D077D1CEFCDC45C720

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Token$InformationProcess$CloseConvertCurrentErrorHandleLastOpenString
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 995526605-0
                                                                                                                                                                                                                                                            • Opcode ID: cf92fa18b9e00c3d9d6dbbac75613ba75212e4a615f40cb6368d246a710d7e34
                                                                                                                                                                                                                                                            • Instruction ID: a70eae16e7ee41aba460752b8da8f3fba74745b7f239b9a07a5e81812939342e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cf92fa18b9e00c3d9d6dbbac75613ba75212e4a615f40cb6368d246a710d7e34
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A4215575B0CA42C1EF90AB55A84096AE3A1EF857E0F904235DE9D47AE4DEFCD445C710

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A87BB0: GetCurrentProcess.KERNEL32 ref: 00007FF762A87BD0
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A87BB0: OpenProcessToken.ADVAPI32 ref: 00007FF762A87BE3
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A87BB0: GetTokenInformation.KERNELBASE ref: 00007FF762A87C08
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A87BB0: GetLastError.KERNEL32 ref: 00007FF762A87C12
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A87BB0: GetTokenInformation.KERNELBASE ref: 00007FF762A87C52
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A87BB0: ConvertSidToStringSidW.ADVAPI32 ref: 00007FF762A87C6E
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A87BB0: CloseHandle.KERNEL32 ref: 00007FF762A87C86
                                                                                                                                                                                                                                                            • LocalFree.KERNEL32(00000000,00007FF762A83099), ref: 00007FF762A8864C
                                                                                                                                                                                                                                                            • LocalFree.KERNEL32 ref: 00007FF762A88655
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Token$FreeInformationLocalProcess$CloseConvertCurrentErrorHandleLastOpenString
                                                                                                                                                                                                                                                            • String ID: D:(A;;FA;;;%s)$D:(A;;FA;;;%s)(A;;FA;;;%s)$S-1-3-4$Security descriptor string length exceeds PYI_PATH_MAX!
                                                                                                                                                                                                                                                            • API String ID: 6828938-1529539262
                                                                                                                                                                                                                                                            • Opcode ID: f56e2b7b13e58d2b58346e81af7f984cd6ebbcb2f1baaaba9af8eb6cf4aaa322
                                                                                                                                                                                                                                                            • Instruction ID: f8e197ebca6507950636ed6157c1a7c25c3896ad9e3721b39e3c27512ef6df2e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f56e2b7b13e58d2b58346e81af7f984cd6ebbcb2f1baaaba9af8eb6cf4aaa322
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DE212C31A08646C6EB94BB10E815AEAE251FF88780FC44435EE4E53B96DFFDD544C7A0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • CreateDirectoryW.KERNELBASE(00000000,?,00007FF762A828EC,FFFFFFFF,00000000,00007FF762A8336A), ref: 00007FF762A87372
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CreateDirectory
                                                                                                                                                                                                                                                            • String ID: %.*s$%s%c$\
                                                                                                                                                                                                                                                            • API String ID: 4241100979-1685191245
                                                                                                                                                                                                                                                            • Opcode ID: 61b418e99efde3a0f519453cac267e08843ad3bf0b3a29706ebb583658b230ee
                                                                                                                                                                                                                                                            • Instruction ID: 2e76ebc460690b9bf58e07e7c156120a813b5508b20d4fd994585967942e66a2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 61b418e99efde3a0f519453cac267e08843ad3bf0b3a29706ebb583658b230ee
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F631B821719AC5C5EFA1AB21E810BEAA354EF84BE0F840631EEAD477D5DEECD245C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF762A9DE4B), ref: 00007FF762A9DF7C
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF762A9DE4B), ref: 00007FF762A9E007
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ConsoleErrorLastMode
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 953036326-0
                                                                                                                                                                                                                                                            • Opcode ID: 25026d299ec132fa7e986de3a50f80dd4a1c565eb46710a002b358a032e27337
                                                                                                                                                                                                                                                            • Instruction ID: 1055568a3024df04c8a97351638b89f211bc3553faaa674d19d5f1a5ac4f9bfe
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 25026d299ec132fa7e986de3a50f80dd4a1c565eb46710a002b358a032e27337
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6991D932E28651C5FF90BF269940A7DA7A0BB00784FA45136DE0E57A85DFFCD885C720
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _get_daylight$_isindst
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4170891091-0
                                                                                                                                                                                                                                                            • Opcode ID: 89e82a0bcb92f9a57c8ce538440e566bc748d838767a3902d6c6661200ebf515
                                                                                                                                                                                                                                                            • Instruction ID: 07ad77d79be9885219963a825f5c60011a734088f6fa3077714404a29e0fb325
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 89e82a0bcb92f9a57c8ce538440e566bc748d838767a3902d6c6661200ebf515
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 53510473F04212CAEF94EF249991BBCA7A5AF10358F900235DE1E52EE5DBB8A441C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: File$ErrorHandleInformationLastNamedPeekPipeType
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2780335769-0
                                                                                                                                                                                                                                                            • Opcode ID: ae309e55c8ec1c6071936a6282bf89ed613bd6d0468dcdab4ccc506c416e71eb
                                                                                                                                                                                                                                                            • Instruction ID: e675deaff6cbeed685f9e7f28762bb57f6ea507e701365a7dacd9b1192d3232d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ae309e55c8ec1c6071936a6282bf89ed613bd6d0468dcdab4ccc506c416e71eb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A8517122E24602C9FB94EF72D8407BDA3A1AF44B88FA08535DE0947749DFF8D841C7A0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CloseCreateFileHandle_invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1279662727-0
                                                                                                                                                                                                                                                            • Opcode ID: 6ce4c88b6d2478032947ca8abe21e63121e2028da5231a2800b2a2486ebac064
                                                                                                                                                                                                                                                            • Instruction ID: 1d4c280814045b6b113e556a0676c368050eeb46ef9f23369315e2629d3353b5
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6ce4c88b6d2478032947ca8abe21e63121e2028da5231a2800b2a2486ebac064
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BF417422D28742C3EB94AB219950769B360FF95764F609334EF9802BD5DFECA5A0C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Process$CurrentExitTerminate
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1703294689-0
                                                                                                                                                                                                                                                            • Opcode ID: 823bef23182f8f61d7efa7880482c28a4a7867c446eada0463010af46261c3c5
                                                                                                                                                                                                                                                            • Instruction ID: 80aa115545d0a2f25646fd037a361da20450e8e2ca5893d271370b2133bb8766
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 823bef23182f8f61d7efa7880482c28a4a7867c446eada0463010af46261c3c5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CFD06714F18A02C6EFD43B715C55AB992526F88711F911439CC8E06793CEEDA84DC661
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: 141dc46c6224036006d776e19841065f05dd1418e65b387591b1a003cf84bd0f
                                                                                                                                                                                                                                                            • Instruction ID: ccd5b15bd26ff0062105115670d7ae5050bfe258eeb9f19e5cdd41f8a533b290
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 141dc46c6224036006d776e19841065f05dd1418e65b387591b1a003cf84bd0f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1E51B721B09287C6FFA4BA269400E79A691BF44BA4FE44738DD6D877D9CEFCD401C620
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_release_startup_lock
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1236291503-0
                                                                                                                                                                                                                                                            • Opcode ID: bbbb43f9e1356fc36a8983c03ebcc8b7addcb0e166801d8c410c30bb16f29642
                                                                                                                                                                                                                                                            • Instruction ID: 8c177f62fcb0ab825c3f5e36381729e5dbe8ac4df7cc6b31c5dfd3f3ea1e746d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bbbb43f9e1356fc36a8983c03ebcc8b7addcb0e166801d8c410c30bb16f29642
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EB318A21E0C202C2EFC8BB65A511BB9E392AF44B84FC45135ED4D476D3DEECA805CA76
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileHandleType
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3000768030-0
                                                                                                                                                                                                                                                            • Opcode ID: b01a8b1655aeb6f71db35254c5ecf6a703e147159c44eee076082fbba724bcfb
                                                                                                                                                                                                                                                            • Instruction ID: 4c6de9cd4c7a38fb3c4ca0c5334725aba6448df670cdbb4fa152bd25398fccf2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b01a8b1655aeb6f71db35254c5ecf6a703e147159c44eee076082fbba724bcfb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1031A821E28F55C1EFA06B16894057AA650FB45BB0BB41375DF6E173E0CFB8E891D310
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • SetFilePointerEx.KERNELBASE(?,?,?,?,?,00007FF762A9D020,?,?,?,?,?,00007FF762A9D129), ref: 00007FF762A9D080
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,?,?,00007FF762A9D020,?,?,?,?,?,00007FF762A9D129), ref: 00007FF762A9D08A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorFileLastPointer
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2976181284-0
                                                                                                                                                                                                                                                            • Opcode ID: fb6a81950565da05b050a92576ed7c02e19ce8787ed1f1a96796d90f6b6408b2
                                                                                                                                                                                                                                                            • Instruction ID: 7ac58a39d0dd6aa29dc396bf9e43602a6ea6e79eb812604a8c77b92933ef2d2f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fb6a81950565da05b050a92576ed7c02e19ce8787ed1f1a96796d90f6b6408b2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6711E661A18A81C1DF90AB26A800469E361AB40BF4FA40331EE7E0B7D4CEFCD441C754
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • FileTimeToSystemTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF762A967F5), ref: 00007FF762A96913
                                                                                                                                                                                                                                                            • SystemTimeToTzSpecificLocalTime.KERNELBASE(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF762A967F5), ref: 00007FF762A96929
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Time$System$FileLocalSpecific
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1707611234-0
                                                                                                                                                                                                                                                            • Opcode ID: 2039fd83e8b56068fe4c14b51341d05702151df0dd8c41e9036d506d0e0dfe63
                                                                                                                                                                                                                                                            • Instruction ID: cf9d2066d2f6ded0be1c5200a6034594c5ff8a7fe22ee8552617b986f598df7c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2039fd83e8b56068fe4c14b51341d05702151df0dd8c41e9036d506d0e0dfe63
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F8116331A1C642C5EF945B15A41157AF760FF41B61FA00235EEAD41AE4EFECD404CB50
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • RtlFreeHeap.NTDLL(?,?,?,00007FF762AA3F92,?,?,?,00007FF762AA3FCF,?,?,00000000,00007FF762AA4495,?,?,?,00007FF762AA43C7), ref: 00007FF762A9B47A
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,00007FF762AA3F92,?,?,?,00007FF762AA3FCF,?,?,00000000,00007FF762AA4495,?,?,?,00007FF762AA43C7), ref: 00007FF762A9B484
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorFreeHeapLast
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 485612231-0
                                                                                                                                                                                                                                                            • Opcode ID: bcb6ed366288f57e679071cac10841f4f6d99062b1a4c36b0c72b5ea8c3cbe48
                                                                                                                                                                                                                                                            • Instruction ID: fbe96e18504e9ef167dd26813bcb1e76e5024e756f910ce512c3235b55687630
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bcb6ed366288f57e679071cac10841f4f6d99062b1a4c36b0c72b5ea8c3cbe48
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: FBE08C51F18A02C6FFD9BBF39C46878A2909F99B41FD08530DD0E46262DEEC6C85C630
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • CloseHandle.KERNELBASE(?,?,?,00007FF762A9B8DD,?,?,00000000,00007FF762A9B992), ref: 00007FF762A9BACE
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,00007FF762A9B8DD,?,?,00000000,00007FF762A9B992), ref: 00007FF762A9BAD8
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CloseErrorHandleLast
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 918212764-0
                                                                                                                                                                                                                                                            • Opcode ID: ee1f6f2c17bcac9912aebe9a75d3c59e1af1689cfc13c1c78b5a219ca8e97850
                                                                                                                                                                                                                                                            • Instruction ID: a0ce796d3a03291a76ce138bd3ada39696f08d231e0c8c541b0a329968850daa
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ee1f6f2c17bcac9912aebe9a75d3c59e1af1689cfc13c1c78b5a219ca8e97850
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C1219220F2868282FFD0B762A99067D92815F44BA0FA44735DE2E47BD1CEECA845C321
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: e4b37d1ac90d15cfb184970c58ebde71eef6bb39a30608cbf4500616c80da583
                                                                                                                                                                                                                                                            • Instruction ID: 88f79434331af50a67a07f9e3dcd5a841918a12e38c5f0f9787ad5234f3a7365
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e4b37d1ac90d15cfb184970c58ebde71eef6bb39a30608cbf4500616c80da583
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2441DE32D28641C7EFA4EB1A9940679B795EB59740F600135DE8E47AD0CFFDE802C761
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _fread_nolock
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 840049012-0
                                                                                                                                                                                                                                                            • Opcode ID: 68a2dc86987dac24af5686cd5d7c9792395e17dea144f7097addb336dff38475
                                                                                                                                                                                                                                                            • Instruction ID: 4c7fbfb07f36f73c3d465c305f708b70d6876cb5e6d1f401861c3836eba02737
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 68a2dc86987dac24af5686cd5d7c9792395e17dea144f7097addb336dff38475
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EE217E25F08692C6EF90BA126904BBADA41BF45BD8FC84430EE4D4A786CEFDE441C620
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: 91dc31986c532176c65ca0e3ff35a3bba52d03db3277bf6d72548c5eb48738d3
                                                                                                                                                                                                                                                            • Instruction ID: 84874aae13cdb02bb408ab9f9a6e2c680e13b27a297ce8eb451a6adb634ea059
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 91dc31986c532176c65ca0e3ff35a3bba52d03db3277bf6d72548c5eb48738d3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 73315E32E28A16C9EF917B569C41B7CA695AB48B91FE14135DE1D033D2CEFCA841C720
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: HandleModule$AddressFreeLibraryProc
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3947729631-0
                                                                                                                                                                                                                                                            • Opcode ID: 78c35fc7c6e2b8000ddfa863f9affaf41ca53d2f0572e0ba78e1a207ed009a92
                                                                                                                                                                                                                                                            • Instruction ID: fce90697fa1f0173cb382859a1086356d8cf3bd684d1f537fb623d8dca0e6bb1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 78c35fc7c6e2b8000ddfa863f9affaf41ca53d2f0572e0ba78e1a207ed009a92
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 00218032E14605CEEF94AFA5C8406AC73A1FB04318FA50636DA6D06AC6EFB8D944C751
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: 0e1df9a836e05c53306103cf914f9f5afd0b17d2d4247778ac0f8a736a470cc7
                                                                                                                                                                                                                                                            • Instruction ID: 20248e233f184371a5712d859e2842770601669a1b1d3537780b3c0ffca81ed0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0e1df9a836e05c53306103cf914f9f5afd0b17d2d4247778ac0f8a736a470cc7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 12111021E28642C1EFA1AF529801A79E254AF45F80FE44431EE4C57B95CFFDDC51CBA0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: 705a0604598582430d769309be7d52bb613e0b4e097a3a0cc12fb03a34ef158b
                                                                                                                                                                                                                                                            • Instruction ID: ad583caaac7db2ab435ab9ec2b3325fc03c19c3f1d657cb3707413cc1e85eb8b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 705a0604598582430d769309be7d52bb613e0b4e097a3a0cc12fb03a34ef158b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 58218632A18642C6DFE19F19D84077EB6A1AF84B94FA44234DE5D4BAD9DFBCD400CB50
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: 43297e0cb54a728217cf8f13d9f8c23c45e2da10c33361e46a2ef0799771412d
                                                                                                                                                                                                                                                            • Instruction ID: 7d693c7e58ef75422805ef6c5412646471fb603d7a1c6f85e5ab44085a8fe90a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 43297e0cb54a728217cf8f13d9f8c23c45e2da10c33361e46a2ef0799771412d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 11018E21A18742C0EF84AB529801879E694AF95FE0FD88635DE6C53BDADEFCD411C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • __scrt_dllmain_crt_thread_attach.LIBCMT ref: 00007FF762A8C3F0
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A8CE18: __vcrt_uninitialize_ptd.LIBVCRUNTIME ref: 00007FF762A8CE20
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A8CE18: __vcrt_uninitialize_locks.LIBVCRUNTIME ref: 00007FF762A8CE25
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: __scrt_dllmain_crt_thread_attach__vcrt_uninitialize_locks__vcrt_uninitialize_ptd
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1208906642-0
                                                                                                                                                                                                                                                            • Opcode ID: ececd82fc3177ae58a022cdb863293519d79894eaec9217f5cc72d6a823b184f
                                                                                                                                                                                                                                                            • Instruction ID: d216936ecc5f379e15722228186e2a5fabcdee7f9f43f1e8d152a82aea7b3d71
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ececd82fc3177ae58a022cdb863293519d79894eaec9217f5cc72d6a823b184f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9EE09210D6D642D1FFEC36611446AB9C6829F25344ED006B5DD8A921C39DCD2457D935
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • HeapAlloc.KERNEL32(?,?,00000000,00007FF762A9C22A,?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392), ref: 00007FF762A9FE59
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AllocHeap
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4292702814-0
                                                                                                                                                                                                                                                            • Opcode ID: e5baedaef9e1aefb999d7e678a491e2cb8f7af630fb86e3f47b81283e20e243b
                                                                                                                                                                                                                                                            • Instruction ID: 80d014f22d4a13340f6b0e463828d1d5049597aa24ec4397291e988008084972
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e5baedaef9e1aefb999d7e678a491e2cb8f7af630fb86e3f47b81283e20e243b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F8F0AF10F29207C5FFD57A579D01BB4D2884F48B80FA80038ED0E8A382EEDCA940CA30
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • HeapAlloc.KERNEL32(?,?,?,00007FF762A90268,?,?,?,00007FF762A918D2,?,?,?,?,?,00007FF762A94595), ref: 00007FF762A9E702
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AllocHeap
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4292702814-0
                                                                                                                                                                                                                                                            • Opcode ID: c4f21c11c5720e62b677d9e99b1ce174dfbed18f849e52640c9a6f6ea7657029
                                                                                                                                                                                                                                                            • Instruction ID: 3fe81cb076e96ff65fb46a50b13187af271a4dc52c9bc35d42b5432d0d988f56
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c4f21c11c5720e62b677d9e99b1ce174dfbed18f849e52640c9a6f6ea7657029
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 23F05E11F2C202C5FFE83BA35E41A75D2806F447A1FA80A31EE2E452C3EEDDA840C631
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84C50
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84C62
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84C99
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84CAB
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84CC4
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84CD6
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84CEF
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D01
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D1D
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D2F
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D4B
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D5D
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D79
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D8B
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84DA7
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84DB9
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84DD5
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84DE7
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AddressErrorLastProc
                                                                                                                                                                                                                                                            • String ID: Failed to get address for %hs$GetProcAddress$PyConfig_Clear$PyConfig_InitIsolatedConfig$PyConfig_Read$PyConfig_SetBytesString$PyConfig_SetString$PyConfig_SetWideStringList$PyErr_Clear$PyErr_Fetch$PyErr_NormalizeException$PyErr_Occurred$PyErr_Print$PyErr_Restore$PyEval_EvalCode$PyImport_AddModule$PyImport_ExecCodeModule$PyImport_ImportModule$PyMarshal_ReadObjectFromString$PyMem_RawFree$PyModule_GetDict$PyObject_CallFunction$PyObject_CallFunctionObjArgs$PyObject_GetAttrString$PyObject_SetAttrString$PyObject_Str$PyPreConfig_InitIsolatedConfig$PyRun_SimpleStringFlags$PyStatus_Exception$PySys_GetObject$PySys_SetObject$PyUnicode_AsUTF8$PyUnicode_Decode$PyUnicode_DecodeFSDefault$PyUnicode_FromFormat$PyUnicode_FromString$PyUnicode_Join$PyUnicode_Replace$Py_DecRef$Py_DecodeLocale$Py_ExitStatusException$Py_Finalize$Py_InitializeFromConfig$Py_IsInitialized$Py_PreInitialize
                                                                                                                                                                                                                                                            • API String ID: 199729137-653951865
                                                                                                                                                                                                                                                            • Opcode ID: 91fe38e706475bc85e8e17d1603b2dd44d209342b91b11e5c33006422c226cfa
                                                                                                                                                                                                                                                            • Instruction ID: 7abf8af8175c20e9390d54b42aea7487db1db7f6c9c2ad26f927efba829dd3e6
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 91fe38e706475bc85e8e17d1603b2dd44d209342b91b11e5c33006422c226cfa
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1C22AD60A0DF07D5FFD5BB64A855DB4A3A4AF48781BC41435DC8E06A60EFFCA489C2B0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
                                                                                                                                                                                                                                                            • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                                                                                                                                                                                                                                                            • API String ID: 808467561-2761157908
                                                                                                                                                                                                                                                            • Opcode ID: d700f69ad9a83803b0d0e637264b1b7e22121a30603610bb88393cfb8a3bc4ed
                                                                                                                                                                                                                                                            • Instruction ID: 2f8fdb874d9891299651fbade8a61628f12b83a870e6a7e452bdc3e0fbb20a16
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d700f69ad9a83803b0d0e637264b1b7e22121a30603610bb88393cfb8a3bc4ed
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CDB2C072E18282CBEFE59E68D440BF9A7A1FF54784F905135DE0957E84DBF8A900CB90
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3140674995-0
                                                                                                                                                                                                                                                            • Opcode ID: 89357c2c4ffda8ae13225540be7c458f51fcd4783b393db7419e501aec0a0031
                                                                                                                                                                                                                                                            • Instruction ID: efe89910f99139dbc544f78613985335f98e336b09a4550045fc1da7c2ae6201
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 89357c2c4ffda8ae13225540be7c458f51fcd4783b393db7419e501aec0a0031
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 89312F72605B81C6EBA4AF60E8407E9B365FB84744F84453ADE8E47B94DFBCD548C720
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1239891234-0
                                                                                                                                                                                                                                                            • Opcode ID: 2c2a6f2487acec397f330098253e2a7329acffa396285c7b3dfee245a17751bc
                                                                                                                                                                                                                                                            • Instruction ID: 0ee70c03c37c685bc58152339bc283b330ecea846c41a4297f98c464bf855779
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2c2a6f2487acec397f330098253e2a7329acffa396285c7b3dfee245a17751bc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B7317F32618F81C6DBA0DB25E8406AEB3A4FB88754F900636EE8D43B94DFBCD545CB50
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileFindFirst_invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2227656907-0
                                                                                                                                                                                                                                                            • Opcode ID: ccac9e585c27fa031d1f88e05c20b38684cf4203d2ca8c6846fc05bcbc68a6e8
                                                                                                                                                                                                                                                            • Instruction ID: 5203971036a1b96dcfa82c92831dbca9b5155f39020d50b039cc4f68b6419e7a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ccac9e585c27fa031d1f88e05c20b38684cf4203d2ca8c6846fc05bcbc68a6e8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F4B1B322B18692C1EFE0EF229800AB9A351EF54BD4F944132DE4E07E95DEFCE851C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2933794660-0
                                                                                                                                                                                                                                                            • Opcode ID: d5122b7aff0e10d146bffe79506b726acaac58846df22bdc99709fd59aa8d240
                                                                                                                                                                                                                                                            • Instruction ID: a2e53720e4fff574850e26a6f65e87a3294146c8e65ef68f6fa3dc93d9ebcd2a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d5122b7aff0e10d146bffe79506b726acaac58846df22bdc99709fd59aa8d240
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9B110D22B54F0189EF809B60E8546A873A4FB19758F441E35DE6D46BA4DFB8D158C290
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpy_s
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1502251526-0
                                                                                                                                                                                                                                                            • Opcode ID: b41cb84a548d2e61bdeb7bb10330278f5fecde395d7a0ce6ff99175555b28b3c
                                                                                                                                                                                                                                                            • Instruction ID: ca17d8c5b407aac4cdd945a334b42fde6ff09a66e48b76660abb08d18351fec1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b41cb84a548d2e61bdeb7bb10330278f5fecde395d7a0ce6ff99175555b28b3c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B0C10772B18286C7DBA4DF59A044A6AF791FB84B84F848135DF4E43B44DBBDE805CB84
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ExceptionRaise_clrfp
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 15204871-0
                                                                                                                                                                                                                                                            • Opcode ID: e29282b711dd5704c0e64fe7638cddbeeb7149a3015151b68882fd3146651568
                                                                                                                                                                                                                                                            • Instruction ID: d9258f239707b5345236fc714356d834655bed2b6545c9e3ac6550ad9882022a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e29282b711dd5704c0e64fe7638cddbeeb7149a3015151b68882fd3146651568
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9DB15773600B88CBEB95CF29C842768BBF1FB44B48F148821DA5D83BA5CBB9D851C751
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: $
                                                                                                                                                                                                                                                            • API String ID: 0-227171996
                                                                                                                                                                                                                                                            • Opcode ID: 5ebab5a2817f928350dc9776a3da4b540f16bc97e78530f340af468d76ff9f5e
                                                                                                                                                                                                                                                            • Instruction ID: 46745b131377c5855e22eebef7adbadfc1f9b1b50b2c35208b0fbccb4c1f9355
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5ebab5a2817f928350dc9776a3da4b540f16bc97e78530f340af468d76ff9f5e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7FE1B472E28646C2EFA8AF26885093DA3A0FB45B48FB44135CE2E07794DFE9DC51C710
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: e+000$gfff
                                                                                                                                                                                                                                                            • API String ID: 0-3030954782
                                                                                                                                                                                                                                                            • Opcode ID: ab39e04084c8b9065030c447a5361eb1aff85978d5a2f70618a83e2e92251626
                                                                                                                                                                                                                                                            • Instruction ID: f0ba0451c90eb880e21dfe0fe9c0366e39030e2511a5fc9a116a1301accb0415
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ab39e04084c8b9065030c447a5361eb1aff85978d5a2f70618a83e2e92251626
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D9518C22F282C586EB609A36DC00B69F795E744B94FA88235DF6C87AC5DEFDD844C710
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentFeaturePresentProcessProcessor
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1010374628-0
                                                                                                                                                                                                                                                            • Opcode ID: de90d4660cad73c020d10a8b6ecdb18ed9fa62073eb22c4578e43967cc91730a
                                                                                                                                                                                                                                                            • Instruction ID: f2e291aa8eba5525966af243bd051b5efb9f7791a52da701bdb72304baf45360
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: de90d4660cad73c020d10a8b6ecdb18ed9fa62073eb22c4578e43967cc91730a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C502BD21F1D642C0EFE5FB169801A79E284AF41B90FD44635DE1D46BE2DEFDA801D3A0
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: gfffffff
                                                                                                                                                                                                                                                            • API String ID: 0-1523873471
                                                                                                                                                                                                                                                            • Opcode ID: 1e22957b1159dd03df7ccd337d5a67203babfefd7ac1e182ea12ea91d3eef3d6
                                                                                                                                                                                                                                                            • Instruction ID: b712a1767f697282d67a10ee32327ef4c69bf846b92b76149fc7eacdaa03bc57
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1e22957b1159dd03df7ccd337d5a67203babfefd7ac1e182ea12ea91d3eef3d6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 33A16962F18785C6EF61DF2A9900BA9BB94FB50B84F508132DE8D47786DEBDE801C710
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: TMP
                                                                                                                                                                                                                                                            • API String ID: 3215553584-3125297090
                                                                                                                                                                                                                                                            • Opcode ID: 2d09a8d0b3f9f3e3f4726bcb3549591c54293473ccc366ec5b1b4d61c621e7ad
                                                                                                                                                                                                                                                            • Instruction ID: 1f25bb7abbcf079ad9ef99a22b9c26e78b8a3f98d88a7bae86557122504ca75a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2d09a8d0b3f9f3e3f4726bcb3549591c54293473ccc366ec5b1b4d61c621e7ad
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 23519E11F28203D5EFE4BB275E1197AD2916F85B84FA88538DD0D47B96EEFDE801C220
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: HeapProcess
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 54951025-0
                                                                                                                                                                                                                                                            • Opcode ID: b79ea0c05b8e708bf2e7ff1fe6aa0946c24d08db99ce40c7e012d78a6a9acfe9
                                                                                                                                                                                                                                                            • Instruction ID: 787bc199b7dcc833bfb41adf391553067036cd4b548706d942e715920cc33ea5
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b79ea0c05b8e708bf2e7ff1fe6aa0946c24d08db99ce40c7e012d78a6a9acfe9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 48B09220F17A02C6EFC83B516C82614A3E4BF48700FD44038C84D51330DEAC21A6DB20
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: a25825d834791a15779abc5a96815a53d20fd0a8b1de7024d724f2c7a0ffd609
                                                                                                                                                                                                                                                            • Instruction ID: 6e948322621ae0017303c58c245b058e79b9569f63c94375e799b03264b3137b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a25825d834791a15779abc5a96815a53d20fd0a8b1de7024d724f2c7a0ffd609
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7BE1B426D28242C6EFA4AA26894093DB7A1FB45B44FB44235CE2D077D8CEFDEC55C760
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 92f5019cce735186dcbe47a7940729bb5e8d7af8c1d6157f075a5e7b95ae45a8
                                                                                                                                                                                                                                                            • Instruction ID: 3f996fabfeb3b1d60f11afe9a7ab8dabc225af209a4e74b653399d9535cd54b3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 92f5019cce735186dcbe47a7940729bb5e8d7af8c1d6157f075a5e7b95ae45a8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6BE1D832D28602C5EFE4AA2AC954BB8A7B1EB45754FB48235CE8D076D5CFE9DC41C360
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 86da56c12cd563bcad921fbd71c05d3fa176844b52d15b5090a52c27ad8a5c54
                                                                                                                                                                                                                                                            • Instruction ID: db0eeb4eb36d451efe3e049fe7b334580819656ec4780429947b31944505a6be
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 86da56c12cd563bcad921fbd71c05d3fa176844b52d15b5090a52c27ad8a5c54
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A6D10E21E28642C5EFE8AA2B8950ABDA7B0EF05B48FB44135DE4D47694CFF9DC45C710
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 8e0142d1de63ac36c46e431d0d75baaff102e1c1a7ac2c303afc5037c5988706
                                                                                                                                                                                                                                                            • Instruction ID: 6bc06cf4811981844faad95fd8a479687c3ff3dbf0c29d2a16c437a66f104690
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8e0142d1de63ac36c46e431d0d75baaff102e1c1a7ac2c303afc5037c5988706
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 64C1B9726141E18BD389EB29E46957B73E1F798389BC4803ADF8B47B85CA3CE014D711
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: b5780ef2d000dcd486574e33efb2770a379a55a34775bc5a7b80e7b31bbd7158
                                                                                                                                                                                                                                                            • Instruction ID: 06a358413bfe7a1fecd86ded25bcf7724f451b8315b86486b33bfe462656f32f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b5780ef2d000dcd486574e33efb2770a379a55a34775bc5a7b80e7b31bbd7158
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E6B1A172D28645C5EBA4AF2AC86067CBBA0E745B48FA44135CF4D47B95CFE9DC40C760
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 56ef1490d9aa7cb50fdbcb208ea1e35327a83dacbd264ffe23c56c6782292f60
                                                                                                                                                                                                                                                            • Instruction ID: 690b274f139c42cfa940a8e59f8adcbf83c7e7f1dab09e4594ecb425a62fb105
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 56ef1490d9aa7cb50fdbcb208ea1e35327a83dacbd264ffe23c56c6782292f60
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E7B16072D28646C9EBA49F2A885063CBBA0E749B48FB44135CE4D47B95CFE9D841C760
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 2a05c6059b1d422c1c0961fd67960772ff2ba502e6a05041136868912dff4d23
                                                                                                                                                                                                                                                            • Instruction ID: b63d19831b57a15bb9b1d2d0134fc0ba97a9a1ab312fa8c4a8438047073f6f09
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2a05c6059b1d422c1c0961fd67960772ff2ba502e6a05041136868912dff4d23
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3A81D972E28781C6DFE4DB1A9840769B690FB45794FA04239EE9D87B95CFBDD800C710
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: eef01635753a3689cfd7199ced0fb7e0b5b43189aa21453eecf28f9410e22187
                                                                                                                                                                                                                                                            • Instruction ID: f080e976045c45fe067d47db049c95025d4ca061ff69f28d33e6b0771c47a5fe
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: eef01635753a3689cfd7199ced0fb7e0b5b43189aa21453eecf28f9410e22187
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8D61DE22F18251C5FFE5E6298C40A7ED681EF44760F944235DE1D4AED9DEEDD840C760
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 27099d1c67046ba5536a5c52bb1b19252402c8bb4a5167aa336477e7b6d5f807
                                                                                                                                                                                                                                                            • Instruction ID: bfb727e6a0a022db59f018b1fae6d84e02210da18e23e35f35a5be1c806e5a02
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 27099d1c67046ba5536a5c52bb1b19252402c8bb4a5167aa336477e7b6d5f807
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 73516176E34651C2EFA49B2AC440A39B3B4EB89B68F744131CE4D17794CBAAEC43C750
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 8e69dfdcc94a0aa650623f7423aa354004c1f2fa01d5c1268249020d4c21f447
                                                                                                                                                                                                                                                            • Instruction ID: 7753f143febd9fb69e8eae67f316dd269f6608ba6bf4535b354b713cb43125b5
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8e69dfdcc94a0aa650623f7423aa354004c1f2fa01d5c1268249020d4c21f447
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0B519736E24652C6EBA49B2AC440638B3A5EB44B58F748231CE4D17794DFFAEC43C790
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 68a3f5aab59b2fac328bd6ba34d5b1cd1fa94c6914f84dc4a79da3b9d8ff9a98
                                                                                                                                                                                                                                                            • Instruction ID: da132678eed42977f01f2f7e3022429b23ed7fd6bec35e5f2b99c03f4bf71dc2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 68a3f5aab59b2fac328bd6ba34d5b1cd1fa94c6914f84dc4a79da3b9d8ff9a98
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2E51A436E28651C6EBA49B2AC450B38B3A4EB44B98F744132DE4D17794CBFAED43C750
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 7c9c7dfd85d7e05c9dc9b7e40d932aad9843605f203f1a6a08d3cc10701c718b
                                                                                                                                                                                                                                                            • Instruction ID: 6a0900678b4c73008541fe55a08160399a09546b0429b3b5973c5020ed9e6676
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7c9c7dfd85d7e05c9dc9b7e40d932aad9843605f203f1a6a08d3cc10701c718b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CB51B536E38651C2EBA49B1AC840A39B7A4EB44B58FB44135CE4D47794CBBAEC42CB50
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 7710b6301a9c53c0f35ccf6fc131232db227f89fb6367f1206a3fe51f4b04988
                                                                                                                                                                                                                                                            • Instruction ID: ef9de8a0ad7e498f2307caea13009d2c5e95450010bae47cfebb4afe304bafa3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7710b6301a9c53c0f35ccf6fc131232db227f89fb6367f1206a3fe51f4b04988
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 58519736E28651C6EBA49B2AC440A3877A4EB44B58FB94131CF4D17794DFFAEC42C790
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 3b300af1d1946d5df55db44b3d4e0876ae34829a82d49cb6751e26c04e9c1898
                                                                                                                                                                                                                                                            • Instruction ID: e4917305441222fd0016c1bda6524eaa704c2064b65fd465ce9c16619c052e00
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3b300af1d1946d5df55db44b3d4e0876ae34829a82d49cb6751e26c04e9c1898
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 23519336E38651C6EBA49B2AC440A29B7A4EB45F98F744131CE4C17794DBFAEC42C750
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: dde3b7cfbcf26fc8d7513faefc9a59c4b8821272907dfbb35b6db6355186da00
                                                                                                                                                                                                                                                            • Instruction ID: abf12634170695901c05136355cfaba1fd1a3294142f95404ec05f43c406e6a9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: dde3b7cfbcf26fc8d7513faefc9a59c4b8821272907dfbb35b6db6355186da00
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2341A592C29B8B84EFD5991F4E04EB4A6949F12FA0DF81270CCA9173C7CDCD6D86C1A0
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorFreeHeapLast
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 485612231-0
                                                                                                                                                                                                                                                            • Opcode ID: 7a7ebbd17873febb15e29de35626f23177de76f7dba359f1eda69606ccc1bea3
                                                                                                                                                                                                                                                            • Instruction ID: afaec6ee44192dc56b17019e130c8ad95ae783c238bb310c9db24579e0489473
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7a7ebbd17873febb15e29de35626f23177de76f7dba359f1eda69606ccc1bea3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 23410463B24A54C2EF84DF6AD914569B3A1BB48FD0B999033EE0D97B54DEBCD441C300
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 3b4b82ba6feb1f2c625fcdd7b78fc6310e7e433b3778e25011fb45a65c2c329c
                                                                                                                                                                                                                                                            • Instruction ID: 2c6f95841e93658b05c0bcb812ebc4e116beb473dce27b403cbc4ffca1bd5e08
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3b4b82ba6feb1f2c625fcdd7b78fc6310e7e433b3778e25011fb45a65c2c329c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8A311632B18B42C6EF94AF26694053DB694AF84B90F648238EE5D53B96DFFCD401C714
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 47026fad3db46e1691e12129f37de500b9ca6af24d2cbfa86880e77cbf706e66
                                                                                                                                                                                                                                                            • Instruction ID: 411d1844d6e1333f32b1bcc63a0fdd61e71ca0660365e21e84fd96312864d61d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 47026fad3db46e1691e12129f37de500b9ca6af24d2cbfa86880e77cbf706e66
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 36F044717282958ADBD49F29A452A2977E0F7583C0B908079E98987B14D6FC9051CF14
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 0095cffb8fe81db1077c877ec2d194bac0958fa6bcac770c2119ba444bc36b37
                                                                                                                                                                                                                                                            • Instruction ID: feaac05681b768b52e591b9260f281f1a70fd219262b5577335e2f306bdfdea2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0095cffb8fe81db1077c877ec2d194bac0958fa6bcac770c2119ba444bc36b37
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 84A00161948C42D0FBC8AB00A951860A261BB50300B800132D85E514A1AFECA804C660
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AddressErrorLastProc
                                                                                                                                                                                                                                                            • String ID: Failed to get address for %hs$GetProcAddress$Tcl_Alloc$Tcl_ConditionFinalize$Tcl_ConditionNotify$Tcl_ConditionWait$Tcl_CreateInterp$Tcl_CreateObjCommand$Tcl_CreateThread$Tcl_DeleteInterp$Tcl_DoOneEvent$Tcl_EvalEx$Tcl_EvalFile$Tcl_EvalObjv$Tcl_Finalize$Tcl_FinalizeThread$Tcl_FindExecutable$Tcl_Free$Tcl_GetCurrentThread$Tcl_GetObjResult$Tcl_GetString$Tcl_GetVar2$Tcl_Init$Tcl_JoinThread$Tcl_MutexFinalize$Tcl_MutexLock$Tcl_MutexUnlock$Tcl_NewByteArrayObj$Tcl_NewStringObj$Tcl_SetVar2$Tcl_SetVar2Ex$Tcl_ThreadAlert$Tcl_ThreadQueueEvent$Tk_GetNumMainWindows$Tk_Init
                                                                                                                                                                                                                                                            • API String ID: 199729137-3427451314
                                                                                                                                                                                                                                                            • Opcode ID: 3ce57ac688b021c07c17bb9d18c3d2db368ff9ca427b7eb3b8bd4dc412038eb8
                                                                                                                                                                                                                                                            • Instruction ID: e1c8d246f559e9a750e0612fe98391ebb60e653483e83105903ed74ece7a40ca
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3ce57ac688b021c07c17bb9d18c3d2db368ff9ca427b7eb3b8bd4dc412038eb8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C5028164A19F07D5FFD9BB64A915DB4A3A0AF04B45BC40036CC4E0AB64EFFDA449C3A0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A88950: MultiByteToWideChar.KERNEL32(?,?,?,00007FF762A83A04,00000000,00007FF762A81965), ref: 00007FF762A88989
                                                                                                                                                                                                                                                            • ExpandEnvironmentStringsW.KERNEL32(00000000,00007FF762A87CF7,FFFFFFFF,00000000,?,00007FF762A83101), ref: 00007FF762A8766C
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ByteCharEnvironmentExpandMultiStringsWide
                                                                                                                                                                                                                                                            • String ID: %.*s$CreateDirectory$LOADER: failed to convert runtime-tmpdir to a wide string.$LOADER: failed to create runtime-tmpdir path %ls!$LOADER: failed to expand environment variables in the runtime-tmpdir.$LOADER: failed to obtain the absolute path of the runtime-tmpdir.$LOADER: runtime-tmpdir points to non-existent drive %ls (type: %d)!$\
                                                                                                                                                                                                                                                            • API String ID: 2001182103-930877121
                                                                                                                                                                                                                                                            • Opcode ID: b30a72d36afce0cd8273f42ba79e9994321ef07812378637c8fd6fc8c555bb8b
                                                                                                                                                                                                                                                            • Instruction ID: b4271627a437d89585abc2372587c93d97997c25836a19f8f5f531160c801905
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b30a72d36afce0cd8273f42ba79e9994321ef07812378637c8fd6fc8c555bb8b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 89517515B28642C1FFD4FB25EC51EBAE251AF44780FC40436DE4E86A95EEECE504C760
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: LongWindow$BlockCreateErrorLastReasonShutdown
                                                                                                                                                                                                                                                            • String ID: Needs to remove its temporary files.
                                                                                                                                                                                                                                                            • API String ID: 3975851968-2863640275
                                                                                                                                                                                                                                                            • Opcode ID: 44e53fe94581f3919e9549e222624ce8134aca65504236f29db41f4538cf5799
                                                                                                                                                                                                                                                            • Instruction ID: 4eb117b721ab040c573d7edb6ee92b7983f8efd8eaa6d73bb7460c030d6ba932
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 44e53fe94581f3919e9549e222624ce8134aca65504236f29db41f4538cf5799
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2921A665B08E42C1EFC5AB7AA844979A390EF88B90F884130DE5D477A4DEECD584C260
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: -$:$f$p$p
                                                                                                                                                                                                                                                            • API String ID: 3215553584-2013873522
                                                                                                                                                                                                                                                            • Opcode ID: 65d4a0ffdc8e7253b8e60b637b85ac8f97459ea152ba9c8238927d2e88e0f15e
                                                                                                                                                                                                                                                            • Instruction ID: c69d4f291705d6ff7ab9b8d735c96ac5ae38cccaefd22a59ce2122ab82b09502
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 65d4a0ffdc8e7253b8e60b637b85ac8f97459ea152ba9c8238927d2e88e0f15e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AB1264A1E29143C6FFA47A169C44A79F691FB40750FE44135DA9A4A9C4DBFCEC80CB34
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: f$f$p$p$f
                                                                                                                                                                                                                                                            • API String ID: 3215553584-1325933183
                                                                                                                                                                                                                                                            • Opcode ID: fc8e2330ab6ced16bd3d959f6bc8057a9fc686b659d09149717256120edd57c1
                                                                                                                                                                                                                                                            • Instruction ID: 770d245e770d9e879ba047ca41ee4f153227c573097134e8f8813fb8bfa91aaf
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fc8e2330ab6ced16bd3d959f6bc8057a9fc686b659d09149717256120edd57c1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 62126261E2C143C6FFA06A169854A7AF691FB50794FE44135DE8A466C4DFFCEC84CB20
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$fread$fseek$malloc
                                                                                                                                                                                                                                                            • API String ID: 2050909247-3659356012
                                                                                                                                                                                                                                                            • Opcode ID: bc104690f901513b1fd297f9374d1419b47e49020e5dea6dd5e3d26072ab1438
                                                                                                                                                                                                                                                            • Instruction ID: ea609a58c6b68c695cb183e1cf4a81e05b43a84f91ebbb45f8b887f9e494135a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bc104690f901513b1fd297f9374d1419b47e49020e5dea6dd5e3d26072ab1438
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 73415722A08692C6EF80FB129841AB9E395AF48BC4FD44436ED5C07B96DEFCE405C760
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$fread$fseek$malloc
                                                                                                                                                                                                                                                            • API String ID: 2050909247-3659356012
                                                                                                                                                                                                                                                            • Opcode ID: c8d8f755826b470e7016656f4a1eb38017cfb54accab5b7c39e5ef29c0382862
                                                                                                                                                                                                                                                            • Instruction ID: 53c96c7e063e2e1755c8f92174668801f7bcc3ac32aabbb1a1347e2497013621
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c8d8f755826b470e7016656f4a1eb38017cfb54accab5b7c39e5ef29c0382862
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 25416D22A08682C6EF85FF219441AB9E391EF48B94FD44432ED5D07A99DEFCE901C760
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
                                                                                                                                                                                                                                                            • String ID: csm$csm$csm
                                                                                                                                                                                                                                                            • API String ID: 849930591-393685449
                                                                                                                                                                                                                                                            • Opcode ID: 7d7d5a635fcd63c536a58b816f4712f1a96a9e43b0d550c3d6dd02e630e8922c
                                                                                                                                                                                                                                                            • Instruction ID: 4fb04ca3c646bade232d5dfb056e40162085506b3b525d85fb3244083f28e421
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7d7d5a635fcd63c536a58b816f4712f1a96a9e43b0d550c3d6dd02e630e8922c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: ECD18F32A08B42C6EFA0AB659540BADB7A0FB45788F900136EE4D57B95DFBCE481C711
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,00007FF762A82AC6,?,00007FF762A82BC5), ref: 00007FF762A82360
                                                                                                                                                                                                                                                            • FormatMessageW.KERNEL32(?,?,?,?,?,?,?,?,00007FF762A82AC6,?,00007FF762A82BC5), ref: 00007FF762A8241A
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentFormatMessageProcess
                                                                                                                                                                                                                                                            • String ID: %ls$%ls: $<FormatMessageW failed.>$[PYI-%d:ERROR]
                                                                                                                                                                                                                                                            • API String ID: 27993502-4247535189
                                                                                                                                                                                                                                                            • Opcode ID: 92e20a795bf73765402ca9ec7783ee5ad9f8f927f89bd5dd19570627e0bc01fb
                                                                                                                                                                                                                                                            • Instruction ID: 66952ce7c9cbe640506a4bce4fc7b276847041c5182a4b3f933631286dc01645
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 92e20a795bf73765402ca9ec7783ee5ad9f8f927f89bd5dd19570627e0bc01fb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E031B562B08A4181EBA0BB65B814AFAE251FF84BD5F800135EF8D53B59DEFCD506C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • LoadLibraryExW.KERNEL32(?,?,?,00007FF762A8D50A,?,?,?,00007FF762A8D1FC,?,?,?,00007FF762A8CDF9), ref: 00007FF762A8D2DD
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,00007FF762A8D50A,?,?,?,00007FF762A8D1FC,?,?,?,00007FF762A8CDF9), ref: 00007FF762A8D2EB
                                                                                                                                                                                                                                                            • LoadLibraryExW.KERNEL32(?,?,?,00007FF762A8D50A,?,?,?,00007FF762A8D1FC,?,?,?,00007FF762A8CDF9), ref: 00007FF762A8D315
                                                                                                                                                                                                                                                            • FreeLibrary.KERNEL32(?,?,?,00007FF762A8D50A,?,?,?,00007FF762A8D1FC,?,?,?,00007FF762A8CDF9), ref: 00007FF762A8D383
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,?,?,00007FF762A8D50A,?,?,?,00007FF762A8D1FC,?,?,?,00007FF762A8CDF9), ref: 00007FF762A8D38F
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Library$Load$AddressErrorFreeLastProc
                                                                                                                                                                                                                                                            • String ID: api-ms-
                                                                                                                                                                                                                                                            • API String ID: 2559590344-2084034818
                                                                                                                                                                                                                                                            • Opcode ID: ec1d8984956c5f4cef63aabdc1ab3d005d502d88db624b4fbd9ceb099b80f4f4
                                                                                                                                                                                                                                                            • Instruction ID: 23d55cf940a4fdfde352bc3151eb89f74e18843ff0b99df9127ee714e4cee9d5
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ec1d8984956c5f4cef63aabdc1ab3d005d502d88db624b4fbd9ceb099b80f4f4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 69319221B1AE42D1EF91BB22A800A79A394FF49BA0F990536DD5D4B784DFFCE445C320
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: Failed to load Python DLL '%ls'.$LoadLibrary$Path of Python shared library (%s) and its name (%s) exceed buffer size (%d)$Path of ucrtbase.dll (%s) and its name exceed buffer size (%d)$Reported length (%d) of Python shared library name (%s) exceeds buffer size (%d)$ucrtbase.dll
                                                                                                                                                                                                                                                            • API String ID: 2050909247-2434346643
                                                                                                                                                                                                                                                            • Opcode ID: bdf35f00908a663c977b541a1155eb73016cf86817925c7fc1db5880fcbaeba1
                                                                                                                                                                                                                                                            • Instruction ID: 21d43796e5575746311a1b9b4121ad6fd18e66cdcd534b648317296cc5c87bbe
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bdf35f00908a663c977b541a1155eb73016cf86817925c7fc1db5880fcbaeba1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B1416C31A18A86D1EF91EB20E4549E9E355FF44384FC00132EE9E43696EEFCE605C7A0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Value$ErrorLast
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2506987500-0
                                                                                                                                                                                                                                                            • Opcode ID: 6cd12d297b2340e5ffa7c7392ce0e4cdced9a85fa0896577ca3510b685e0d80d
                                                                                                                                                                                                                                                            • Instruction ID: 69408a4eb412dcb39a5b403c41a15c5ce230bb2acaa0d94ef8d2aed8ebf4fb05
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6cd12d297b2340e5ffa7c7392ce0e4cdced9a85fa0896577ca3510b685e0d80d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D4213920F1CB42C2FFE5B7225A41A79D2424F487A0FA44735DD2E1ABD6DEECAC45C660
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
                                                                                                                                                                                                                                                            • String ID: CONOUT$
                                                                                                                                                                                                                                                            • API String ID: 3230265001-3130406586
                                                                                                                                                                                                                                                            • Opcode ID: 09a7ef29c2f791f79e4b414a588c98caae924e0a86b8d7fe5631f15f3a619b4d
                                                                                                                                                                                                                                                            • Instruction ID: eb12f1851bcb1c9878626ede341390a1ec5c6537cb24efeb3d48ad4405937d90
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 09a7ef29c2f791f79e4b414a588c98caae924e0a86b8d7fe5631f15f3a619b4d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 45118461718A41C6EBD0AB52E844729B2A0FF88BE4F904234DD5D47B94CFFCD444C790
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcess.KERNEL32(FFFFFFFF,?,?,00000000,00007FF762A88706), ref: 00007FF762A879E2
                                                                                                                                                                                                                                                            • K32EnumProcessModules.KERNEL32(?,?,00000000,00007FF762A88706), ref: 00007FF762A87A39
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A88950: MultiByteToWideChar.KERNEL32(?,?,?,00007FF762A83A04,00000000,00007FF762A81965), ref: 00007FF762A88989
                                                                                                                                                                                                                                                            • K32GetModuleFileNameExW.KERNEL32(?,?,00000000,00007FF762A88706), ref: 00007FF762A87AC8
                                                                                                                                                                                                                                                            • K32GetModuleFileNameExW.KERNEL32(?,?,00000000,00007FF762A88706), ref: 00007FF762A87B34
                                                                                                                                                                                                                                                            • FreeLibrary.KERNEL32(?,?,00000000,00007FF762A88706), ref: 00007FF762A87B45
                                                                                                                                                                                                                                                            • FreeLibrary.KERNEL32(?,?,00000000,00007FF762A88706), ref: 00007FF762A87B5A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileFreeLibraryModuleNameProcess$ByteCharCurrentEnumModulesMultiWide
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3462794448-0
                                                                                                                                                                                                                                                            • Opcode ID: e394586919bb787c5c57ed27fc0ac332066dc84938bb9692acbe845e24378f8e
                                                                                                                                                                                                                                                            • Instruction ID: ba9d769ff319d81d3f4927f3d1f1f41821441393657c6b842fe01330002a6561
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e394586919bb787c5c57ed27fc0ac332066dc84938bb9692acbe845e24378f8e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2041B366B19682C1EFB0AB12A844AAAE395FF48BC4F840135DF8D97795DEFCD501C720
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C1D7
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C20D
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C23A
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C24B
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C25C
                                                                                                                                                                                                                                                            • SetLastError.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C277
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Value$ErrorLast
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2506987500-0
                                                                                                                                                                                                                                                            • Opcode ID: 297eb830bf51183a03152683679a33ac8e7e939d0b2a29d40b44e033b6affbc9
                                                                                                                                                                                                                                                            • Instruction ID: e5af5d55bf96298790d327a77ed8d5003dbd11848b76ced79e338d94becddc0c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 297eb830bf51183a03152683679a33ac8e7e939d0b2a29d40b44e033b6affbc9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6C114C20E1CB42C2FFD4B3A65A41A79D1425F48BA0FA44735DD2E16BE6DEECA805C760
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AddressFreeHandleLibraryModuleProc
                                                                                                                                                                                                                                                            • String ID: CorExitProcess$mscoree.dll
                                                                                                                                                                                                                                                            • API String ID: 4061214504-1276376045
                                                                                                                                                                                                                                                            • Opcode ID: f90418b582b416691a14bbb2ae6c6b71f2096e7654ee2338269033ad2dc175a6
                                                                                                                                                                                                                                                            • Instruction ID: ca0ca4163430e266e0447d1206e1fbe60c4528e3ebc94023d0a33cc5d61dacc9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f90418b582b416691a14bbb2ae6c6b71f2096e7654ee2338269033ad2dc175a6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 10F0C821E18A02C2EF946B10E844B79D320EF48761FD4063ACD5E465E4CFECD444C760
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _set_statfp
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1156100317-0
                                                                                                                                                                                                                                                            • Opcode ID: bce21d2362216a5e504affcf34f2858e363de54600403cac3d1eeb36cb2ab404
                                                                                                                                                                                                                                                            • Instruction ID: 5ab8393d8190aa152b914c1b76b3254a28cfef298b930ae61bc2b0f5196844ba
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bce21d2362216a5e504affcf34f2858e363de54600403cac3d1eeb36cb2ab404
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EE115E32E58A0281FFE9312CD552B75E1E26F54364E844634ED6E06BD7CEEC6841C9A2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • FlsGetValue.KERNEL32(?,?,?,00007FF762A9B4E7,?,?,00000000,00007FF762A9B782,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9C2AF
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A9B4E7,?,?,00000000,00007FF762A9B782,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9C2CE
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A9B4E7,?,?,00000000,00007FF762A9B782,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9C2F6
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A9B4E7,?,?,00000000,00007FF762A9B782,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9C307
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A9B4E7,?,?,00000000,00007FF762A9B782,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9C318
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Value
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3702945584-0
                                                                                                                                                                                                                                                            • Opcode ID: 336e871d9fe7b9feb1d4e8714057d4483739f4a760c37d9f3dc9b8317e64e27b
                                                                                                                                                                                                                                                            • Instruction ID: a4dc2ebadb1afc0c3fde04c17fdc47dab259f9fa8ccef5eb07a43353b3505cbb
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 336e871d9fe7b9feb1d4e8714057d4483739f4a760c37d9f3dc9b8317e64e27b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 81113860E1CB42C2FFD8B3669941A7AE1425F487A0FE44735ED2D167D6DEECA805C620
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Value
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3702945584-0
                                                                                                                                                                                                                                                            • Opcode ID: 4d8455bc275ec880ad9f8951d6e4f70d9feb0184cd7bbcf1a18e1e455a1bd2fd
                                                                                                                                                                                                                                                            • Instruction ID: fb6eeae55dbbdb4ea9d8c9201b159eddf0659c53d3be8551d5598476f4d9439f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4d8455bc275ec880ad9f8951d6e4f70d9feb0184cd7bbcf1a18e1e455a1bd2fd
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DC11E650E28702C2FFD9B2664C51A79D1424F69360EF80B39DD2E196E2DDECBC49CA60
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Window$Process$ConsoleCurrentShowSleepThread
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3908687701-0
                                                                                                                                                                                                                                                            • Opcode ID: c4ce1bea477394a5bd7c29aaffed6a601c2f4b1d57d0592e327ceaa9095476a5
                                                                                                                                                                                                                                                            • Instruction ID: 01440664bf2980b55facbd88c67a1cb7ff70f10a34c1eae6f5ebd817de86c709
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c4ce1bea477394a5bd7c29aaffed6a601c2f4b1d57d0592e327ceaa9095476a5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 92016220E18B46C6EFD87B21A584839A2E1EF44BC0F845034DD8F42A54DEFDD445C760
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: verbose
                                                                                                                                                                                                                                                            • API String ID: 3215553584-579935070
                                                                                                                                                                                                                                                            • Opcode ID: 5742ae6ca51b03e9d6fd204cb41504e479b7e72b202bc53543779a715851f7d3
                                                                                                                                                                                                                                                            • Instruction ID: d9d6de414654c1455ec1742203b6785f2c7ef21095278253c6612446b08ce63e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5742ae6ca51b03e9d6fd204cb41504e479b7e72b202bc53543779a715851f7d3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4691C162E28646C1EBA1AE26DC50B7DB291AB04B94FE44136DE494B3D5DEFDEC05C330
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: UTF-16LEUNICODE$UTF-8$ccs
                                                                                                                                                                                                                                                            • API String ID: 3215553584-1196891531
                                                                                                                                                                                                                                                            • Opcode ID: 59f559b3b4a43374a67f10f227721a3fbc4a07d852e694dccd2ae9d3b54f0314
                                                                                                                                                                                                                                                            • Instruction ID: f77b89ae6c8fef886b8efcabf78bc9e3e68469457256616bdff4e2e0e0973d77
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 59f559b3b4a43374a67f10f227721a3fbc4a07d852e694dccd2ae9d3b54f0314
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B181A132E08252D5FFE4AE258111B7CB6A0AF11B84FD58035CE0A67A85CBEDE941D7A1
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
                                                                                                                                                                                                                                                            • String ID: csm
                                                                                                                                                                                                                                                            • API String ID: 2395640692-1018135373
                                                                                                                                                                                                                                                            • Opcode ID: ab412f78eb90613ff4c98a1fac2d50a5770803065215d444c3ce453a3de23157
                                                                                                                                                                                                                                                            • Instruction ID: 8b839578d54c4051ecafa202a9e52c89a6f399a9b07acbfb5e63abde33a77a4e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ab412f78eb90613ff4c98a1fac2d50a5770803065215d444c3ce453a3de23157
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0C519332B19602CADF98AF15E044E79B7A2EB44B98F914231DE4947785EFFCE841CB10
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CallEncodePointerTranslator
                                                                                                                                                                                                                                                            • String ID: MOC$RCC
                                                                                                                                                                                                                                                            • API String ID: 3544855599-2084237596
                                                                                                                                                                                                                                                            • Opcode ID: 2d0d38728c8b81eb1afee087d1255ca92539906646f1d2432080e5defd871a42
                                                                                                                                                                                                                                                            • Instruction ID: d7af30e578c9a96058b7463cdc39b83fe55648c0987b07dd193f63e56634c4de
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2d0d38728c8b81eb1afee087d1255ca92539906646f1d2432080e5defd871a42
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 18616E32908BC5C1DBA0AB25E540BAAF7A0FB95794F444635EE9D03B95DFBCE190CB10
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
                                                                                                                                                                                                                                                            • String ID: csm$csm
                                                                                                                                                                                                                                                            • API String ID: 3896166516-3733052814
                                                                                                                                                                                                                                                            • Opcode ID: 881cb4ef47e13874d43f93ad661edca9df8e178c9ea1252ba64912ddd8f944cb
                                                                                                                                                                                                                                                            • Instruction ID: ff3ff10498f315b203673806a15f8b50cb6f3702ea573d62da6cc9f0d00e01d4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 881cb4ef47e13874d43f93ad661edca9df8e178c9ea1252ba64912ddd8f944cb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0C519F32A08682C6EFB4AB219644B68F7A0FB55B94F944136EE8C57B85CFFCE450C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(FFFFFFFF,00000000,00000000,?,00000000,00007FF762A8866F), ref: 00007FF762A8226E
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: %ls$WARNING$[PYI-%d:%ls]
                                                                                                                                                                                                                                                            • API String ID: 2050909247-3372507544
                                                                                                                                                                                                                                                            • Opcode ID: 92da2cbc5b979b0862b6cfd95371d042a7d5931ee882c49d5c626b31f152fc77
                                                                                                                                                                                                                                                            • Instruction ID: 1555bf8a3fd2d24aa679b595dd03b99e05ba00b997130c612a3d8ff2a36efca4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 92da2cbc5b979b0862b6cfd95371d042a7d5931ee882c49d5c626b31f152fc77
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5921A422A19B8281EB90AB51F845AEAB354FF847C0F800135EE8D53A5ADEFCD115C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileWrite$ConsoleErrorLastOutput
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2718003287-0
                                                                                                                                                                                                                                                            • Opcode ID: fabcd4fad7fa856dcf2e9951dc7cbf89ababb6e1d40fd4369e0489b0ae7d9f25
                                                                                                                                                                                                                                                            • Instruction ID: 6bf35f70c8acc521bfa49695b1f98c02fa60a18b2b1cd4e1ff810336a8dcceea
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fabcd4fad7fa856dcf2e9951dc7cbf89ababb6e1d40fd4369e0489b0ae7d9f25
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 12D12832F18A40C9EB50EF76D8406AC77B5FB44B98B908235CE4E57B99DEB8D446C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _get_daylight$_invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: ?
                                                                                                                                                                                                                                                            • API String ID: 1286766494-1684325040
                                                                                                                                                                                                                                                            • Opcode ID: 44877219fa58a3c80076740d489941753dcdf7d4d18713102933f3384318ca38
                                                                                                                                                                                                                                                            • Instruction ID: 0059bc3c30a0a2e177d3c5686362c0ee0d3b497b74d0f44811f0438f87c8820a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 44877219fa58a3c80076740d489941753dcdf7d4d18713102933f3384318ca38
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AE41B312A18282C6EFE4AB2AD401B7A9650EF90BA4F944235EE5C06FD5DEFCD441CF50
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • _invalid_parameter_noinfo.LIBCMT ref: 00007FF762A99F82
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A9B464: RtlFreeHeap.NTDLL(?,?,?,00007FF762AA3F92,?,?,?,00007FF762AA3FCF,?,?,00000000,00007FF762AA4495,?,?,?,00007FF762AA43C7), ref: 00007FF762A9B47A
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A9B464: GetLastError.KERNEL32(?,?,?,00007FF762AA3F92,?,?,?,00007FF762AA3FCF,?,?,00000000,00007FF762AA4495,?,?,?,00007FF762AA43C7), ref: 00007FF762A9B484
                                                                                                                                                                                                                                                            • GetModuleFileNameW.KERNEL32(?,?,?,?,?,00007FF762A8C165), ref: 00007FF762A99FA0
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorFileFreeHeapLastModuleName_invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                            • API String ID: 3580290477-1435481288
                                                                                                                                                                                                                                                            • Opcode ID: 2a2f06ea51d58fd39cad35a47b9855af257a0ebd26d3c321afc8fcfaab6f6b1a
                                                                                                                                                                                                                                                            • Instruction ID: 02a1199e031b997a4e238caaeadfd03397ceba76a0f8b22a0a1ff78659e265c8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2a2f06ea51d58fd39cad35a47b9855af257a0ebd26d3c321afc8fcfaab6f6b1a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 56418032E18B12C5EF94FF26A9408B8A7A5FB44780BA44036ED4D47B56DEFDE841C260
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorFileLastWrite
                                                                                                                                                                                                                                                            • String ID: U
                                                                                                                                                                                                                                                            • API String ID: 442123175-4171548499
                                                                                                                                                                                                                                                            • Opcode ID: 57f6403a17afa6857eb93518903eebf05678db2d18f563f749b6ba14b42682ba
                                                                                                                                                                                                                                                            • Instruction ID: f3713a92358fd7d41139c798a35f3fbaecbd9df67ad5917f0a9b95c49fad62b9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 57f6403a17afa6857eb93518903eebf05678db2d18f563f749b6ba14b42682ba
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1541A462B28A41C5DBA0AF26E8447A9A7A0FB94794F904131EE8D87758DFFCD441C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(?,?,?,?,00000000,00000000,?,00000000,00007FF762A81B4A), ref: 00007FF762A82070
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: %s: %s$[PYI-%d:ERROR]
                                                                                                                                                                                                                                                            • API String ID: 2050909247-3704582800
                                                                                                                                                                                                                                                            • Opcode ID: a5f084cc36529dd82358bb6d3c03fbfc020d3d736b3f3fde6876dd26524326fa
                                                                                                                                                                                                                                                            • Instruction ID: 2a5c6b6747f0e815d533cedcb26b03b305f312fa4b68a6c5ba16a67f845a5921
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a5f084cc36529dd82358bb6d3c03fbfc020d3d736b3f3fde6876dd26524326fa
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5721F662B1868185EBA0A761BC41AF6A254BF88BD4F804131FE8D53B59DEFCD546C610
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentDirectory
                                                                                                                                                                                                                                                            • String ID: :
                                                                                                                                                                                                                                                            • API String ID: 1611563598-336475711
                                                                                                                                                                                                                                                            • Opcode ID: e405b3d95a77a686cd9e65060fb5efdbb8b04b637a4feec6827f9fe163836890
                                                                                                                                                                                                                                                            • Instruction ID: 1d1652dc1db61412bc5ec864a3ea62ed0055560b504dc615a47a28bb2b8861f4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e405b3d95a77a686cd9e65060fb5efdbb8b04b637a4feec6827f9fe163836890
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7621BF22A08681C1EFA0AB25D44466DB3A1FF88B44FC54135DE8C43A85DFFCE945C7A0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(00000000,?,?,?,00000000,00007FF762A828DA,FFFFFFFF,00000000,00007FF762A8336A), ref: 00007FF762A8218E
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: WARNING$[PYI-%d:%s]
                                                                                                                                                                                                                                                            • API String ID: 2050909247-3752221249
                                                                                                                                                                                                                                                            • Opcode ID: 28628bd70d5a97629098dcd42eabd330bee057474c06a66384895197b474a4b9
                                                                                                                                                                                                                                                            • Instruction ID: 0eb64d26c4cd515024161dbb68a1f0abd9e0ac644ae1bd99e8c06514ef7b796c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 28628bd70d5a97629098dcd42eabd330bee057474c06a66384895197b474a4b9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6A114D72A19B8181EBA0AB51B881AEAB364FF887C4F800135EE8D53A59DEFCD155C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(?,00000000,00000000,?,00000000,00007FF762A81B79), ref: 00007FF762A81E9E
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: ERROR$[PYI-%d:%s]
                                                                                                                                                                                                                                                            • API String ID: 2050909247-3005936843
                                                                                                                                                                                                                                                            • Opcode ID: c1c0bec23ccac853a0e083361079492e25c9a947d7081d13b76ea5259852d608
                                                                                                                                                                                                                                                            • Instruction ID: fbb9aa96cad8fe0aac67ead9085d39c394e14a168c263ea92d088d53b0dfccca
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c1c0bec23ccac853a0e083361079492e25c9a947d7081d13b76ea5259852d608
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BF114F72A19B8181EBA0AB51B8819EAB764EF847C4F800135EE8D53A59DEFCD155C610
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ExceptionFileHeaderRaise
                                                                                                                                                                                                                                                            • String ID: csm
                                                                                                                                                                                                                                                            • API String ID: 2573137834-1018135373
                                                                                                                                                                                                                                                            • Opcode ID: 778d4a5eeee770603d02c5501bef52114850414878b0bee781498c4a1570bacf
                                                                                                                                                                                                                                                            • Instruction ID: 41bac1b582cd0326c5eade36639e426b90208622e18df68967ba50a053486a85
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 778d4a5eeee770603d02c5501bef52114850414878b0bee781498c4a1570bacf
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BC114C32608B8182EBA09B15F440669B7E0FB88B84F984234EEDD47B54DFBCD551C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.2009263136.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009236254.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009296224.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009356198.00007FF762AC4000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000000.00000002.2009433721.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DriveType_invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: :
                                                                                                                                                                                                                                                            • API String ID: 2595371189-336475711
                                                                                                                                                                                                                                                            • Opcode ID: a21020f9989eba13c36801fee87724dcdfb53302495b3b0e02d80308072ceaa1
                                                                                                                                                                                                                                                            • Instruction ID: 98b49f67d9fef050f3940b7c82424ffe5923bd8f5c34704510572d160a3f00f1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a21020f9989eba13c36801fee87724dcdfb53302495b3b0e02d80308072ceaa1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AB017122A1C202C5EFF0BF609462A7EA3A0FF48744FC41535DE4D82A95DFECD504CA64

                                                                                                                                                                                                                                                            Execution Graph

                                                                                                                                                                                                                                                            Execution Coverage:4%
                                                                                                                                                                                                                                                            Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                                                                            Signature Coverage:0%
                                                                                                                                                                                                                                                            Total number of Nodes:647
                                                                                                                                                                                                                                                            Total number of Limit Nodes:19
                                                                                                                                                                                                                                                            execution_graph 29767 7ffdfa8d1f4b 29768 7ffdfa8e0650 29767->29768 29769 7ffdfa8e06cc BIO_ctrl 29768->29769 29770 7ffdfa8e06b2 29768->29770 29771 7ffdfa8e06ec 29769->29771 29772 7ff762a9cf14 29773 7ff762a9cf6b 29772->29773 29779 7ff762a9cf3d 29772->29779 29773->29779 29780 7ff762a9934c EnterCriticalSection 29773->29780 29775 7ff762a9cfe2 29776 7ff762a9cff9 29775->29776 29777 7ff762a9d034 _fread_nolock SetFilePointerEx GetLastError 29775->29777 29778 7ff762a99434 _fread_nolock LeaveCriticalSection 29776->29778 29777->29776 29778->29779 29781 7ff762a965e4 29782 7ff762a9661b 29781->29782 29786 7ff762a965fe 29781->29786 29783 7ff762a9662e CreateFileW 29782->29783 29782->29786 29784 7ff762a96662 29783->29784 29785 7ff762a96698 29783->29785 29797 7ff762a96738 15 API calls 29784->29797 29798 7ff762a96bc0 IsProcessorFeaturePresent capture_previous_context __raise_securityfailure GetDriveTypeW 29785->29798 29789 7ff762a9660b _invalid_parameter_noinfo 29786->29789 29792 7ff762a966b9 29789->29792 29790 7ff762a96670 29793 7ff762a96677 CloseHandle 29790->29793 29794 7ff762a9668d CloseHandle 29790->29794 29791 7ff762a9669d 29796 7ff762a966a1 29791->29796 29799 7ff762a96980 8 API calls 29791->29799 29793->29792 29794->29792 29796->29792 29797->29790 29798->29791 29799->29796 29800 7ff762a9e3d8 29809 7ff762a9b384 29800->29809 29803 7ff762a9e3ff 29805 7ff762a9e479 29813 7ff762a9e168 29805->29813 29807 7ff762a9e438 29807->29803 29807->29805 29822 7ff762aa4bec 29807->29822 29810 7ff762a9b3a2 29809->29810 29811 7ff762a9b38d 29809->29811 29810->29803 29810->29807 29821 7ff762a9e35c SetFilePointerEx GetFileSizeEx 29810->29821 29812 7ff762a9b392 _invalid_parameter_noinfo 29811->29812 29812->29810 29814 7ff762a9b384 _fread_nolock _invalid_parameter_noinfo 29813->29814 29815 7ff762a9e18d 29814->29815 29816 7ff762a9e22e 29815->29816 29817 7ff762a9e19d 29815->29817 29827 7ff762a9dd40 29816->29827 29819 7ff762a9dd40 27 API calls 29817->29819 29820 7ff762a9e1c9 29817->29820 29819->29820 29820->29803 29821->29807 29836 7ff762a9fe04 29822->29836 29824 7ff762aa4c10 29840 7ff762a9b464 HeapFree GetLastError 29824->29840 29826 7ff762aa4c1b 29826->29805 29828 7ff762a9dd96 29827->29828 29834 7ff762a9dd69 29827->29834 29828->29834 29835 7ff762a9934c EnterCriticalSection 29828->29835 29830 7ff762a9de0d 29831 7ff762a9de24 29830->29831 29832 7ff762a9de60 25 API calls 29830->29832 29833 7ff762a99434 _fread_nolock LeaveCriticalSection 29831->29833 29832->29831 29833->29834 29834->29820 29839 7ff762a9fe15 _fread_nolock 29836->29839 29837 7ff762a9fe4a HeapAlloc 29838 7ff762a9fe64 29837->29838 29837->29839 29838->29824 29839->29837 29839->29838 29840->29826 29841 7ff762a9a899 29851 7ff762a9b358 29841->29851 29843 7ff762a9a89e 29844 7ff762a9a8c5 GetModuleHandleW 29843->29844 29846 7ff762a9a90f 29843->29846 29844->29846 29849 7ff762a9a8d2 29844->29849 29845 7ff762a9a952 29846->29845 29847 7ff762a9a968 6 API calls 29846->29847 29848 7ff762a9a964 29847->29848 29849->29846 29850 7ff762a9a9c0 GetModuleHandleExW GetProcAddress FreeLibrary 29849->29850 29850->29846 29852 7ff762a9b361 29851->29852 29855 7ff762a9b40c IsProcessorFeaturePresent __GetCurrentState 29852->29855 29856 70186644 PySys_GetObject 29857 7018667f PyTuple_GetItem 29856->29857 29858 70186cc3 29856->29858 29857->29858 29859 70186696 PyLong_AsLong PyTuple_GetItem 29857->29859 29859->29858 29860 701866bb PyLong_AsLong PySys_GetObject 29859->29860 29861 701866e2 GetProcAddress GetProcAddress GetProcAddress PyModule_Create2 29860->29861 29862 701866d6 PyLong_AsVoidPtr 29860->29862 29861->29858 29863 70186776 PyModule_GetName 29861->29863 29862->29861 29863->29858 29864 7018678b strrchr 29863->29864 29865 701867a8 malloc 29864->29865 29866 701867df 29864->29866 29865->29866 29867 701867c2 memcpy 29865->29867 29868 701867fe 29866->29868 29872 70186f00 29866->29872 29867->29866 29870 70186813 PyBytes_FromStringAndSize 29868->29870 29877 701873c9 29868->29877 29869 70186b27 29869->29877 29888 701873a4 29869->29888 29913 70186cb0 29869->29913 29943 701a0ae0 29869->29943 29873 70186831 PyBytes_AsString 29870->29873 29870->29913 29871 70187687 exit 29872->29869 29872->29871 29876 70186f3c PyErr_Format 29872->29876 29874 7018684a malloc 29873->29874 29875 70186ce0 29873->29875 29874->29875 29880 70186861 PyCMethod_New 29874->29880 29882 70186cf7 _Py_Dealloc 29875->29882 29875->29913 29883 70186f70 _Py_Dealloc 29876->29883 29877->29871 29886 7018740f PyErr_Format 29877->29886 29877->29913 29879 70186d00 _Py_Dealloc 29879->29858 29881 701868a9 PyCMethod_New 29880->29881 29885 70186d10 29880->29885 29884 701868ef PyCMethod_New 29881->29884 29881->29885 29882->29913 29883->29875 29884->29885 29887 70186935 PyBytes_FromStringAndSize 29884->29887 29885->29875 29885->29883 29890 7018742f 29886->29890 29889 70186966 PyBytes_AsString 29887->29889 29887->29913 29888->29888 29891 70195700 29889->29891 29892 70187440 29890->29892 29893 70187582 29890->29893 29895 70186a44 _time64 srand 29891->29895 29892->29871 29907 70187453 29892->29907 29960 701881b0 PyErr_Format exit 29893->29960 29894 70186b44 29896 70186d40 malloc 29894->29896 29898 70186be9 strstr 29894->29898 29899 70186c44 29894->29899 29894->29913 29934 70186a7e 29895->29934 29897 70187639 _errno 29896->29897 29910 70186d5b 29896->29910 29902 70187550 29897->29902 29898->29899 29901 70186c05 29898->29901 29903 70187630 29899->29903 29904 70186c55 29899->29904 29901->29899 29908 70186c20 strncmp 29901->29908 29959 701880b0 8 API calls 29902->29959 29903->29897 29904->29871 29905 70186c6c 29904->29905 29912 70186c85 PyErr_Format 29905->29912 29905->29913 29909 70187473 PyErr_Format 29907->29909 29908->29896 29908->29899 29909->29913 29910->29913 29914 70186daf free 29910->29914 29915 70186db4 malloc 29910->29915 29911 7018755a _errno 29911->29913 29912->29913 29913->29858 29913->29879 29914->29915 29916 70187541 _errno 29915->29916 29917 70186dd1 memcpy 29915->29917 29916->29902 29918 70186df2 29917->29918 29922 70187090 29917->29922 29919 70186df8 29918->29919 29923 70186e90 29918->29923 29920 70186e0d free 29919->29920 29921 70186e12 malloc 29919->29921 29926 70186e41 29919->29926 29920->29921 29924 70186e2f memcpy 29921->29924 29925 70187673 _errno 29921->29925 29922->29871 29927 701870cd PyErr_Format 29922->29927 29931 70187493 29922->29931 29923->29871 29930 70186ecd PyErr_Format 29923->29930 29923->29931 29924->29926 29925->29902 29928 70186e49 29926->29928 29957 701840e0 exit 29926->29957 29927->29913 29928->29913 29932 70186e51 29928->29932 29930->29913 29931->29877 29932->29858 29933 70186b0c 29933->29869 29933->29928 29934->29890 29934->29913 29934->29928 29934->29933 29935 70186f9b PyBytes_AsStringAndSize 29934->29935 29935->29913 29940 70186fb7 29935->29940 29936 70187012 29936->29893 29939 70187039 memcpy 29936->29939 29937 70186ff5 29958 701881b0 PyErr_Format exit 29937->29958 29939->29933 29941 70187050 29939->29941 29940->29936 29940->29937 29941->29933 29942 70187060 _Py_Dealloc 29941->29942 29942->29933 29944 701a0b00 29943->29944 29953 701a0f2a 29943->29953 29945 701a0b1b 29944->29945 29944->29953 29961 701a2790 29945->29961 29948 701a0b63 29948->29894 29949 701a0b75 calloc 29952 701a0b94 29949->29952 29950 701a0fd0 29950->29894 29951 701a1022 29951->29950 29956 701a2790 4 API calls 29951->29956 29955 701a0c2e free 29952->29955 29953->29950 29953->29951 29954 701a2790 4 API calls 29953->29954 29954->29951 29955->29948 29956->29951 29958->29928 29959->29911 29960->29913 29962 701a27c7 29961->29962 29963 701a0b5d 29961->29963 29962->29963 29965 7019d9a0 29962->29965 29963->29948 29963->29949 29966 7019d9a9 29965->29966 29968 7019d9b4 29965->29968 29966->29962 29967 7019d9d9 29967->29962 29968->29967 29969 7019e39d calloc 29968->29969 29970 7019e3be 29968->29970 29969->29962 29971 7019e3f7 calloc 29970->29971 29975 7019e457 29970->29975 29972 7019e441 29971->29972 29973 7019e413 29971->29973 29972->29962 29973->29972 29974 7019e439 free 29973->29974 29974->29972 29976 7019e4a3 29975->29976 29977 7019ebd2 calloc 29975->29977 29976->29962 29978 7019ebec 29977->29978 29978->29962 29978->29976 29979 7ff762a8c1fc 29988 7ff762a8c3dc 29979->29988 29981 7ff762a8c291 __scrt_release_startup_lock 29984 7ff762a8c29d 29981->29984 29982 7ff762a8c260 __GetCurrentState 29983 7ff762a8c215 __scrt_acquire_startup_lock 29983->29981 29983->29982 29986 7ff762a8c2e6 29984->29986 30084 7ff762a9aa64 IsProcessorFeaturePresent 29984->30084 29994 7ff762a81000 29986->29994 29989 7ff762a8c3e4 29988->29989 29990 7ff762a8c3f0 __scrt_dllmain_crt_thread_attach 29989->29990 29991 7ff762a8c3f9 29990->29991 29992 7ff762a8c3fd 29990->29992 29991->29983 30085 7ff762a9b30c 29992->30085 29995 7ff762a82b80 29994->29995 30115 7ff762a82a70 29995->30115 30001 7ff762a830ec 30001->29982 30004 7ff762a82d2a 30191 7ff762a81e50 30004->30191 30007 7ff762a82d1d 30008 7ff762a82d22 30007->30008 30013 7ff762a82d45 30007->30013 30187 7ff762a8f5a4 30008->30187 30009 7ff762a82bfd 30017 7ff762a82c7b 30009->30017 30167 7ff762a87fe0 MultiByteToWideChar MultiByteToWideChar _invalid_parameter_noinfo 30009->30167 30013->30013 30016 7ff762a81930 79 API calls 30013->30016 30014 7ff762a82dcc 30200 7ff762a87fe0 MultiByteToWideChar MultiByteToWideChar _invalid_parameter_noinfo 30014->30200 30019 7ff762a82d8e 30016->30019 30026 7ff762a82cce 30017->30026 30199 7ff762a87f80 MultiByteToWideChar MultiByteToWideChar _invalid_parameter_noinfo 30017->30199 30018 7ff762a82dd8 30201 7ff762a87fe0 MultiByteToWideChar MultiByteToWideChar _invalid_parameter_noinfo 30018->30201 30019->30009 30021 7ff762a82d9e 30019->30021 30023 7ff762a81e50 40 API calls 30021->30023 30022 7ff762a82de4 30202 7ff762a87fe0 MultiByteToWideChar MultiByteToWideChar _invalid_parameter_noinfo 30022->30202 30049 7ff762a82bc9 30023->30049 30025 7ff762a82ef9 30028 7ff762a81e50 40 API calls 30025->30028 30026->30025 30027 7ff762a82e29 30026->30027 30030 7ff762a82e6c 30027->30030 30203 7ff762a87f80 MultiByteToWideChar MultiByteToWideChar _invalid_parameter_noinfo 30027->30203 30028->30049 30031 7ff762a83094 30030->30031 30034 7ff762a8311a 30030->30034 30044 7ff762a83171 30030->30044 30032 7ff762a830f9 30031->30032 30033 7ff762a830a5 30031->30033 30210 7ff762a87ca0 45 API calls 30032->30210 30039 7ff762a81e50 40 API calls 30033->30039 30034->30033 30036 7ff762a83133 30034->30036 30043 7ff762a83158 30036->30043 30036->30044 30037 7ff762a8320a 30151 7ff762a88950 30037->30151 30038 7ff762a83101 30041 7ff762a8310e 30038->30041 30042 7ff762a83105 30038->30042 30039->30049 30041->30044 30042->30033 30047 7ff762a81e50 40 API calls 30043->30047 30044->30037 30045 7ff762a831ed SetDllDirectoryW LoadLibraryExW 30044->30045 30045->30037 30046 7ff762a8321d SetDllDirectoryW 30054 7ff762a83250 30046->30054 30076 7ff762a832a1 30046->30076 30047->30049 30204 7ff762a8bb10 30049->30204 30050 7ff762a83362 30217 7ff762a82780 42 API calls _fread_nolock 30050->30217 30052 7ff762a83433 30156 7ff762a82720 30052->30156 30053 7ff762a83339 30216 7ff762a87f80 MultiByteToWideChar MultiByteToWideChar _invalid_parameter_noinfo 30053->30216 30054->30053 30062 7ff762a83295 30054->30062 30057 7ff762a8345e 30163 7ff762a82a30 30057->30163 30060 7ff762a8336a 30060->30049 30218 7ff762a87f80 MultiByteToWideChar MultiByteToWideChar _invalid_parameter_noinfo 30060->30218 30062->30076 30211 7ff762a86780 80 API calls 30062->30211 30064 7ff762a833ac 30219 7ff762a86400 FreeLibrary 30064->30219 30065 7ff762a83474 30067 7ff762a832c8 30074 7ff762a832e9 30067->30074 30078 7ff762a832cc 30067->30078 30212 7ff762a86240 42 API calls 30067->30212 30069 7ff762a833c2 30220 7ff762a87f20 11 API calls 30069->30220 30072 7ff762a83327 30215 7ff762a86400 FreeLibrary 30072->30215 30074->30078 30213 7ff762a86930 41 API calls 30074->30213 30076->30050 30076->30052 30078->30076 30214 7ff762a82140 40 API calls 30078->30214 30079 7ff762a833da 30079->30049 30080 7ff762a8341a 30079->30080 30081 7ff762a83401 30079->30081 30221 7ff762a82140 40 API calls 30080->30221 30082 7ff762a81e50 40 API calls 30081->30082 30082->30049 30084->29986 30086 7ff762aa471c 30085->30086 30087 7ff762aa475e 30086->30087 30089 7ff762a9d420 30086->30089 30087->29991 30090 7ff762a9d430 30089->30090 30097 7ff762a992a4 30090->30097 30092 7ff762a9d439 30093 7ff762a9d447 30092->30093 30103 7ff762a9d228 GetStartupInfoW 30092->30103 30093->30086 30098 7ff762a992c3 30097->30098 30102 7ff762a992ec 30097->30102 30099 7ff762a992c8 _invalid_parameter_noinfo 30098->30099 30100 7ff762a992d6 30099->30100 30100->30092 30102->30100 30114 7ff762a991ac 9 API calls _fread_nolock 30102->30114 30104 7ff762a9d2f7 30103->30104 30105 7ff762a9d25d 30103->30105 30109 7ff762a9d318 30104->30109 30105->30104 30106 7ff762a992a4 10 API calls 30105->30106 30107 7ff762a9d286 30106->30107 30107->30104 30108 7ff762a9d2b0 GetFileType 30107->30108 30108->30107 30110 7ff762a9d336 30109->30110 30111 7ff762a9d405 30110->30111 30112 7ff762a9d391 GetStdHandle 30110->30112 30111->30093 30112->30110 30113 7ff762a9d3a4 GetFileType 30112->30113 30113->30110 30114->30102 30116 7ff762a8be10 30115->30116 30117 7ff762a82a7c GetModuleFileNameW 30116->30117 30118 7ff762a82aab GetLastError 30117->30118 30119 7ff762a82ad0 30117->30119 30228 7ff762a82310 39 API calls 30118->30228 30223 7ff762a88840 FindFirstFileExW 30119->30223 30122 7ff762a82ada 30127 7ff762a82af4 30122->30127 30130 7ff762a82b0c __vcrt_FlsAlloc 30122->30130 30124 7ff762a8bb10 3 API calls 30126 7ff762a82b75 30124->30126 30125 7ff762a82b4b 30131 7ff762a82ac6 30125->30131 30231 7ff762a81f30 37 API calls 30125->30231 30126->30049 30132 7ff762a81930 30126->30132 30229 7ff762a81f30 37 API calls 30127->30229 30230 7ff762a88a00 WideCharToMultiByte WideCharToMultiByte 30130->30230 30131->30124 30133 7ff762a839d0 69 API calls 30132->30133 30134 7ff762a81965 30133->30134 30135 7ff762a81c23 30134->30135 30137 7ff762a873d0 25 API calls 30134->30137 30136 7ff762a8bb10 3 API calls 30135->30136 30139 7ff762a81c3e 30136->30139 30138 7ff762a819ab 30137->30138 30150 7ff762a819c9 30138->30150 30232 7ff762a8fc2c 30138->30232 30139->30009 30168 7ff762a839d0 30139->30168 30141 7ff762a8f5a4 9 API calls 30141->30135 30142 7ff762a819c5 30142->30150 30236 7ff762a8f8f4 30142->30236 30144 7ff762a81a00 30145 7ff762a8fc2c 4 API calls 30144->30145 30144->30150 30146 7ff762a81ae1 30145->30146 30147 7ff762a8f8f4 _fread_nolock 25 API calls 30146->30147 30146->30150 30148 7ff762a81b2a 30147->30148 30149 7ff762a81e50 40 API calls 30148->30149 30148->30150 30149->30150 30150->30141 30152 7ff762a88972 MultiByteToWideChar 30151->30152 30154 7ff762a88996 30151->30154 30152->30154 30155 7ff762a889ac 30152->30155 30153 7ff762a889b3 MultiByteToWideChar 30153->30155 30154->30153 30154->30155 30155->30046 30260 7ff762a857a0 30156->30260 30160 7ff762a82741 30162 7ff762a8274d 30160->30162 30322 7ff762a85490 30160->30322 30162->30057 30164 7ff762a82a3e 30163->30164 30166 7ff762a82a4f 30164->30166 30389 7ff762a884a0 FreeLibrary 30164->30389 30222 7ff762a86400 FreeLibrary 30166->30222 30167->30017 30169 7ff762a839dc 30168->30169 30170 7ff762a88950 2 API calls 30169->30170 30171 7ff762a83a04 30170->30171 30172 7ff762a88950 2 API calls 30171->30172 30173 7ff762a83a17 30172->30173 30390 7ff762a96f54 30173->30390 30175 7ff762a83a26 30176 7ff762a8bb10 3 API calls 30175->30176 30177 7ff762a82ceb 30176->30177 30177->30004 30178 7ff762a873d0 30177->30178 30179 7ff762a873f4 30178->30179 30180 7ff762a874cb 30179->30180 30181 7ff762a8fc2c 4 API calls 30179->30181 30180->30007 30182 7ff762a87410 30181->30182 30182->30180 30479 7ff762a98804 30182->30479 30184 7ff762a8fc2c 4 API calls 30186 7ff762a87425 30184->30186 30185 7ff762a8f8f4 _fread_nolock 25 API calls 30185->30186 30186->30180 30186->30184 30186->30185 30188 7ff762a8f5d4 30187->30188 30492 7ff762a8f380 30188->30492 30190 7ff762a8f5ed 30190->30004 30192 7ff762a8be10 30191->30192 30193 7ff762a81e74 GetCurrentProcessId 30192->30193 30194 7ff762a81ec5 30193->30194 30501 7ff762a81cc0 30194->30501 30197 7ff762a8bb10 3 API calls 30198 7ff762a81f1c 30197->30198 30198->30049 30199->30014 30200->30018 30201->30022 30202->30026 30203->30030 30205 7ff762a8bb19 30204->30205 30206 7ff762a8bb24 30205->30206 30207 7ff762a8bea0 IsProcessorFeaturePresent 30205->30207 30206->30001 30208 7ff762a8bebf capture_previous_context __raise_securityfailure 30207->30208 30209 7ff762a8beb8 30207->30209 30208->30001 30209->30208 30210->30038 30211->30067 30212->30074 30213->30078 30214->30072 30215->30076 30216->30076 30217->30060 30218->30064 30219->30069 30220->30079 30221->30049 30222->30065 30224 7ff762a8887f FindClose 30223->30224 30225 7ff762a88892 30223->30225 30224->30225 30226 7ff762a8bb10 3 API calls 30225->30226 30227 7ff762a888b3 30226->30227 30227->30122 30228->30131 30229->30131 30230->30125 30231->30131 30233 7ff762a8fc5c 30232->30233 30239 7ff762a8f9bc 30233->30239 30235 7ff762a8fc75 30235->30142 30248 7ff762a8f914 30236->30248 30240 7ff762a8fa26 30239->30240 30241 7ff762a8f9e6 30239->30241 30240->30241 30247 7ff762a962dc EnterCriticalSection 30240->30247 30241->30235 30243 7ff762a8fa37 30244 7ff762a8fb40 SetFilePointerEx GetLastError 30243->30244 30245 7ff762a8fa49 30244->30245 30246 7ff762a962e8 _fread_nolock LeaveCriticalSection 30245->30246 30246->30241 30249 7ff762a8f90c 30248->30249 30250 7ff762a8f93e 30248->30250 30249->30144 30250->30249 30251 7ff762a8f98a 30250->30251 30252 7ff762a8f94d _fread_nolock 30250->30252 30259 7ff762a962dc EnterCriticalSection 30251->30259 30255 7ff762a8f962 _invalid_parameter_noinfo 30252->30255 30254 7ff762a8f992 30256 7ff762a8f694 _fread_nolock 22 API calls 30254->30256 30255->30249 30257 7ff762a8f9a9 30256->30257 30258 7ff762a962e8 _fread_nolock LeaveCriticalSection 30257->30258 30258->30249 30261 7ff762a857b5 30260->30261 30262 7ff762a857fa 30261->30262 30265 7ff762a8581d 30261->30265 30263 7ff762a81e50 40 API calls 30262->30263 30264 7ff762a85813 30263->30264 30267 7ff762a8bb10 3 API calls 30264->30267 30266 7ff762a85853 30265->30266 30268 7ff762a81e50 40 API calls 30265->30268 30331 7ff762a83970 30266->30331 30270 7ff762a8272e 30267->30270 30268->30266 30270->30162 30285 7ff762a85940 30270->30285 30272 7ff762a8586b 30274 7ff762a858a9 30272->30274 30275 7ff762a85889 30272->30275 30273 7ff762a884c0 3 API calls 30273->30272 30337 7ff762a884c0 30274->30337 30276 7ff762a81e50 40 API calls 30275->30276 30276->30264 30278 7ff762a858b6 30279 7ff762a858c2 30278->30279 30280 7ff762a85901 30278->30280 30281 7ff762a88950 2 API calls 30279->30281 30342 7ff762a84c40 125 API calls 30280->30342 30283 7ff762a858da GetLastError 30281->30283 30341 7ff762a82310 39 API calls 30283->30341 30343 7ff762a84810 30285->30343 30287 7ff762a85966 30288 7ff762a8596e 30287->30288 30289 7ff762a8597f 30287->30289 30290 7ff762a81e50 40 API calls 30288->30290 30347 7ff762a840a0 30289->30347 30297 7ff762a8597a 30290->30297 30293 7ff762a8599c 30296 7ff762a859ac 30293->30296 30299 7ff762a859bd 30293->30299 30294 7ff762a8598b 30295 7ff762a81e50 40 API calls 30294->30295 30295->30297 30298 7ff762a81e50 40 API calls 30296->30298 30297->30160 30298->30297 30300 7ff762a859ed 30299->30300 30301 7ff762a859dc 30299->30301 30303 7ff762a85a0d 30300->30303 30304 7ff762a859fc 30300->30304 30302 7ff762a81e50 40 API calls 30301->30302 30302->30297 30351 7ff762a84160 30303->30351 30305 7ff762a81e50 40 API calls 30304->30305 30305->30297 30308 7ff762a85a1c 30309 7ff762a81e50 40 API calls 30308->30309 30309->30297 30310 7ff762a85a2d 30311 7ff762a85a4d 30310->30311 30312 7ff762a85a3c 30310->30312 30314 7ff762a85a5f 30311->30314 30316 7ff762a85a70 30311->30316 30313 7ff762a81e50 40 API calls 30312->30313 30313->30297 30315 7ff762a81e50 40 API calls 30314->30315 30315->30297 30319 7ff762a85a9a 30316->30319 30361 7ff762a981ec EnterCriticalSection LeaveCriticalSection 30316->30361 30318 7ff762a85a88 30362 7ff762a981ec EnterCriticalSection LeaveCriticalSection 30318->30362 30319->30297 30320 7ff762a81e50 40 API calls 30319->30320 30320->30297 30323 7ff762a854b0 30322->30323 30323->30323 30324 7ff762a854d9 30323->30324 30330 7ff762a854f0 30323->30330 30325 7ff762a81e50 40 API calls 30324->30325 30326 7ff762a854e5 30325->30326 30326->30162 30327 7ff762a855fb 30327->30162 30329 7ff762a81e50 40 API calls 30329->30330 30330->30327 30330->30329 30363 7ff762a81450 30330->30363 30332 7ff762a8397a 30331->30332 30333 7ff762a88950 2 API calls 30332->30333 30334 7ff762a8399f 30333->30334 30335 7ff762a8bb10 3 API calls 30334->30335 30336 7ff762a839c7 30335->30336 30336->30272 30336->30273 30338 7ff762a88950 2 API calls 30337->30338 30339 7ff762a884d4 LoadLibraryExW 30338->30339 30340 7ff762a884f3 30339->30340 30340->30278 30341->30264 30342->30264 30346 7ff762a8483c 30343->30346 30344 7ff762a84844 30344->30287 30345 7ff762a83be0 IsProcessorFeaturePresent capture_previous_context __raise_securityfailure 30345->30346 30346->30344 30346->30345 30348 7ff762a840d0 30347->30348 30349 7ff762a8bb10 3 API calls 30348->30349 30350 7ff762a8413a 30349->30350 30350->30293 30350->30294 30352 7ff762a84175 30351->30352 30353 7ff762a84243 30352->30353 30356 7ff762a88950 2 API calls 30352->30356 30354 7ff762a8bb10 3 API calls 30353->30354 30355 7ff762a8428e 30354->30355 30355->30308 30355->30310 30357 7ff762a84216 30356->30357 30358 7ff762a88950 2 API calls 30357->30358 30359 7ff762a8422d 30358->30359 30360 7ff762a88950 2 API calls 30359->30360 30360->30353 30361->30318 30362->30319 30364 7ff762a839d0 69 API calls 30363->30364 30365 7ff762a81473 30364->30365 30366 7ff762a8149c 30365->30366 30367 7ff762a8147b 30365->30367 30369 7ff762a8fc2c 4 API calls 30366->30369 30368 7ff762a81e50 40 API calls 30367->30368 30370 7ff762a8148b 30368->30370 30371 7ff762a814b1 30369->30371 30370->30330 30372 7ff762a814b5 30371->30372 30373 7ff762a81518 30371->30373 30378 7ff762a8152b 30371->30378 30375 7ff762a8f5a4 9 API calls 30372->30375 30379 7ff762a811f0 30373->30379 30376 7ff762a815a4 30375->30376 30376->30330 30377 7ff762a8f8f4 _fread_nolock 25 API calls 30377->30378 30378->30372 30378->30377 30380 7ff762a81248 30379->30380 30381 7ff762a8124f 30380->30381 30385 7ff762a81277 30380->30385 30382 7ff762a81e50 40 API calls 30381->30382 30383 7ff762a81262 30382->30383 30383->30372 30384 7ff762a8f8f4 _fread_nolock 25 API calls 30384->30385 30385->30384 30386 7ff762a81291 30385->30386 30387 7ff762a813af 30385->30387 30386->30372 30388 7ff762a81e50 40 API calls 30387->30388 30388->30386 30389->30166 30391 7ff762a96e88 30390->30391 30392 7ff762a96eae 30391->30392 30393 7ff762a96ee1 30391->30393 30394 7ff762a96eb3 _invalid_parameter_noinfo 30392->30394 30397 7ff762a96ebe 30393->30397 30401 7ff762a9bb30 30393->30401 30394->30397 30396 7ff762a96efe 30396->30397 30405 7ff762aa113c 30396->30405 30397->30175 30399 7ff762a96f28 30409 7ff762a962e8 LeaveCriticalSection 30399->30409 30402 7ff762a9bb47 30401->30402 30410 7ff762a9bba4 30402->30410 30404 7ff762a9bb52 30404->30396 30406 7ff762aa1162 30405->30406 30407 7ff762aa1196 30406->30407 30428 7ff762aa7fc4 30406->30428 30407->30399 30417 7ff762a9bbd5 30410->30417 30411 7ff762a9bc6e 30411->30404 30412 7ff762a9bc24 30413 7ff762a9fe04 _fread_nolock HeapAlloc 30412->30413 30415 7ff762a9bc31 30413->30415 30425 7ff762a9b464 HeapFree GetLastError 30415->30425 30417->30411 30417->30412 30417->30417 30423 7ff762a962dc EnterCriticalSection 30417->30423 30424 7ff762a962e8 LeaveCriticalSection 30417->30424 30418 7ff762a9bc3b 30418->30411 30426 7ff762aa02e0 6 API calls __crtLCMapStringW 30418->30426 30421 7ff762a9bc5b 30427 7ff762a962dc EnterCriticalSection 30421->30427 30425->30418 30426->30421 30431 7ff762aa75c4 30428->30431 30432 7ff762aa75f9 30431->30432 30433 7ff762aa75db 30431->30433 30432->30433 30435 7ff762aa7615 30432->30435 30434 7ff762aa75e0 _invalid_parameter_noinfo 30433->30434 30436 7ff762aa75ee 30434->30436 30440 7ff762aa7bd4 30435->30440 30436->30407 30438 7ff762aa7640 30438->30436 30464 7ff762a99434 LeaveCriticalSection 30438->30464 30441 7ff762aa7c1b 30440->30441 30451 7ff762aa7c49 30441->30451 30465 7ff762a9945c 30441->30465 30443 7ff762aa7c66 30444 7ff762aa7c86 CreateFileW 30443->30444 30443->30451 30445 7ff762aa7cf1 30444->30445 30446 7ff762aa7d6c GetFileType 30444->30446 30449 7ff762aa7d39 GetLastError 30445->30449 30450 7ff762aa7cff CreateFileW 30445->30450 30447 7ff762aa7dca 30446->30447 30448 7ff762aa7d79 GetLastError 30446->30448 30474 7ff762a99374 SetStdHandle 30447->30474 30452 7ff762a95dbc 30448->30452 30449->30451 30450->30446 30450->30449 30451->30438 30453 7ff762aa7d88 CloseHandle 30452->30453 30453->30451 30463 7ff762aa7dba 30453->30463 30455 7ff762aa7dec 30456 7ff762aa7e40 30455->30456 30475 7ff762aa7b10 41 API calls _fread_nolock 30455->30475 30458 7ff762aa7e47 30456->30458 30459 7ff762aa7e8d 30456->30459 30476 7ff762a9b9c8 CloseHandle GetLastError 30458->30476 30459->30451 30461 7ff762aa7f0c CloseHandle CreateFileW 30459->30461 30462 7ff762aa7f53 GetLastError 30461->30462 30461->30463 30462->30463 30463->30451 30470 7ff762a9947f 30465->30470 30466 7ff762a994cb 30466->30443 30467 7ff762a994a8 30477 7ff762a991ac 9 API calls _fread_nolock 30467->30477 30469 7ff762a994ad 30469->30466 30478 7ff762a9934c EnterCriticalSection 30469->30478 30470->30466 30470->30467 30471 7ff762a994fe EnterCriticalSection 30470->30471 30471->30466 30473 7ff762a9950d LeaveCriticalSection 30471->30473 30473->30470 30474->30455 30475->30456 30476->30451 30477->30469 30480 7ff762a98834 30479->30480 30483 7ff762a98310 30480->30483 30482 7ff762a9884d 30482->30186 30484 7ff762a9835a 30483->30484 30486 7ff762a9832b 30483->30486 30491 7ff762a962dc EnterCriticalSection 30484->30491 30486->30482 30487 7ff762a9835f 30488 7ff762a9837c _invalid_parameter_noinfo 30487->30488 30489 7ff762a9836b 30488->30489 30490 7ff762a962e8 _fread_nolock LeaveCriticalSection 30489->30490 30490->30486 30493 7ff762a8f3c9 30492->30493 30494 7ff762a8f39b 30492->30494 30493->30494 30500 7ff762a962dc EnterCriticalSection 30493->30500 30494->30190 30496 7ff762a8f3e0 30497 7ff762a8f3fc 7 API calls 30496->30497 30498 7ff762a8f3ec 30497->30498 30499 7ff762a962e8 _fread_nolock LeaveCriticalSection 30498->30499 30499->30494 30502 7ff762a81ccc 30501->30502 30503 7ff762a88950 2 API calls 30502->30503 30504 7ff762a81cf4 30503->30504 30506 7ff762a81d17 30504->30506 30509 7ff762a81e00 30504->30509 30507 7ff762a8bb10 3 API calls 30506->30507 30508 7ff762a81d40 30507->30508 30508->30197 30510 7ff762a81e26 30509->30510 30513 7ff762a957a0 30510->30513 30512 7ff762a81e3c 30512->30506 30514 7ff762a957ca 30513->30514 30516 7ff762a95802 30514->30516 30517 7ff762a900d8 30514->30517 30516->30512 30524 7ff762a962dc EnterCriticalSection 30517->30524 30519 7ff762a900f5 30520 7ff762a92178 35 API calls 30519->30520 30521 7ff762a900fe 30520->30521 30522 7ff762a962e8 _fread_nolock LeaveCriticalSection 30521->30522 30523 7ff762a90108 30522->30523 30523->30516 30525 7ff762a82480 30526 7ff762a82490 30525->30526 30527 7ff762a824cb 30526->30527 30528 7ff762a824e1 30526->30528 30529 7ff762a81e50 40 API calls 30527->30529 30530 7ff762a82501 30528->30530 30538 7ff762a82517 30528->30538 30533 7ff762a824d7 30529->30533 30531 7ff762a81e50 40 API calls 30530->30531 30531->30533 30532 7ff762a8bb10 3 API calls 30534 7ff762a8269a 30532->30534 30533->30532 30535 7ff762a81450 79 API calls 30535->30538 30536 7ff762a82706 30537 7ff762a81e50 40 API calls 30536->30537 30537->30533 30538->30533 30538->30535 30538->30536 30539 7ff762a826f0 30538->30539 30541 7ff762a826ca 30538->30541 30543 7ff762a826a7 30538->30543 30540 7ff762a81e50 40 API calls 30539->30540 30540->30533 30542 7ff762a81e50 40 API calls 30541->30542 30542->30533 30544 7ff762a81e50 40 API calls 30543->30544 30544->30533
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • PySys_GetObject.PYTHON313 ref: 70186671
                                                                                                                                                                                                                                                            • PyTuple_GetItem.PYTHON313 ref: 7018668B
                                                                                                                                                                                                                                                            • PyLong_AsLong.PYTHON313 ref: 701866A0
                                                                                                                                                                                                                                                            • PyTuple_GetItem.PYTHON313 ref: 701866B0
                                                                                                                                                                                                                                                            • PyLong_AsLong.PYTHON313 ref: 701866BE
                                                                                                                                                                                                                                                            • PySys_GetObject.PYTHON313 ref: 701866CD
                                                                                                                                                                                                                                                            • PyLong_AsVoidPtr.PYTHON313 ref: 701866D9
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32 ref: 701866FE
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32 ref: 7018671C
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32 ref: 7018673A
                                                                                                                                                                                                                                                            • PyModule_Create2.PYTHON313 ref: 70186764
                                                                                                                                                                                                                                                            • PyModule_GetName.PYTHON313 ref: 70186779
                                                                                                                                                                                                                                                            • strrchr.MSVCRT ref: 7018679E
                                                                                                                                                                                                                                                            • malloc.MSVCRT ref: 701867B4
                                                                                                                                                                                                                                                            • memcpy.MSVCRT ref: 701867CE
                                                                                                                                                                                                                                                            • PyBytes_FromStringAndSize.PYTHON313 ref: 70186821
                                                                                                                                                                                                                                                            • PyBytes_AsString.PYTHON313 ref: 7018683B
                                                                                                                                                                                                                                                            • malloc.MSVCRT ref: 7018684F
                                                                                                                                                                                                                                                            • PyCMethod_New.PYTHON313 ref: 7018689D
                                                                                                                                                                                                                                                            • PyCMethod_New.PYTHON313 ref: 701868E3
                                                                                                                                                                                                                                                            • PyCMethod_New.PYTHON313 ref: 70186929
                                                                                                                                                                                                                                                            • PyBytes_FromStringAndSize.PYTHON313 ref: 70186953
                                                                                                                                                                                                                                                            • PyBytes_AsString.PYTHON313 ref: 70186969
                                                                                                                                                                                                                                                            • _time64.MSVCRT ref: 70186A46
                                                                                                                                                                                                                                                            • srand.MSVCRT ref: 70186A4E
                                                                                                                                                                                                                                                            • PyErr_Format.PYTHON313 ref: 70187488
                                                                                                                                                                                                                                                              • Part of subcall function 7019F550: memcmp.MSVCRT ref: 7019F583
                                                                                                                                                                                                                                                              • Part of subcall function 7019F550: memcmp.MSVCRT ref: 7019F5A0
                                                                                                                                                                                                                                                              • Part of subcall function 7019F550: memcmp.MSVCRT ref: 7019F5C2
                                                                                                                                                                                                                                                              • Part of subcall function 7019F550: memcmp.MSVCRT ref: 7019F5E2
                                                                                                                                                                                                                                                              • Part of subcall function 7019F550: memcmp.MSVCRT ref: 7019F602
                                                                                                                                                                                                                                                              • Part of subcall function 7019F550: memcmp.MSVCRT ref: 7019F622
                                                                                                                                                                                                                                                              • Part of subcall function 7019F550: memcmp.MSVCRT ref: 7019F642
                                                                                                                                                                                                                                                              • Part of subcall function 7019F550: memcmp.MSVCRT ref: 7019F662
                                                                                                                                                                                                                                                              • Part of subcall function 7019F2C0: memcmp.MSVCRT ref: 7019F2F3
                                                                                                                                                                                                                                                              • Part of subcall function 7019F2C0: memcmp.MSVCRT ref: 7019F313
                                                                                                                                                                                                                                                              • Part of subcall function 7019F2C0: memcmp.MSVCRT ref: 7019F335
                                                                                                                                                                                                                                                              • Part of subcall function 7019F2C0: memcmp.MSVCRT ref: 7019F355
                                                                                                                                                                                                                                                              • Part of subcall function 7019F2C0: memcmp.MSVCRT ref: 7019F375
                                                                                                                                                                                                                                                              • Part of subcall function 7019F2C0: memcmp.MSVCRT ref: 7019F395
                                                                                                                                                                                                                                                              • Part of subcall function 7019F2C0: memcmp.MSVCRT ref: 7019F3B5
                                                                                                                                                                                                                                                              • Part of subcall function 7019F2C0: memcmp.MSVCRT ref: 7019F3D5
                                                                                                                                                                                                                                                              • Part of subcall function 7019ECF0: strcmp.MSVCRT ref: 7019ED1B
                                                                                                                                                                                                                                                              • Part of subcall function 7019ECF0: strcmp.MSVCRT ref: 7019ED45
                                                                                                                                                                                                                                                              • Part of subcall function 7019ECF0: strcmp.MSVCRT ref: 7019ED64
                                                                                                                                                                                                                                                              • Part of subcall function 7019ECF0: strcmp.MSVCRT ref: 7019ED83
                                                                                                                                                                                                                                                              • Part of subcall function 7019ECF0: strcmp.MSVCRT ref: 7019EDA2
                                                                                                                                                                                                                                                              • Part of subcall function 7019ECF0: strcmp.MSVCRT ref: 7019EDBD
                                                                                                                                                                                                                                                              • Part of subcall function 7019ECF0: strcmp.MSVCRT ref: 7019EDD8
                                                                                                                                                                                                                                                              • Part of subcall function 7019ECF0: strcmp.MSVCRT ref: 7019EDF3
                                                                                                                                                                                                                                                              • Part of subcall function 7019EF90: strcmp.MSVCRT ref: 7019EFBB
                                                                                                                                                                                                                                                              • Part of subcall function 7019EF90: strcmp.MSVCRT ref: 7019EFDF
                                                                                                                                                                                                                                                              • Part of subcall function 7019EF90: strcmp.MSVCRT ref: 7019EFFB
                                                                                                                                                                                                                                                              • Part of subcall function 7019EF90: strcmp.MSVCRT ref: 7019F01A
                                                                                                                                                                                                                                                              • Part of subcall function 7019EF90: strcmp.MSVCRT ref: 7019F039
                                                                                                                                                                                                                                                              • Part of subcall function 7019EF90: strcmp.MSVCRT ref: 7019F054
                                                                                                                                                                                                                                                              • Part of subcall function 7019EF90: strcmp.MSVCRT ref: 7019F06F
                                                                                                                                                                                                                                                              • Part of subcall function 7019EF90: strcmp.MSVCRT ref: 7019F08A
                                                                                                                                                                                                                                                              • Part of subcall function 7019EE40: strcmp.MSVCRT ref: 7019EE6B
                                                                                                                                                                                                                                                              • Part of subcall function 7019EE40: strcmp.MSVCRT ref: 7019EE95
                                                                                                                                                                                                                                                              • Part of subcall function 7019EE40: strcmp.MSVCRT ref: 7019EEB4
                                                                                                                                                                                                                                                              • Part of subcall function 7019EE40: strcmp.MSVCRT ref: 7019EED3
                                                                                                                                                                                                                                                              • Part of subcall function 7019EE40: strcmp.MSVCRT ref: 7019EEF2
                                                                                                                                                                                                                                                              • Part of subcall function 7019EE40: strcmp.MSVCRT ref: 7019EF0D
                                                                                                                                                                                                                                                              • Part of subcall function 7019EE40: strcmp.MSVCRT ref: 7019EF28
                                                                                                                                                                                                                                                              • Part of subcall function 7019EE40: strcmp.MSVCRT ref: 7019EF43
                                                                                                                                                                                                                                                            • strstr.MSVCRT ref: 70186BF5
                                                                                                                                                                                                                                                            • strncmp.MSVCRT ref: 70186C31
                                                                                                                                                                                                                                                            • PyErr_Format.PYTHON313 ref: 70186CA4
                                                                                                                                                                                                                                                            • malloc.MSVCRT ref: 70186D45
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 70186DAF
                                                                                                                                                                                                                                                            • malloc.MSVCRT ref: 70186DBB
                                                                                                                                                                                                                                                            • memcpy.MSVCRT ref: 70186DDE
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 70186E0D
                                                                                                                                                                                                                                                            • malloc.MSVCRT ref: 70186E19
                                                                                                                                                                                                                                                            • memcpy.MSVCRT ref: 70186E3C
                                                                                                                                                                                                                                                            • PyBytes_AsStringAndSize.PYTHON313 ref: 70186FA8
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strcmp$memcmp$Bytes_Stringmalloc$AddressLong_Method_ProcSizememcpy$Err_FormatFromItemLongModule_ObjectSys_Tuple_free$Create2NameVoid_time64srandstrncmpstrrchrstrstr
                                                                                                                                                                                                                                                            • String ID: p$%s (%d:%d)$,*$.pyarmor.ikey$000000$@ p$C_ASSERT_ARMORED_INDEX$C_ENTER_CO_OBJECT_INDEX$C_LEAVE_CO_OBJECT_INDEX$PyCell_Get$PyCell_New$PyCell_Set$aes$dllhandle$pyarmor_runtime_$sha256$sprng$version_info
                                                                                                                                                                                                                                                            • API String ID: 493229627-4112846590
                                                                                                                                                                                                                                                            • Opcode ID: db645594d2fa9e1c84ce9a7968f33ce07d9232056e09f8c3ceb725da3e3d4d2a
                                                                                                                                                                                                                                                            • Instruction ID: f4aef0bf8597120958d9e19d3fb4d860c832a6a3365c4a86ef16b9ae3033049e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: db645594d2fa9e1c84ce9a7968f33ce07d9232056e09f8c3ceb725da3e3d4d2a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A2821333709B8486EB01CB25E44436E3BA5FB45BA4F56811ACE8E57B95DF3CEA46C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Err_Format
                                                                                                                                                                                                                                                            • String ID: %s (%d:%d)$000000$<frozen %U>$@, p$OOy#|i$P* p$__main__$__mp_main__$__spec__$hdinfo$keyinfo$) p
                                                                                                                                                                                                                                                            • API String ID: 376477240-3355152298
                                                                                                                                                                                                                                                            • Opcode ID: 6e9e404dea3077424a3ef18c09a6997136e931dd7fbff1c68454bc86aacbb7f8
                                                                                                                                                                                                                                                            • Instruction ID: 3affe792f66515957ded9b41e4680d281b56d5e4864e074318df825bafd9b88d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6e9e404dea3077424a3ef18c09a6997136e931dd7fbff1c68454bc86aacbb7f8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 26A2B172A08B84C5EB118B15E89435D37B1F785BE4F558226DE4E47BA9DF3CD642CB00

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 1573 7ff762aa7bd4-7ff762aa7c47 call 7ff762aa7908 1576 7ff762aa7c61-7ff762aa7c6b call 7ff762a9945c 1573->1576 1577 7ff762aa7c49-7ff762aa7c52 call 7ff762a95e28 1573->1577 1583 7ff762aa7c86-7ff762aa7cef CreateFileW 1576->1583 1584 7ff762aa7c6d-7ff762aa7c84 call 7ff762a95e28 call 7ff762a95e48 1576->1584 1582 7ff762aa7c55-7ff762aa7c5c call 7ff762a95e48 1577->1582 1597 7ff762aa7fa2-7ff762aa7fc2 1582->1597 1587 7ff762aa7cf1-7ff762aa7cf7 1583->1587 1588 7ff762aa7d6c-7ff762aa7d77 GetFileType 1583->1588 1584->1582 1593 7ff762aa7d39-7ff762aa7d67 GetLastError call 7ff762a95dbc 1587->1593 1594 7ff762aa7cf9-7ff762aa7cfd 1587->1594 1590 7ff762aa7dca-7ff762aa7dd1 1588->1590 1591 7ff762aa7d79-7ff762aa7db4 GetLastError call 7ff762a95dbc CloseHandle 1588->1591 1600 7ff762aa7dd3-7ff762aa7dd7 1590->1600 1601 7ff762aa7dd9-7ff762aa7ddc 1590->1601 1591->1582 1608 7ff762aa7dba-7ff762aa7dc5 call 7ff762a95e48 1591->1608 1593->1582 1594->1593 1595 7ff762aa7cff-7ff762aa7d37 CreateFileW 1594->1595 1595->1588 1595->1593 1605 7ff762aa7de2-7ff762aa7e37 call 7ff762a99374 1600->1605 1601->1605 1606 7ff762aa7dde 1601->1606 1611 7ff762aa7e56-7ff762aa7e87 call 7ff762aa7688 1605->1611 1612 7ff762aa7e39-7ff762aa7e45 call 7ff762aa7b10 1605->1612 1606->1605 1608->1582 1619 7ff762aa7e89-7ff762aa7e8b 1611->1619 1620 7ff762aa7e8d-7ff762aa7ecf 1611->1620 1612->1611 1618 7ff762aa7e47 1612->1618 1621 7ff762aa7e49-7ff762aa7e51 call 7ff762a9b9c8 1618->1621 1619->1621 1622 7ff762aa7ef1-7ff762aa7efc 1620->1622 1623 7ff762aa7ed1-7ff762aa7ed5 1620->1623 1621->1597 1624 7ff762aa7fa0 1622->1624 1625 7ff762aa7f02-7ff762aa7f06 1622->1625 1623->1622 1627 7ff762aa7ed7-7ff762aa7eec 1623->1627 1624->1597 1625->1624 1628 7ff762aa7f0c-7ff762aa7f51 CloseHandle CreateFileW 1625->1628 1627->1622 1630 7ff762aa7f53-7ff762aa7f81 GetLastError call 7ff762a95dbc call 7ff762a9959c 1628->1630 1631 7ff762aa7f86-7ff762aa7f9b 1628->1631 1630->1631 1631->1624
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1617910340-0
                                                                                                                                                                                                                                                            • Opcode ID: f7d25cc6398c99507331e2d119a18c280b6cb5988aed80ed714a7f2df808d279
                                                                                                                                                                                                                                                            • Instruction ID: 1e5abbd3833abcd1512cef039a3801bc757cfbd3cd616dadb5ab32fa3d2afe2f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f7d25cc6398c99507331e2d119a18c280b6cb5988aed80ed714a7f2df808d279
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A4C1E332B28A42C5EF90EF65C880ABD7761EB48B98B501235DE1E5BBD8CFB8D411C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Find$CloseFileFirst
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2295610775-0
                                                                                                                                                                                                                                                            • Opcode ID: c8bb1e00aee5117eaed99adb2432ba14ac7573cdfbb2fa81c580c042f8a510df
                                                                                                                                                                                                                                                            • Instruction ID: 20c57f1a02fce89bb7a5b43a1a5323e2dcfbc337d7b2086a9509702143c2ef8e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c8bb1e00aee5117eaed99adb2432ba14ac7573cdfbb2fa81c580c042f8a510df
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 72F06866A18646C6FBE09B60B459B66B350FF847A4F844335DEAE42AD4DFFCD009CB10
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorFileLastModuleName
                                                                                                                                                                                                                                                            • String ID: Could not create temporary directory!$Could not load PyInstaller's embedded PKG archive from the executable (%s)$Could not side-load PyInstaller's PKG archive from external file (%s)$Failed to convert DLL search path!$Failed to initialize security descriptor for temporary directory!$Failed to load Tcl/Tk shared libraries for splash screen!$Failed to load splash screen resources!$Failed to remove temporary directory: %s$Failed to start splash screen!$Failed to unpack splash screen dependencies from PKG archive!$Invalid value in _PYI_PARENT_PROCESS_LEVEL: %s$MEI$PYINSTALLER_RESET_ENVIRONMENT$PYINSTALLER_STRICT_UNPACK_MODE$PYINSTALLER_SUPPRESS_SPLASH_SCREEN$Path exceeds PYI_PATH_MAX limit.$Py_GIL_DISABLED$VCRUNTIME140.dll$_PYI_APPLICATION_HOME_DIR$_PYI_APPLICATION_HOME_DIR not set for onefile child process!$_PYI_ARCHIVE_FILE$_PYI_PARENT_PROCESS_LEVEL$_PYI_SPLASH_IPC$hide-early$hide-late$minimize-early$minimize-late$pkg$pyi-contents-directory$pyi-hide-console$pyi-python-flag$pyi-runtime-tmpdir
                                                                                                                                                                                                                                                            • API String ID: 2776309574-3325264605
                                                                                                                                                                                                                                                            • Opcode ID: a87ce1111aaa9f75919e0f10b033bef507aa605cb544164b54aab19a29868a2d
                                                                                                                                                                                                                                                            • Instruction ID: 0209b71196b7997057d6a63c30d0245b23abee0407367805cdd925bdd4c4055d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a87ce1111aaa9f75919e0f10b033bef507aa605cb544164b54aab19a29868a2d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 19428B21E0C682D0FFE5BB21D815AF9E691AF54780FC44032DE9E466D6EEECE548C360

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 805 7ff762a81930-7ff762a8196b call 7ff762a839d0 808 7ff762a81c2e-7ff762a81c52 call 7ff762a8bb10 805->808 809 7ff762a81971-7ff762a819b1 call 7ff762a873d0 805->809 814 7ff762a81c1b-7ff762a81c1e call 7ff762a8f5a4 809->814 815 7ff762a819b7-7ff762a819c7 call 7ff762a8fc2c 809->815 819 7ff762a81c23-7ff762a81c2b 814->819 820 7ff762a819c9-7ff762a819e3 call 7ff762a95e48 call 7ff762a82020 815->820 821 7ff762a819e8-7ff762a81a04 call 7ff762a8f8f4 815->821 819->808 820->814 827 7ff762a81a06-7ff762a81a20 call 7ff762a95e48 call 7ff762a82020 821->827 828 7ff762a81a25-7ff762a81a3a call 7ff762a95e68 821->828 827->814 834 7ff762a81a3c-7ff762a81a56 call 7ff762a95e48 call 7ff762a82020 828->834 835 7ff762a81a5b-7ff762a81ae5 call 7ff762a81c60 * 2 call 7ff762a8fc2c call 7ff762a95e84 828->835 834->814 849 7ff762a81aea-7ff762a81af4 835->849 850 7ff762a81af6-7ff762a81b10 call 7ff762a95e48 call 7ff762a82020 849->850 851 7ff762a81b15-7ff762a81b2e call 7ff762a8f8f4 849->851 850->814 857 7ff762a81b30-7ff762a81b4a call 7ff762a95e48 call 7ff762a82020 851->857 858 7ff762a81b4f-7ff762a81b6b call 7ff762a8f668 851->858 857->814 864 7ff762a81b7e-7ff762a81b8c 858->864 865 7ff762a81b6d-7ff762a81b79 call 7ff762a81e50 858->865 864->814 868 7ff762a81b92-7ff762a81b99 864->868 865->814 871 7ff762a81ba1-7ff762a81ba7 868->871 872 7ff762a81ba9-7ff762a81bb6 871->872 873 7ff762a81bc0-7ff762a81bcf 871->873 874 7ff762a81bd1-7ff762a81bda 872->874 873->873 873->874 875 7ff762a81bdc-7ff762a81bdf 874->875 876 7ff762a81bef 874->876 875->876 878 7ff762a81be1-7ff762a81be4 875->878 877 7ff762a81bf1-7ff762a81c04 876->877 879 7ff762a81c0d-7ff762a81c19 877->879 880 7ff762a81c06 877->880 878->876 881 7ff762a81be6-7ff762a81be9 878->881 879->814 879->871 880->879 881->876 882 7ff762a81beb-7ff762a81bed 881->882 882->877
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A873D0: _fread_nolock.LIBCMT ref: 00007FF762A8747A
                                                                                                                                                                                                                                                            • _fread_nolock.LIBCMT ref: 00007FF762A819FB
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A82020: GetCurrentProcessId.KERNEL32(?,?,?,?,00000000,00000000,?,00000000,00007FF762A81B4A), ref: 00007FF762A82070
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _fread_nolock$CurrentProcess
                                                                                                                                                                                                                                                            • String ID: Could not allocate buffer for TOC!$Could not allocate memory for archive structure!$Could not read full TOC!$Error on file.$Failed to read cookie!$Failed to seek to cookie position!$MEI$calloc$fread$fseek$malloc
                                                                                                                                                                                                                                                            • API String ID: 2397952137-3497178890
                                                                                                                                                                                                                                                            • Opcode ID: ac955d15e7f6fe3a9e8e3d515fa619d732a5d365b4ae2fbb1a0359e78cae8bc0
                                                                                                                                                                                                                                                            • Instruction ID: 9cdccab4bf7e56fc91621882ccb54258a177c061bf0799454fbd2a9d34c76cd1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ac955d15e7f6fe3a9e8e3d515fa619d732a5d365b4ae2fbb1a0359e78cae8bc0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3281AE71A08A86C5EFD0EB24D045AB9A3A1EF48784FD04036DE8D47B99DEFCE445CB60

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 883 701a0ae0-701a0afa 884 701a0f5c-701a0fae call 7019ec80 883->884 885 701a0b00-701a0b03 883->885 895 701a0fb4-701a0fb7 884->895 896 701a1165-701a1179 call 7019ec80 884->896 886 701a0b09-701a0b15 885->886 887 701a0f43-701a0f57 call 7019ec80 885->887 889 701a0f2a-701a0f3e call 7019ec80 886->889 890 701a0b1b-701a0b58 call 701a2790 886->890 887->884 889->887 897 701a0b5d-701a0b61 890->897 899 701a114c-701a1160 call 7019ec80 895->899 900 701a0fbd-701a0fc0 895->900 901 701a117e-701a1192 call 7019ec80 896->901 903 701a0b63-701a0b74 897->903 904 701a0b75-701a0b8e calloc 897->904 899->896 900->901 902 701a0fc6-701a0fce 900->902 911 701a1197-701a11b1 901->911 906 701a0fe0-701a0fe3 902->906 907 701a0fd0-701a0fdf 902->907 908 701a0cd2-701a0d19 call 701a29b0 904->908 909 701a0b94-701a0bcc call 701a3840 904->909 906->907 912 701a0fe5-701a0fee call 701a2bf0 906->912 926 701a0d20-701a0d2d 908->926 920 701a0bce-701a0c26 call 701a36d0 909->920 921 701a0c40-701a0c7a call 701a36d0 909->921 922 701a10a6-701a10dc call 701a29b0 911->922 923 701a11b7-701a11cf 911->923 912->907 925 701a0ff0-701a1024 call 701a2790 912->925 933 701a0c28 920->933 934 701a0c89 920->934 921->926 936 701a0c80-701a0c83 921->936 947 701a10e5-701a10fc 922->947 923->922 942 701a11d5-701a1219 call 701a2790 923->942 925->907 944 701a1026-701a1036 925->944 939 701a0d33-701a0d44 926->939 940 701a0ea0-701a0eb0 926->940 941 701a0c2e-701a0c36 free 933->941 943 701a0c8b-701a0ccd call 701a29b0 934->943 936->926 936->934 939->943 953 701a0d4a-701a0e8a call 701a36d0 939->953 957 701a0ebc-701a0f0f call 701a36d0 940->957 958 701a0eb2-701a0eb7 940->958 941->903 954 701a121b-701a1227 942->954 955 701a1229-701a1239 call 701a5f40 942->955 943->941 944->922 956 701a1038-701a103a 944->956 947->922 961 701a10fe-701a111b 947->961 972 701a0f1a-701a0f25 953->972 973 701a0e90-701a0e95 953->973 954->955 975 701a123e-701a1253 954->975 955->922 964 701a1090-701a10a4 call 701a2a60 956->964 957->934 970 701a0f15 957->970 958->943 961->922 976 701a111d-701a112f 961->976 964->922 977 701a1040-701a1057 964->977 970->972 972->941 973->943 975->955 981 701a1255-701a126b 975->981 976->911 985 701a1131-701a1145 call 701a2a60 976->985 977->922 984 701a1059-701a1076 977->984 981->955 989 701a126d-701a1284 981->989 984->922 991 701a1078-701a108a 984->991 985->947 992 701a1147 985->992 989->955 995 701a1286-701a12a0 989->995 991->964 991->985 992->922 995->955 997 701a12a2-701a12ba 995->997 997->955 999 701a12c0-701a12db 997->999 999->955 1001 701a12e1-701a12f7 999->1001 1001->955 1003 701a12fd-701a130b 1001->1003 1003->955 1005 701a1311-701a131f 1003->1005 1005->955 1007 701a1325-701a132c 1005->1007 1007->922
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: callocfree
                                                                                                                                                                                                                                                            • String ID: in != NULL$key != NULL$key != NULL$ltc_mp.name != NULL$ltc_mp.name != NULL$size > 0$src/pk/rsa/rsa_import.c$src/pk/rsa/rsa_make_key.c
                                                                                                                                                                                                                                                            • API String ID: 306872129-2031961738
                                                                                                                                                                                                                                                            • Opcode ID: 54b2554e38001375c1a0e020d11789e0834ceb482827cca65a755c51bbaa414a
                                                                                                                                                                                                                                                            • Instruction ID: c957a3dd69c1c5ce4e982145441e36976485b4d7137b39b17cd2c16ead7f70b0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 54b2554e38001375c1a0e020d11789e0834ceb482827cca65a755c51bbaa414a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 93121AB6208B80C6E7608F62E44478EB7B5F784B98F104116EF8E87B58DF79D589CB40
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: a != NULL$b != NULL$c != NULL$d != NULL$src/math/tfm_desc.c
                                                                                                                                                                                                                                                            • API String ID: 0-1480740242
                                                                                                                                                                                                                                                            • Opcode ID: 1492749e04c81861c4cdd4fb8d0ff21c03dc4c47115b40cc82a8ba9f5aca0f49
                                                                                                                                                                                                                                                            • Instruction ID: 75073e56af50f3f69bd586369297c29b2f386fa82bb1814c47ac470caf3a13d4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1492749e04c81861c4cdd4fb8d0ff21c03dc4c47115b40cc82a8ba9f5aca0f49
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6292F665B29685E5FF089754DA893AC23F1EB5538CF80C929CD0F43BA0DA2DE687C705

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$fread$fseek$malloc
                                                                                                                                                                                                                                                            • API String ID: 2050909247-3659356012
                                                                                                                                                                                                                                                            • Opcode ID: 8a96ec6d56a324ff58f098d83054f195dd52cd89981cd53588a3651a40864c79
                                                                                                                                                                                                                                                            • Instruction ID: 53c96c7e063e2e1755c8f92174668801f7bcc3ac32aabbb1a1347e2497013621
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8a96ec6d56a324ff58f098d83054f195dd52cd89981cd53588a3651a40864c79
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 25416D22A08682C6EF85FF219441AB9E391EF48B94FD44432ED5D07A99DEFCE901C760

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 1636 7ff762a811f0-7ff762a8124d call 7ff762a8b340 1639 7ff762a81277-7ff762a8128f call 7ff762a95e84 1636->1639 1640 7ff762a8124f-7ff762a81276 call 7ff762a81e50 1636->1640 1645 7ff762a812b4-7ff762a812c4 call 7ff762a95e84 1639->1645 1646 7ff762a81291-7ff762a812af call 7ff762a95e48 call 7ff762a82020 1639->1646 1651 7ff762a812e9-7ff762a812fb 1645->1651 1652 7ff762a812c6-7ff762a812e4 call 7ff762a95e48 call 7ff762a82020 1645->1652 1659 7ff762a81419-7ff762a8144d call 7ff762a8b020 call 7ff762a95e70 * 2 1646->1659 1655 7ff762a81300-7ff762a8131d call 7ff762a8f8f4 1651->1655 1652->1659 1662 7ff762a81322-7ff762a81325 1655->1662 1665 7ff762a8132b-7ff762a81335 call 7ff762a8f668 1662->1665 1666 7ff762a81411 1662->1666 1665->1666 1672 7ff762a8133b-7ff762a81347 1665->1672 1666->1659 1674 7ff762a81350-7ff762a81378 call 7ff762a89780 1672->1674 1677 7ff762a8137a-7ff762a8137d 1674->1677 1678 7ff762a813f6-7ff762a8140c call 7ff762a81e50 1674->1678 1679 7ff762a813f1 1677->1679 1680 7ff762a8137f-7ff762a81389 1677->1680 1678->1666 1679->1678 1682 7ff762a8138b-7ff762a813a1 call 7ff762a90034 1680->1682 1683 7ff762a813b4-7ff762a813b7 1680->1683 1692 7ff762a813a3-7ff762a813ad call 7ff762a8f668 1682->1692 1693 7ff762a813af-7ff762a813b2 1682->1693 1685 7ff762a813ca-7ff762a813cf 1683->1685 1686 7ff762a813b9-7ff762a813c7 call 7ff762aab0a0 1683->1686 1685->1674 1687 7ff762a813d5-7ff762a813d8 1685->1687 1686->1685 1690 7ff762a813ec-7ff762a813ef 1687->1690 1691 7ff762a813da-7ff762a813dd 1687->1691 1690->1666 1691->1678 1695 7ff762a813df-7ff762a813e7 1691->1695 1692->1685 1692->1693 1693->1678 1695->1655
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: 1.3.1$Failed to extract %s: decompression resulted in return code %d!$Failed to extract %s: failed to allocate temporary input buffer!$Failed to extract %s: failed to allocate temporary output buffer!$Failed to extract %s: inflateInit() failed with return code %d!$malloc
                                                                                                                                                                                                                                                            • API String ID: 2050909247-2813020118
                                                                                                                                                                                                                                                            • Opcode ID: 9affaf0de7306ce34d3fe18153eb52c63318511bddc6c8cbbd58f27af357ba63
                                                                                                                                                                                                                                                            • Instruction ID: 3f1b78f1634af4d99bcdff370af77eab22e9422f6a3c10268cd3a21c60dcf5ff
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9affaf0de7306ce34d3fe18153eb52c63318511bddc6c8cbbd58f27af357ba63
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3251E262A08A82C5EFE0BB15A440BBAA291FF84794FD44135ED5D47BD5EEFCE801C750

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetModuleFileNameW.KERNEL32(?,00007FF762A82BC5), ref: 00007FF762A82AA1
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A82BC5), ref: 00007FF762A82AAB
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A82310: GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,00007FF762A82AC6,?,00007FF762A82BC5), ref: 00007FF762A82360
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A82310: FormatMessageW.KERNEL32(?,?,?,?,?,?,?,?,00007FF762A82AC6,?,00007FF762A82BC5), ref: 00007FF762A8241A
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentErrorFileFormatLastMessageModuleNameProcess
                                                                                                                                                                                                                                                            • String ID: Failed to convert executable path to UTF-8.$Failed to obtain executable path.$Failed to resolve full path to executable %ls.$GetModuleFileNameW$\\?\
                                                                                                                                                                                                                                                            • API String ID: 4002088556-2863816727
                                                                                                                                                                                                                                                            • Opcode ID: 093d1e49c6a3f32bbd7db28c580ca23961d52f0e240546522d41da137270d6a4
                                                                                                                                                                                                                                                            • Instruction ID: a4b40ac2ce78d5381e56b91b096a020cb695683fc068692abd230afe6ea539d3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 093d1e49c6a3f32bbd7db28c580ca23961d52f0e240546522d41da137270d6a4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 74218661B19582C1FFE0BB20E855BB6E250BF58784FC00132EE5D869E5EEECE504C760

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 1797 7ff762a9c95c-7ff762a9c982 1798 7ff762a9c984-7ff762a9c998 call 7ff762a95e28 call 7ff762a95e48 1797->1798 1799 7ff762a9c99d-7ff762a9c9a1 1797->1799 1813 7ff762a9cd8e 1798->1813 1800 7ff762a9cd77-7ff762a9cd83 call 7ff762a95e28 call 7ff762a95e48 1799->1800 1801 7ff762a9c9a7-7ff762a9c9ae 1799->1801 1819 7ff762a9cd89 _invalid_parameter_noinfo 1800->1819 1801->1800 1804 7ff762a9c9b4-7ff762a9c9e2 1801->1804 1804->1800 1807 7ff762a9c9e8-7ff762a9c9ef 1804->1807 1811 7ff762a9c9f1-7ff762a9ca03 call 7ff762a95e28 call 7ff762a95e48 1807->1811 1812 7ff762a9ca08-7ff762a9ca0b 1807->1812 1811->1819 1816 7ff762a9ca11-7ff762a9ca17 1812->1816 1817 7ff762a9cd73-7ff762a9cd75 1812->1817 1818 7ff762a9cd91-7ff762a9cda8 1813->1818 1816->1817 1821 7ff762a9ca1d-7ff762a9ca20 1816->1821 1817->1818 1819->1813 1821->1811 1823 7ff762a9ca22-7ff762a9ca47 1821->1823 1825 7ff762a9ca7a-7ff762a9ca81 1823->1825 1826 7ff762a9ca49-7ff762a9ca4b 1823->1826 1827 7ff762a9ca83-7ff762a9ca8f call 7ff762a9e6c4 1825->1827 1828 7ff762a9ca56-7ff762a9ca6d call 7ff762a95e28 call 7ff762a95e48 _invalid_parameter_noinfo 1825->1828 1829 7ff762a9ca72-7ff762a9ca78 1826->1829 1830 7ff762a9ca4d-7ff762a9ca54 1826->1830 1837 7ff762a9ca94-7ff762a9caab call 7ff762a9b464 * 2 1827->1837 1848 7ff762a9cc00 1828->1848 1832 7ff762a9caf8-7ff762a9cb0f 1829->1832 1830->1828 1830->1829 1835 7ff762a9cb11-7ff762a9cb19 1832->1835 1836 7ff762a9cb8a-7ff762a9cb94 call 7ff762aa4b8c 1832->1836 1835->1836 1840 7ff762a9cb1b-7ff762a9cb1d 1835->1840 1846 7ff762a9cb9a-7ff762a9cbaf 1836->1846 1847 7ff762a9cc1e 1836->1847 1861 7ff762a9cac8-7ff762a9caf3 call 7ff762a9d184 1837->1861 1862 7ff762a9caad-7ff762a9cac3 call 7ff762a95e48 call 7ff762a95e28 1837->1862 1840->1836 1844 7ff762a9cb1f-7ff762a9cb35 1840->1844 1844->1836 1849 7ff762a9cb37-7ff762a9cb43 1844->1849 1846->1847 1852 7ff762a9cbb1-7ff762a9cbc3 GetConsoleMode 1846->1852 1851 7ff762a9cc23-7ff762a9cc43 ReadFile 1847->1851 1853 7ff762a9cc03-7ff762a9cc0d call 7ff762a9b464 1848->1853 1849->1836 1854 7ff762a9cb45-7ff762a9cb47 1849->1854 1856 7ff762a9cc49-7ff762a9cc51 1851->1856 1857 7ff762a9cd3d-7ff762a9cd46 GetLastError 1851->1857 1852->1847 1858 7ff762a9cbc5-7ff762a9cbcd 1852->1858 1853->1818 1854->1836 1860 7ff762a9cb49-7ff762a9cb61 1854->1860 1856->1857 1863 7ff762a9cc57 1856->1863 1866 7ff762a9cd63-7ff762a9cd66 1857->1866 1867 7ff762a9cd48-7ff762a9cd5e call 7ff762a95e48 call 7ff762a95e28 1857->1867 1858->1851 1865 7ff762a9cbcf-7ff762a9cbf1 ReadConsoleW 1858->1865 1860->1836 1869 7ff762a9cb63-7ff762a9cb6f 1860->1869 1861->1832 1862->1848 1872 7ff762a9cc5e-7ff762a9cc73 1863->1872 1874 7ff762a9cc12-7ff762a9cc1c 1865->1874 1875 7ff762a9cbf3 GetLastError 1865->1875 1878 7ff762a9cbf9-7ff762a9cbfb call 7ff762a95dbc 1866->1878 1879 7ff762a9cd6c-7ff762a9cd6e 1866->1879 1867->1848 1869->1836 1877 7ff762a9cb71-7ff762a9cb73 1869->1877 1872->1853 1881 7ff762a9cc75-7ff762a9cc80 1872->1881 1874->1872 1875->1878 1877->1836 1884 7ff762a9cb75-7ff762a9cb85 1877->1884 1878->1848 1879->1853 1886 7ff762a9cc82-7ff762a9cc9b call 7ff762a9c574 1881->1886 1887 7ff762a9cca7-7ff762a9ccaf 1881->1887 1884->1836 1894 7ff762a9cca0-7ff762a9cca2 1886->1894 1890 7ff762a9ccb1-7ff762a9ccc3 1887->1890 1891 7ff762a9cd2b-7ff762a9cd38 call 7ff762a9c3b4 1887->1891 1895 7ff762a9ccc5 1890->1895 1896 7ff762a9cd1e-7ff762a9cd26 1890->1896 1891->1894 1894->1853 1898 7ff762a9ccca-7ff762a9ccd1 1895->1898 1896->1853 1899 7ff762a9ccd3-7ff762a9ccd7 1898->1899 1900 7ff762a9cd0d-7ff762a9cd18 1898->1900 1901 7ff762a9ccf3 1899->1901 1902 7ff762a9ccd9-7ff762a9cce0 1899->1902 1900->1896 1903 7ff762a9ccf9-7ff762a9cd09 1901->1903 1902->1901 1904 7ff762a9cce2-7ff762a9cce6 1902->1904 1903->1898 1905 7ff762a9cd0b 1903->1905 1904->1901 1906 7ff762a9cce8-7ff762a9ccf1 1904->1906 1905->1896 1906->1903
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: eb536eff56005b26acab214ddad3b7f617f69f6ae0f39e6e286dc3f6b59ee020
                                                                                                                                                                                                                                                            • Instruction ID: b5cd8617b4287ca5fe1b8e729424905f02e419d85b2470b6077fe63e742b9eec
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: eb536eff56005b26acab214ddad3b7f617f69f6ae0f39e6e286dc3f6b59ee020
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: FDC1B422D2CB86D1EF91AB169840ABDAB56AB89B80FA54131DE4D077D1CEFCDC45C720

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: Failed to load Python DLL '%ls'.$LoadLibrary$Path of Python shared library (%s) and its name (%s) exceed buffer size (%d)$Path of ucrtbase.dll (%s) and its name exceed buffer size (%d)$Reported length (%d) of Python shared library name (%s) exceeds buffer size (%d)$ucrtbase.dll
                                                                                                                                                                                                                                                            • API String ID: 2050909247-2434346643
                                                                                                                                                                                                                                                            • Opcode ID: 0161030ac6cb013b432a21c9304879e0f469f25312fd656d8e332880937228c1
                                                                                                                                                                                                                                                            • Instruction ID: 21d43796e5575746311a1b9b4121ad6fd18e66cdcd534b648317296cc5c87bbe
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0161030ac6cb013b432a21c9304879e0f469f25312fd656d8e332880937228c1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B1416C31A18A86D1EF91EB20E4549E9E355FF44384FC00132EE9E43696EEFCE605C7A0

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 1979 7ff762a9de60-7ff762a9de85 1980 7ff762a9e153 1979->1980 1981 7ff762a9de8b-7ff762a9de8e 1979->1981 1982 7ff762a9e155-7ff762a9e165 1980->1982 1983 7ff762a9de90-7ff762a9dec2 call 7ff762a9b758 1981->1983 1984 7ff762a9dec7-7ff762a9def3 1981->1984 1983->1982 1986 7ff762a9def5-7ff762a9defc 1984->1986 1987 7ff762a9defe-7ff762a9df04 1984->1987 1986->1983 1986->1987 1988 7ff762a9df14-7ff762a9df29 call 7ff762aa4b8c 1987->1988 1989 7ff762a9df06-7ff762a9df0f call 7ff762a9d220 1987->1989 1994 7ff762a9df2f-7ff762a9df38 1988->1994 1995 7ff762a9e043-7ff762a9e04c 1988->1995 1989->1988 1994->1995 1998 7ff762a9df3e-7ff762a9df42 1994->1998 1996 7ff762a9e0a0-7ff762a9e0c5 WriteFile 1995->1996 1997 7ff762a9e04e-7ff762a9e054 1995->1997 1999 7ff762a9e0d0 1996->1999 2000 7ff762a9e0c7-7ff762a9e0cd GetLastError 1996->2000 2001 7ff762a9e056-7ff762a9e059 1997->2001 2002 7ff762a9e08c-7ff762a9e099 call 7ff762a9d918 1997->2002 2003 7ff762a9df44-7ff762a9df4c call 7ff762a95270 1998->2003 2004 7ff762a9df53-7ff762a9df5e 1998->2004 2005 7ff762a9e0d3 1999->2005 2000->1999 2006 7ff762a9e078-7ff762a9e08a call 7ff762a9db38 2001->2006 2007 7ff762a9e05b-7ff762a9e05e 2001->2007 2019 7ff762a9e09e 2002->2019 2003->2004 2009 7ff762a9df60-7ff762a9df69 2004->2009 2010 7ff762a9df6f-7ff762a9df84 GetConsoleMode 2004->2010 2012 7ff762a9e0d8 2005->2012 2027 7ff762a9e030-7ff762a9e037 2006->2027 2013 7ff762a9e0e4-7ff762a9e0ee 2007->2013 2014 7ff762a9e064-7ff762a9e076 call 7ff762a9da1c 2007->2014 2009->1995 2009->2010 2017 7ff762a9df8a-7ff762a9df90 2010->2017 2018 7ff762a9e03c 2010->2018 2020 7ff762a9e0dd 2012->2020 2021 7ff762a9e0f0-7ff762a9e0f5 2013->2021 2022 7ff762a9e14c-7ff762a9e151 2013->2022 2014->2027 2025 7ff762a9df96-7ff762a9df99 2017->2025 2026 7ff762a9e019-7ff762a9e02b call 7ff762a9d4a0 2017->2026 2018->1995 2019->2027 2020->2013 2028 7ff762a9e123-7ff762a9e12d 2021->2028 2029 7ff762a9e0f7-7ff762a9e0fa 2021->2029 2022->1982 2031 7ff762a9dfa4-7ff762a9dfb2 2025->2031 2032 7ff762a9df9b-7ff762a9df9e 2025->2032 2026->2027 2027->2012 2038 7ff762a9e12f-7ff762a9e132 2028->2038 2039 7ff762a9e134-7ff762a9e143 2028->2039 2036 7ff762a9e113-7ff762a9e11e call 7ff762a95e04 2029->2036 2037 7ff762a9e0fc-7ff762a9e10b 2029->2037 2034 7ff762a9e010-7ff762a9e014 2031->2034 2035 7ff762a9dfb4 2031->2035 2032->2020 2032->2031 2034->2005 2040 7ff762a9dfb8-7ff762a9dfcf call 7ff762aa4c58 2035->2040 2036->2028 2037->2036 2038->1980 2038->2039 2039->2022 2045 7ff762a9dfd1-7ff762a9dfdd 2040->2045 2046 7ff762a9e007-7ff762a9e00d GetLastError 2040->2046 2047 7ff762a9dfdf-7ff762a9dff1 call 7ff762aa4c58 2045->2047 2048 7ff762a9dffc-7ff762a9e003 2045->2048 2046->2034 2047->2046 2052 7ff762a9dff3-7ff762a9dffa 2047->2052 2048->2034 2050 7ff762a9e005 2048->2050 2050->2040 2052->2048
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF762A9DE4B), ref: 00007FF762A9DF7C
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF762A9DE4B), ref: 00007FF762A9E007
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ConsoleErrorLastMode
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 953036326-0
                                                                                                                                                                                                                                                            • Opcode ID: 25026d299ec132fa7e986de3a50f80dd4a1c565eb46710a002b358a032e27337
                                                                                                                                                                                                                                                            • Instruction ID: 1055568a3024df04c8a97351638b89f211bc3553faaa674d19d5f1a5ac4f9bfe
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 25026d299ec132fa7e986de3a50f80dd4a1c565eb46710a002b358a032e27337
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6991D932E28651C5FF90BF269940A7DA7A0BB00784FA45136DE0E57A85DFFCD885C720

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CloseCreateFileHandle_invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1279662727-0
                                                                                                                                                                                                                                                            • Opcode ID: a7851f35165aa053145fe01894016aececa3f2381e8a001c745c02259ff3d92e
                                                                                                                                                                                                                                                            • Instruction ID: 1d4c280814045b6b113e556a0676c368050eeb46ef9f23369315e2629d3353b5
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a7851f35165aa053145fe01894016aececa3f2381e8a001c745c02259ff3d92e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BF417422D28742C3EB94AB219950769B360FF95764F609334EF9802BD5DFECA5A0C750

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(?,00000000,00000000,?,00000000,00007FF762A81B79), ref: 00007FF762A81E9E
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: ERROR$[PYI-%d:%s]
                                                                                                                                                                                                                                                            • API String ID: 2050909247-3005936843
                                                                                                                                                                                                                                                            • Opcode ID: c1c0bec23ccac853a0e083361079492e25c9a947d7081d13b76ea5259852d608
                                                                                                                                                                                                                                                            • Instruction ID: fbb9aa96cad8fe0aac67ead9085d39c394e14a168c263ea92d088d53b0dfccca
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c1c0bec23ccac853a0e083361079492e25c9a947d7081d13b76ea5259852d608
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BF114F72A19B8181EBA0AB51B8819EAB764EF847C4F800135EE8D53A59DEFCD155C610

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Process$CurrentExitTerminate
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1703294689-0
                                                                                                                                                                                                                                                            • Opcode ID: 823bef23182f8f61d7efa7880482c28a4a7867c446eada0463010af46261c3c5
                                                                                                                                                                                                                                                            • Instruction ID: 80aa115545d0a2f25646fd037a361da20450e8e2ca5893d271370b2133bb8766
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 823bef23182f8f61d7efa7880482c28a4a7867c446eada0463010af46261c3c5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CFD06714F18A02C6EFD43B715C55AB992526F88711F911439CC8E06793CEEDA84DC661
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: eff41cba983b05e0f9e09f52185aba8178b112ae95ee52c2a1f9a5fdd57fcc68
                                                                                                                                                                                                                                                            • Instruction ID: ccd5b15bd26ff0062105115670d7ae5050bfe258eeb9f19e5cdd41f8a533b290
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: eff41cba983b05e0f9e09f52185aba8178b112ae95ee52c2a1f9a5fdd57fcc68
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1E51B721B09287C6FFA4BA269400E79A691BF44BA4FE44738DD6D877D9CEFCD401C620
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_release_startup_lock
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1236291503-0
                                                                                                                                                                                                                                                            • Opcode ID: bbbb43f9e1356fc36a8983c03ebcc8b7addcb0e166801d8c410c30bb16f29642
                                                                                                                                                                                                                                                            • Instruction ID: 8c177f62fcb0ab825c3f5e36381729e5dbe8ac4df7cc6b31c5dfd3f3ea1e746d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bbbb43f9e1356fc36a8983c03ebcc8b7addcb0e166801d8c410c30bb16f29642
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EB318A21E0C202C2EFC8BB65A511BB9E392AF44B84FC45135ED4D476D3DEECA805CA76
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorFileLastWrite
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 442123175-0
                                                                                                                                                                                                                                                            • Opcode ID: 8ebc058675795335f9a47618937f9bde65187aaad64a1c6bbc7aea363135bb52
                                                                                                                                                                                                                                                            • Instruction ID: 68f5bef18c585d27fd5ec6ee3fe52288f13adf1b6584937d493340f15f39b310
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8ebc058675795335f9a47618937f9bde65187aaad64a1c6bbc7aea363135bb52
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4431D632A18A81CADB90BF15E844699B760FB58780F944032DF8D87B19DFBCD555C720
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileHandleType
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3000768030-0
                                                                                                                                                                                                                                                            • Opcode ID: b01a8b1655aeb6f71db35254c5ecf6a703e147159c44eee076082fbba724bcfb
                                                                                                                                                                                                                                                            • Instruction ID: 4c6de9cd4c7a38fb3c4ca0c5334725aba6448df670cdbb4fa152bd25398fccf2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b01a8b1655aeb6f71db35254c5ecf6a703e147159c44eee076082fbba724bcfb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1031A821E28F55C1EFA06B16894057AA650FB45BB0BB41375DF6E173E0CFB8E891D310
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • SetFilePointerEx.KERNEL32(?,?,?,?,?,00007FF762A9D020,?,?,?,?,?,00007FF762A9D129), ref: 00007FF762A9D080
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,?,?,00007FF762A9D020,?,?,?,?,?,00007FF762A9D129), ref: 00007FF762A9D08A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorFileLastPointer
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2976181284-0
                                                                                                                                                                                                                                                            • Opcode ID: fb6a81950565da05b050a92576ed7c02e19ce8787ed1f1a96796d90f6b6408b2
                                                                                                                                                                                                                                                            • Instruction ID: 7ac58a39d0dd6aa29dc396bf9e43602a6ea6e79eb812604a8c77b92933ef2d2f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fb6a81950565da05b050a92576ed7c02e19ce8787ed1f1a96796d90f6b6408b2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6711E661A18A81C1DF90AB26A800469E361AB40BF4FA40331EE7E0B7D4CEFCD441C754
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • CloseHandle.KERNEL32(?,?,?,00007FF762A9B8DD,?,?,00000000,00007FF762A9B992), ref: 00007FF762A9BACE
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,00007FF762A9B8DD,?,?,00000000,00007FF762A9B992), ref: 00007FF762A9BAD8
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CloseErrorHandleLast
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 918212764-0
                                                                                                                                                                                                                                                            • Opcode ID: ee1f6f2c17bcac9912aebe9a75d3c59e1af1689cfc13c1c78b5a219ca8e97850
                                                                                                                                                                                                                                                            • Instruction ID: a0ce796d3a03291a76ce138bd3ada39696f08d231e0c8c541b0a329968850daa
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ee1f6f2c17bcac9912aebe9a75d3c59e1af1689cfc13c1c78b5a219ca8e97850
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C1219220F2868282FFD0B762A99067D92815F44BA0FA44735DE2E47BD1CEECA845C321
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: cf3d959f73a155a0d737dce44897d7a2acb78217b54b69b3c35a670fde34ce7f
                                                                                                                                                                                                                                                            • Instruction ID: 88f79434331af50a67a07f9e3dcd5a841918a12e38c5f0f9787ad5234f3a7365
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cf3d959f73a155a0d737dce44897d7a2acb78217b54b69b3c35a670fde34ce7f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2441DE32D28641C7EFA4EB1A9940679B795EB59740F600135DE8E47AD0CFFDE802C761
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _fread_nolock
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 840049012-0
                                                                                                                                                                                                                                                            • Opcode ID: 024a65eceea4021ca9242a00480abe65ac50bece6db994538720df64ffac909c
                                                                                                                                                                                                                                                            • Instruction ID: 4c7fbfb07f36f73c3d465c305f708b70d6876cb5e6d1f401861c3836eba02737
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 024a65eceea4021ca9242a00480abe65ac50bece6db994538720df64ffac909c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EE217E25F08692C6EF90BA126904BBADA41BF45BD8FC84430EE4D4A786CEFDE441C620
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: 253ecda3210493d2f26eb4f52b5119aed9cb222ec82c37949b93d1e134238cda
                                                                                                                                                                                                                                                            • Instruction ID: 84874aae13cdb02bb408ab9f9a6e2c680e13b27a297ce8eb451a6adb634ea059
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 253ecda3210493d2f26eb4f52b5119aed9cb222ec82c37949b93d1e134238cda
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 73315E32E28A16C9EF917B569C41B7CA695AB48B91FE14135DE1D033D2CEFCA841C720
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_ctrl
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3605655398-0
                                                                                                                                                                                                                                                            • Opcode ID: 6d0a7c46b07cd7016860ecfb13084718b787f51b2db9be319604d8e51638b5c7
                                                                                                                                                                                                                                                            • Instruction ID: 90f09d3d69318fbc9b963d408728500590c9a268634649577667f7ddd2420d5b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6d0a7c46b07cd7016860ecfb13084718b787f51b2db9be319604d8e51638b5c7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 22218C32719B8186E7548F61E450BDA7760FB85B88F484136EF9C4BB8DCF78C9408B00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: HandleModule$AddressFreeLibraryProc
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3947729631-0
                                                                                                                                                                                                                                                            • Opcode ID: 78c35fc7c6e2b8000ddfa863f9affaf41ca53d2f0572e0ba78e1a207ed009a92
                                                                                                                                                                                                                                                            • Instruction ID: fce90697fa1f0173cb382859a1086356d8cf3bd684d1f537fb623d8dca0e6bb1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 78c35fc7c6e2b8000ddfa863f9affaf41ca53d2f0572e0ba78e1a207ed009a92
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 00218032E14605CEEF94AFA5C8406AC73A1FB04318FA50636DA6D06AC6EFB8D944C751
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: 0e1df9a836e05c53306103cf914f9f5afd0b17d2d4247778ac0f8a736a470cc7
                                                                                                                                                                                                                                                            • Instruction ID: 20248e233f184371a5712d859e2842770601669a1b1d3537780b3c0ffca81ed0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0e1df9a836e05c53306103cf914f9f5afd0b17d2d4247778ac0f8a736a470cc7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 12111021E28642C1EFA1AF529801A79E254AF45F80FE44431EE4C57B95CFFDDC51CBA0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: 705a0604598582430d769309be7d52bb613e0b4e097a3a0cc12fb03a34ef158b
                                                                                                                                                                                                                                                            • Instruction ID: ad583caaac7db2ab435ab9ec2b3325fc03c19c3f1d657cb3707413cc1e85eb8b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 705a0604598582430d769309be7d52bb613e0b4e097a3a0cc12fb03a34ef158b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 58218632A18642C6DFE19F19D84077EB6A1AF84B94FA44234DE5D4BAD9DFBCD400CB50
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3215553584-0
                                                                                                                                                                                                                                                            • Opcode ID: 43297e0cb54a728217cf8f13d9f8c23c45e2da10c33361e46a2ef0799771412d
                                                                                                                                                                                                                                                            • Instruction ID: 7d693c7e58ef75422805ef6c5412646471fb603d7a1c6f85e5ab44085a8fe90a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 43297e0cb54a728217cf8f13d9f8c23c45e2da10c33361e46a2ef0799771412d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 11018E21A18742C0EF84AB529801879E694AF95FE0FD88635DE6C53BDADEFCD411C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • __scrt_dllmain_crt_thread_attach.LIBCMT ref: 00007FF762A8C3F0
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A8CE18: __vcrt_uninitialize_ptd.LIBVCRUNTIME ref: 00007FF762A8CE20
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A8CE18: __vcrt_uninitialize_locks.LIBVCRUNTIME ref: 00007FF762A8CE25
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: __scrt_dllmain_crt_thread_attach__vcrt_uninitialize_locks__vcrt_uninitialize_ptd
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1208906642-0
                                                                                                                                                                                                                                                            • Opcode ID: ececd82fc3177ae58a022cdb863293519d79894eaec9217f5cc72d6a823b184f
                                                                                                                                                                                                                                                            • Instruction ID: d216936ecc5f379e15722228186e2a5fabcdee7f9f43f1e8d152a82aea7b3d71
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ececd82fc3177ae58a022cdb863293519d79894eaec9217f5cc72d6a823b184f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9EE09210D6D642D1FFEC36611446AB9C6829F25344ED006B5DD8A921C39DCD2457D935
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A88950: MultiByteToWideChar.KERNEL32(?,?,?,00007FF762A83A04,00000000,00007FF762A81965), ref: 00007FF762A88989
                                                                                                                                                                                                                                                            • LoadLibraryExW.KERNEL32(?,00007FF762A858B6,00000000,00007FF762A8272E), ref: 00007FF762A884E2
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ByteCharLibraryLoadMultiWide
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2592636585-0
                                                                                                                                                                                                                                                            • Opcode ID: f60a4b28f40848f04726842085d853143cffca2c4904261e2b888fe767e0f7e9
                                                                                                                                                                                                                                                            • Instruction ID: 6a4a3c3a195b1f03fffe5637689f56e277efa3e03ffc37b78146ec10d1e4ae8a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f60a4b28f40848f04726842085d853143cffca2c4904261e2b888fe767e0f7e9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4ED0C212F2464681EFC4B767BA4697AA2529F89BC0E988034EE4D03F56DC7CD4818B00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • HeapAlloc.KERNEL32(?,?,00000000,00007FF762A9C22A,?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392), ref: 00007FF762A9FE59
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AllocHeap
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4292702814-0
                                                                                                                                                                                                                                                            • Opcode ID: e5baedaef9e1aefb999d7e678a491e2cb8f7af630fb86e3f47b81283e20e243b
                                                                                                                                                                                                                                                            • Instruction ID: 80d014f22d4a13340f6b0e463828d1d5049597aa24ec4397291e988008084972
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e5baedaef9e1aefb999d7e678a491e2cb8f7af630fb86e3f47b81283e20e243b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F8F0AF10F29207C5FFD57A579D01BB4D2884F48B80FA80038ED0E8A382EEDCA940CA30
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • HeapAlloc.KERNEL32(?,?,?,00007FF762A90268,?,?,?,00007FF762A918D2,?,?,?,?,?,00007FF762A94595), ref: 00007FF762A9E702
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AllocHeap
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4292702814-0
                                                                                                                                                                                                                                                            • Opcode ID: c4f21c11c5720e62b677d9e99b1ce174dfbed18f849e52640c9a6f6ea7657029
                                                                                                                                                                                                                                                            • Instruction ID: 3fe81cb076e96ff65fb46a50b13187af271a4dc52c9bc35d42b5432d0d988f56
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c4f21c11c5720e62b677d9e99b1ce174dfbed18f849e52640c9a6f6ea7657029
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 23F05E11F2C202C5FFE83BA35E41A75D2806F447A1FA80A31EE2E452C3EEDDA840C631
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_free$R_newR_set_debug$O_ctrlO_newO_s_fileR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_rsa.c$SERVERINFO FOR $SERVERINFOV2 FOR $SSL_CTX_use_serverinfo_file
                                                                                                                                                                                                                                                            • API String ID: 1122662597-2528746747
                                                                                                                                                                                                                                                            • Opcode ID: 0569fd1127461df0ac78495252f0f065c20110ce9feb11926496cf74e6b99c14
                                                                                                                                                                                                                                                            • Instruction ID: 83ad35c849868271d39a964d75b4b977e029699fd5b8d269338083f4057980dc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0569fd1127461df0ac78495252f0f065c20110ce9feb11926496cf74e6b99c14
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6CB1D565B2868385FB189B61D8709FD63A5BF44798F8080B6DD2D87BDDDE7CDA058300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Heap$Process$AdaptersAddressesAllocComputerFreeNamemallocstrlen
                                                                                                                                                                                                                                                            • String ID: 01234567$89abcdef$:[sc$Characteristics$NetCfgInstanceId$SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}
                                                                                                                                                                                                                                                            • API String ID: 1478035857-3618987999
                                                                                                                                                                                                                                                            • Opcode ID: 6c676aee9aa6e351fdfa83a77c458ae481204e918b0d3610458ad732b133904f
                                                                                                                                                                                                                                                            • Instruction ID: e65f62340553651df863f4c933dd24887c06cd0150530891a7768b6f60f012dc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6c676aee9aa6e351fdfa83a77c458ae481204e918b0d3610458ad732b133904f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 83F19E723287C08AE720CB66B84479EBBA5F785BC4F454129DE8A87B18DF3CD405CB14
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug$O_freememcpy$O_zalloc
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_srvr.c$tls_process_client_hello
                                                                                                                                                                                                                                                            • API String ID: 2132817427-1456301196
                                                                                                                                                                                                                                                            • Opcode ID: cf98b1c22e46938ab3c9824a624ca8b17ad45a32bf6abfcc7bf73a3e55641af5
                                                                                                                                                                                                                                                            • Instruction ID: 1c42f2f2e833d55ad8f69ce04a8f44d7c532bc46964efdd541be08b1ac04afcf
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cf98b1c22e46938ab3c9824a624ca8b17ad45a32bf6abfcc7bf73a3e55641af5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1202A321B1CA8385FB289B21D460A7D6390EF45B84F80D176EE6E866DDDE3CE291C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: X509_$R_newR_set_debugR_set_error$L_sk_numX_free$D_run_onceL_sk_pop_freeL_sk_valueM_move_peernameM_set1X509_verify_certX_get0_chainX_get1_chainX_get_errorX_initX_new_exX_set0_daneX_set_defaultX_set_ex_dataX_set_flagsX_set_verify_cb
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_cert.c$ssl_client$ssl_server$ssl_verify_cert_chain
                                                                                                                                                                                                                                                            • API String ID: 374146265-1087352319
                                                                                                                                                                                                                                                            • Opcode ID: 38cb83850ea50f4f544b8c07a01951c975ef9c4b0861eb40b163d806d8c327c8
                                                                                                                                                                                                                                                            • Instruction ID: 73132c2bfc2abb9de0feefc93ebfcca2da3a6154367252b0c15a029a57a07f6e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 38cb83850ea50f4f544b8c07a01951c975ef9c4b0861eb40b163d806d8c327c8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C371C369B0864385FF4CAB61C5B1BB91391AF85BC8F8490B1DD2D8B7DEDE2DE9418340
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Palette$Select$Realize$ColorsCompatibleCreateObjectUpdate$BitmapDeleteModeRelease
                                                                                                                                                                                                                                                            • String ID: $Only ZPixmap types are implemented$XGetImageZPixmap Failure
                                                                                                                                                                                                                                                            • API String ID: 4159931456-2551037732
                                                                                                                                                                                                                                                            • Opcode ID: 9340185e78ed9fd7071c3a3033a70bd5c5f577ab5219f89a3ef6cde1afd4e561
                                                                                                                                                                                                                                                            • Instruction ID: 6caa787ecbab1c235cffc4b79419a273efa3cd6700ce2d210554d62d08174c2c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9340185e78ed9fd7071c3a3033a70bd5c5f577ab5219f89a3ef6cde1afd4e561
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 64229172718B86C3DB688F16E4A4A29B7A5FB84B90F045179DE9E43B98DF3CD444DB00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: L_sk_new_nullL_sk_pop_freeR_newR_set_debugX509X509_freeX509_new_exd2i_
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_clnt.c$tls_process_server_certificate
                                                                                                                                                                                                                                                            • API String ID: 3085087540-2730446810
                                                                                                                                                                                                                                                            • Opcode ID: e9a4fc834aa89716036a4f9ad36d6ac857268f789a661d2739c54c79d6464987
                                                                                                                                                                                                                                                            • Instruction ID: 3a5baccab4d7074e18bd26b3372427365909284d5868c0d7074bd83e6320777c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e9a4fc834aa89716036a4f9ad36d6ac857268f789a661d2739c54c79d6464987
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B8C1C461B0CB8245EB289B25D460BBD63A1EF84788F949171DAADC76CEDF3DE581C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_lib.c$SSL_new
                                                                                                                                                                                                                                                            • API String ID: 1552677711-1278568459
                                                                                                                                                                                                                                                            • Opcode ID: 96f50ba53d471986c50c324f7cbadeae805ee7a3248c6187a897ede070d8f3d4
                                                                                                                                                                                                                                                            • Instruction ID: 8c9ff139e4e02c263a571a18b5f9ea0aa6b9d769e9836784b493f4b71d7ad9c6
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 96f50ba53d471986c50c324f7cbadeae805ee7a3248c6187a897ede070d8f3d4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 93E13A36715B8296EB88CF25D550BE873A4FB48B88F444136DF6C8B399EF78E5608310
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: N_clear_free$R_newR_set_debug$N_num_bitsO_clear_freeO_malloc
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\tls_srp.c$srp_generate_client_master_secret
                                                                                                                                                                                                                                                            • API String ID: 1310426286-3880031085
                                                                                                                                                                                                                                                            • Opcode ID: b90a57775e25e2e286002ed3aab0e61506ca9649ce3f25730446de935b7eb68b
                                                                                                                                                                                                                                                            • Instruction ID: 3b5d9a432f33fe4a092d71ee067ecbc9db2a1594fc79990385551ed55c156dba
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b90a57775e25e2e286002ed3aab0e61506ca9649ce3f25730446de935b7eb68b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B061C126B09A8351EB5CAB16D520FF92290BF89BC4F8450B5DE6D87BCADF3CE1518300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • EVP_MD_CTX_new.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA934451
                                                                                                                                                                                                                                                            • EVP_DigestInit.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA934468
                                                                                                                                                                                                                                                            • EVP_DigestUpdate.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA934485
                                                                                                                                                                                                                                                            • EVP_DigestUpdate.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA9344A2
                                                                                                                                                                                                                                                            • EVP_DigestFinal_ex.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA9344BC
                                                                                                                                                                                                                                                            • EVP_MD_CTX_free.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA9344CC
                                                                                                                                                                                                                                                            • CRYPTO_malloc.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA9344EF
                                                                                                                                                                                                                                                            • ERR_new.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA9346C4
                                                                                                                                                                                                                                                            • ERR_set_debug.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA9346D9
                                                                                                                                                                                                                                                            • EVP_PKEY_CTX_free.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA9346F1
                                                                                                                                                                                                                                                            • CRYPTO_clear_free.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA934709
                                                                                                                                                                                                                                                            • ERR_new.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA934710
                                                                                                                                                                                                                                                            • ERR_set_debug.LIBCRYPTO-3(00000000,?,?,?,?,?,?,00007FFDFA935B97), ref: 00007FFDFA934728
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Digest$R_newR_set_debugUpdateX_free$Final_exInitO_clear_freeO_mallocX_new
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_clnt.c$tls_construct_cke_gost18
                                                                                                                                                                                                                                                            • API String ID: 1516884489-304060821
                                                                                                                                                                                                                                                            • Opcode ID: 4718e602e498fa9548965e4fe091250fac36401393b9439c50c4b15e55499c55
                                                                                                                                                                                                                                                            • Instruction ID: 0c8c2a72f9f33c48e8e6700ed1fe0e92c96e6cec73201d0a520c1370c14fc20c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4718e602e498fa9548965e4fe091250fac36401393b9439c50c4b15e55499c55
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F691A225B08A8341FB58AB169830FBA1295AF85788FC550B5ED6DCB7DEDE3CDA418340
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FromPointWindowmemset
                                                                                                                                                                                                                                                            • String ID: &$CLIPBOARD
                                                                                                                                                                                                                                                            • API String ID: 908244748-1846057221
                                                                                                                                                                                                                                                            • Opcode ID: d3497a70072ca7c5c3a631fbc713c5beab918abeb7523b5a66c386af0f96041f
                                                                                                                                                                                                                                                            • Instruction ID: d9a8e2d58000c51f5e1b839cbb1d33c19f91e4283a644923e2848d61b83a8b50
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d3497a70072ca7c5c3a631fbc713c5beab918abeb7523b5a66c386af0f96041f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A7F1C172B08282CBF7588F29D464A7E7BA1FB44744F545179EA6A87BD8DE3CE440DB00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: J_nid2snO_zallocP_get_digestbyname
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_lib.c$dane_ctx_enable
                                                                                                                                                                                                                                                            • API String ID: 481619167-1287278166
                                                                                                                                                                                                                                                            • Opcode ID: c2867071a3303bf8944f2cc0cf556ee6616352100b3f4d2b810e73fdd564d021
                                                                                                                                                                                                                                                            • Instruction ID: 9d0b8fcbb0421dfa411074fb5ee837061063819676c59728773580b6c94fd093
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c2867071a3303bf8944f2cc0cf556ee6616352100b3f4d2b810e73fdd564d021
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1E31E161F1878282FB8C9351E561BB91690EF457C4F8490B8ED6D4BBCEDF6CE6518300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug$O_free
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_clnt.c$D:\a\1\s\include\internal/packet.h$tls_process_ske_psk_preamble
                                                                                                                                                                                                                                                            • API String ID: 1233037391-1906891150
                                                                                                                                                                                                                                                            • Opcode ID: 0b6528a612a63d93a0904871f21b1c017866618bc446eba2776d67c557741d00
                                                                                                                                                                                                                                                            • Instruction ID: f0c4fa71f967e3f71801bb971e6090f14a234940fa2dc59516883dd57a64b6ea
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0b6528a612a63d93a0904871f21b1c017866618bc446eba2776d67c557741d00
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2641D421F1CA9241F3149B15E420FAD6760AF89784FC45171EEAC87BCECF6DE6818700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_free$O_mallocmemset
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\record\rec_layer_d1.c$dtls1_buffer_record
                                                                                                                                                                                                                                                            • API String ID: 1168073369-935135588
                                                                                                                                                                                                                                                            • Opcode ID: 94fbb7bed2ab732a1c41d67245f5f2ebe7cdf28c899c3715c231e9dc3647a586
                                                                                                                                                                                                                                                            • Instruction ID: 2714ce53a2c55c2accf4930b9606a2ab6f079226f16e86ccd95815a6060d3c12
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 94fbb7bed2ab732a1c41d67245f5f2ebe7cdf28c899c3715c231e9dc3647a586
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 18519411F18B8681F718DB25E560AF96351FF99BC4F84A271EE6D4679AEF2CE1818300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CombineCreateDeleteObjectRectmemcpymemset$Indirect
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4136945625-0
                                                                                                                                                                                                                                                            • Opcode ID: 54afd1366b1766e0bfdbe5d045e29cab90dba55b2ae09bed171dc4b45d8606fe
                                                                                                                                                                                                                                                            • Instruction ID: 0704fdfa944d0ed43873615e4fc6f314bd6500d19e110c3cd3ad2bdde90daf16
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 54afd1366b1766e0bfdbe5d045e29cab90dba55b2ae09bed171dc4b45d8606fe
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E1A1A262B0864287EB68BF6AA460A3AB7E1FF45B85F100175D95E53ADCEF3CE441C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_reallocR_newR_set_debugR_set_errormemcpy
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\t1_lib.c$?$@$gid_cb$group '%s' cannot be set
                                                                                                                                                                                                                                                            • API String ID: 2487840641-1486293874
                                                                                                                                                                                                                                                            • Opcode ID: 6586109db5c7ad4861b72bb4f3107577c9dc97d18332b1779b98e788b5f3472e
                                                                                                                                                                                                                                                            • Instruction ID: d897d721047caeb7f5e32fde7a15f3706439db5f6a7e335411b39ed47294c9c0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6586109db5c7ad4861b72bb4f3107577c9dc97d18332b1779b98e788b5f3472e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7B41E969B0969641EF689B65E420AB967A1FFD47C0FCC8072DE5DC77D9EE2CD5008300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug$O_freeO_malloc
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_parse_stoc_sct
                                                                                                                                                                                                                                                            • API String ID: 3068916411-3063144252
                                                                                                                                                                                                                                                            • Opcode ID: 0dc04de0c3e8958578d00c6267740bbd28eb958337bcad495197dfb001f8af13
                                                                                                                                                                                                                                                            • Instruction ID: 9b67ee8f4069c9ba0c7ab2214ee273009a364a79031ea30731b89f0dd11a8999
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0dc04de0c3e8958578d00c6267740bbd28eb958337bcad495197dfb001f8af13
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F441E525B18B8341F7589B11E820FBA6690EF84788F985075EE6D8BFDDDF2DE5008700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: State
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1649606143-0
                                                                                                                                                                                                                                                            • Opcode ID: 53ed0d45b3e0ce5a58d2be60204ef511d152e613adcfc9cedf2c48a17558e0f3
                                                                                                                                                                                                                                                            • Instruction ID: e1c1e6457c07f243d95df1252e990ce526c61be7bb4b0d841d125ce3172176f1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 53ed0d45b3e0ce5a58d2be60204ef511d152e613adcfc9cedf2c48a17558e0f3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3F216039F0475793E7482BA199E277865F2EFC8762F420078CE5B133E58F6E58438110
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\s3_enc.c$ssl3_setup_key_block
                                                                                                                                                                                                                                                            • API String ID: 0-2303705756
                                                                                                                                                                                                                                                            • Opcode ID: c73b8ea01a43f5656d2de56e94c70a10ede541e9e30d12f64adef1cedfddc30d
                                                                                                                                                                                                                                                            • Instruction ID: baac0a6ae683540522a21823403be8978b1e057b6be3521a7a3b5a09165cec60
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c73b8ea01a43f5656d2de56e94c70a10ede541e9e30d12f64adef1cedfddc30d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4751A432B08B8687E75CDB25E1606E9B7A4FB88B80F400175EB6C87789DF7CE2518740
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_mallocR_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_clnt.c$P$U$[$`$tls_process_cert_status_body
                                                                                                                                                                                                                                                            • API String ID: 4191474876-1928312256
                                                                                                                                                                                                                                                            • Opcode ID: fba9710200d61aa45fd89a82e9165f345a5174dacc70b8886a80579c7900c5cb
                                                                                                                                                                                                                                                            • Instruction ID: 292b42234449176ab85e399340f47c0231c43b3a918511386287e9a35b8ae385
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fba9710200d61aa45fd89a82e9165f345a5174dacc70b8886a80579c7900c5cb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4D31B661708B9184F7489F12986067A77A4FB45BC0F948075DF7E877D9DE7CE2958300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug$O_freeO_memdup
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_srvr.c$D:\a\1\s\include\internal/packet.h$tls_parse_ctos_ec_pt_formats
                                                                                                                                                                                                                                                            • API String ID: 3243760035-2708166893
                                                                                                                                                                                                                                                            • Opcode ID: ab93668ba9d89262296b78dc5fd8118763a9d078aa92ad0008419e569d609a33
                                                                                                                                                                                                                                                            • Instruction ID: 781fc7f93a73ae737815121e56a7fc9d31ee7c9b1a17e4ae7a92f7086b4dd551
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ab93668ba9d89262296b78dc5fd8118763a9d078aa92ad0008419e569d609a33
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A831BB21B0DB8241E7189B11E551BBA63A0FF45788F944171EEAC97BDEDF3CE6918700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CapsDevicememcpy
                                                                                                                                                                                                                                                            • String ID: (background event handler)$bold$italic$overstrike$underline
                                                                                                                                                                                                                                                            • API String ID: 58821350-4131028843
                                                                                                                                                                                                                                                            • Opcode ID: a17713759a73529424e8ca9c41101c1a72ee52b59a6956204543100086b68434
                                                                                                                                                                                                                                                            • Instruction ID: 529329cc9e98c22877caf2490349a2ce0821aac18349616b282b5c3c16ca0465
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a17713759a73529424e8ca9c41101c1a72ee52b59a6956204543100086b68434
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 32917235709B85C6DB188F5AE8646B967A1FB89F90F554172CD2E937E8EE3CD4058300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_freeO_mallocR_pop_to_markX_freeX_new_from_pkeyY_freeY_set_type
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\t1_lib.c
                                                                                                                                                                                                                                                            • API String ID: 355840433-1643863364
                                                                                                                                                                                                                                                            • Opcode ID: e6ed24203918b64b06758e4b9987f189c297571487f69a15613d8ae327fd6686
                                                                                                                                                                                                                                                            • Instruction ID: d6456be92e3dde47e20acda802c798733d538375b1225b31a28ca6d900b8ebae
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e6ed24203918b64b06758e4b9987f189c297571487f69a15613d8ae327fd6686
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7831C56AF0975282F7559B219560ABE63A0FF49B88F849071DF6C477CADF7CE5508300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_free$O_mallocR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\t1_lib.c$tls1_save_u16
                                                                                                                                                                                                                                                            • API String ID: 1304317871-3868075628
                                                                                                                                                                                                                                                            • Opcode ID: 4d48bacb5106bb8cac33b7dd82007534850fc67835a260ac1d7558940884a5b5
                                                                                                                                                                                                                                                            • Instruction ID: b47732bbb8bf4bf9add1f1fec2bed2bed37d9e99665ab7cb9307756e473930c2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4d48bacb5106bb8cac33b7dd82007534850fc67835a260ac1d7558940884a5b5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1631A225B18B6281E7188B21D520AAA6761EF85BC4FC8D071EE6D87BCDDF2CE5008300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_freeO_mallocR_newR_set_debugR_set_errormemcpy
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_sess.c$SSL_set_session_ticket_ext
                                                                                                                                                                                                                                                            • API String ID: 3414495729-2771971639
                                                                                                                                                                                                                                                            • Opcode ID: 33ff73018322d7b51af2a0daf8fd580d98ef873d2e93b57a57980e9f3efb85e5
                                                                                                                                                                                                                                                            • Instruction ID: 110dd20f29633e963c074683dd6c0819d9a30dfb4b0b5bd8c6c03ea5f1d91187
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 33ff73018322d7b51af2a0daf8fd580d98ef873d2e93b57a57980e9f3efb85e5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9F31C032718B8281EB949F15E450AA97360EB85BC4F949072EE5D97BD9DE3DD981C300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_freeO_memdup
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_cust.c
                                                                                                                                                                                                                                                            • API String ID: 3962629258-3973221358
                                                                                                                                                                                                                                                            • Opcode ID: 738a822d1e3cbd9bff253c4388f0ffe59fa978b3bf31d50a908cf80ad26fc2a0
                                                                                                                                                                                                                                                            • Instruction ID: f91798eb90b4446e6c520d54225833f9df278b0bccf87b5a9d045791e94fc0ea
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 738a822d1e3cbd9bff253c4388f0ffe59fa978b3bf31d50a908cf80ad26fc2a0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B9417136B05B4281EB1C9B01E8A4AA973A4FF44788F859476DE6D877C9DF7CE194C340
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileFind$DirectoryRemove$CloseDeleteFirstNext
                                                                                                                                                                                                                                                            • String ID: %s\*
                                                                                                                                                                                                                                                            • API String ID: 1057558799-766152087
                                                                                                                                                                                                                                                            • Opcode ID: 33e10a2293b6f66987fc751628de3762a02ba3a339ba911e57677f2f560f8a7f
                                                                                                                                                                                                                                                            • Instruction ID: c6a0e0edded10e0b9014de964185dfb8d8de27f0b5918f81837c364a8ddae8f9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 33e10a2293b6f66987fc751628de3762a02ba3a339ba911e57677f2f560f8a7f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: FB413025B0CA42C1EFE0AB24A844AB9A361FF98754FD00632DD9E47694DFFCD546C760
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_freeO_strdupR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_lib.c$SSL_use_psk_identity_hint
                                                                                                                                                                                                                                                            • API String ID: 598019968-3050056966
                                                                                                                                                                                                                                                            • Opcode ID: 6a7186c22779984460632f0d8cd213799fa53bb9072794df5bc172ebfb32efea
                                                                                                                                                                                                                                                            • Instruction ID: fa63d7a88cde6ac75d10ee22d7a570eede60cad78bc354d62516c28461253bb4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6a7186c22779984460632f0d8cd213799fa53bb9072794df5bc172ebfb32efea
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8C21AE61F286C355FB589715E460BB91790FF84784F8890B2DA7D877DADF6CD8A14300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Menu$AsyncState$ClientCountCursorFromItemMetricsPointPopupRemoveScreenSystemTrackWindow
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2544695384-0
                                                                                                                                                                                                                                                            • Opcode ID: 6b2d61f20f9b650e3330f0ca04cb982fe0e49d58ec3fc10b07149b399d4994d0
                                                                                                                                                                                                                                                            • Instruction ID: 6b4953ae7a19f75a06a3066599d0e3599321b8ea7af93cdb73b8541407aa94d6
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6b2d61f20f9b650e3330f0ca04cb982fe0e49d58ec3fc10b07149b399d4994d0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 51716F32B08646C7E7189F55E4A0A6973B1FB88B94F145076DE6E83798DF3CE885DB00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_zallocR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\crypto\packet.c$wpacket_intern_init_len
                                                                                                                                                                                                                                                            • API String ID: 3755831613-2385383871
                                                                                                                                                                                                                                                            • Opcode ID: d8d29241b34f6ed1448e2b191bfe5aaeec13669fc189dc889723cdd5f99c9a51
                                                                                                                                                                                                                                                            • Instruction ID: 92e89a84f09c732bbb74be5807bd3ff607b12228a716c32b5c8cfaacd34b5d45
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d8d29241b34f6ed1448e2b191bfe5aaeec13669fc189dc889723cdd5f99c9a51
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 68112626B19A0282E7189B14F460BBC62A4EF447A8F944334EA7D47BCADE2CD590C300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_zallocR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\crypto\packet.c$wpacket_intern_init_len
                                                                                                                                                                                                                                                            • API String ID: 3755831613-2385383871
                                                                                                                                                                                                                                                            • Opcode ID: 3ef190c75523e7896d3889d634bb52ef9347001eb4dc940cafadcbf989413ff2
                                                                                                                                                                                                                                                            • Instruction ID: 0092c17da7fcb8e32b69dc6f6baf1066c6a5cc5caee9b196ff555824c095e1dc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3ef190c75523e7896d3889d634bb52ef9347001eb4dc940cafadcbf989413ff2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2A110825B14B4286E75CAB5CF450A6822A0FF44768FE45374EA7C8B7DACF3DD5528300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_zallocR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\crypto\packet.c$wpacket_intern_init_len
                                                                                                                                                                                                                                                            • API String ID: 3755831613-2385383871
                                                                                                                                                                                                                                                            • Opcode ID: e02cf82d1fb0afa0ceb5a2c2d3529a885e177d5fda12af0ff3bad9361f88992d
                                                                                                                                                                                                                                                            • Instruction ID: 024d3e18bf6c03dcc2116fc64bc09906dead38056cc2ac358732d0ab11654123
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e02cf82d1fb0afa0ceb5a2c2d3529a885e177d5fda12af0ff3bad9361f88992d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DD012631B14B0286E75CA718F421A6872E4EF44758FE05271E67C8BBEACF3DD5528300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_freeO_strdupR_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\s3_lib.c$ssl3_ctx_ctrl
                                                                                                                                                                                                                                                            • API String ID: 1600027128-780421027
                                                                                                                                                                                                                                                            • Opcode ID: 7d40c234d0f22eb61ccb567c1d7ddc2cc3355691a0df2bdf89c5a968330fce78
                                                                                                                                                                                                                                                            • Instruction ID: b431da7ceee7ced454312eedcbb96945dc54355d3b0ab691ba9ccc1096527a77
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7d40c234d0f22eb61ccb567c1d7ddc2cc3355691a0df2bdf89c5a968330fce78
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 43F04464F2EB4385FB699B11E471EB82350AF41748FC451B6DC2D8AADDDE6CE641C300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_ctrl
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3605655398-0
                                                                                                                                                                                                                                                            • Opcode ID: 57a8fa268219bd8da3a78fb2d0d544eb281db7a6e311204462a33761bf488ad1
                                                                                                                                                                                                                                                            • Instruction ID: 601b97c8359c87c2c6466436d15787b4387e24c6c6f07cb0afba444e147151ac
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 57a8fa268219bd8da3a78fb2d0d544eb281db7a6e311204462a33761bf488ad1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0D31963272464146EB9C976595F5FFD2291EB88B84F0451B4EE2E47BCADF6CE4618300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_free$L_sk_pop_free
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_conf.c
                                                                                                                                                                                                                                                            • API String ID: 1650471521-1527728938
                                                                                                                                                                                                                                                            • Opcode ID: 50704227a650c2f30f39b5772116175a30cb97e45407adf3e1a9b74e05b90be2
                                                                                                                                                                                                                                                            • Instruction ID: 757b605e46459fc51c22bec6d02a0ea476c4bd7bcd3c764a417798d1f10eb347
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 50704227a650c2f30f39b5772116175a30cb97e45407adf3e1a9b74e05b90be2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2E01DD25F28A4785EB48E711F4A0AB92311EB45BC4FC4A071ED5D87BDDDE2CD6058700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileFindFirst_invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2227656907-0
                                                                                                                                                                                                                                                            • Opcode ID: b6a193d294c3b32593d30be4cab4f407475a0a4c133e91729be199528772a0a4
                                                                                                                                                                                                                                                            • Instruction ID: 5203971036a1b96dcfa82c92831dbca9b5155f39020d50b039cc4f68b6419e7a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b6a193d294c3b32593d30be4cab4f407475a0a4c133e91729be199528772a0a4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F4B1B322B18692C1EFE0EF229800AB9A351EF54BD4F944132DE4E07E95DEFCE851C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_free
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_cust.c
                                                                                                                                                                                                                                                            • API String ID: 2581946324-3973221358
                                                                                                                                                                                                                                                            • Opcode ID: 73b89328d94985fa1e4bbd774a4cb8d5ea07f780b4c5cc7a6c352a81da706b54
                                                                                                                                                                                                                                                            • Instruction ID: 08bb819dac47ca4aa6d967b4f78efb4d61bee63c39d1ed50866764e0b1574eb5
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 73b89328d94985fa1e4bbd774a4cb8d5ea07f780b4c5cc7a6c352a81da706b54
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AF117032B19A4281E7589B16F8607AD6360FB44788F84A076EEAC8779DDF7CE1418700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: D_read_lockD_unlockH_retrievememcpy
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2272600717-0
                                                                                                                                                                                                                                                            • Opcode ID: eb8f01d32f11ce757cc108247e8aaa33bb29da89dfad56b58e05de3c2455db79
                                                                                                                                                                                                                                                            • Instruction ID: 17496cc41c44096cb0c8738e1ac9b18256d94bf9e3ad5facf296a58b5c5ebe5a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: eb8f01d32f11ce757cc108247e8aaa33bb29da89dfad56b58e05de3c2455db79
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 291154257286C282EF68DB25E4617A97364FF88B84F444171DA5CC7799EF6CD2508700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_freeO_strdup
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_conf.c
                                                                                                                                                                                                                                                            • API String ID: 2148955802-1527728938
                                                                                                                                                                                                                                                            • Opcode ID: 4dfb2f5347d2243fba05db8b9de97b1409010663ecc0b3d09fb5f849f8aa4d7b
                                                                                                                                                                                                                                                            • Instruction ID: a6809a44d63993ab764a0f3cea038d1271f56ab060220bff1f4fb4cfe2276e4a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4dfb2f5347d2243fba05db8b9de97b1409010663ecc0b3d09fb5f849f8aa4d7b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7F11C625F2879381FB5C8756F0E0A299691AB44BC4F449074EF7D07BCDDE6CE8A28700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_free
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions.c
                                                                                                                                                                                                                                                            • API String ID: 2581946324-1165805907
                                                                                                                                                                                                                                                            • Opcode ID: bda865ca90fb9742dd0f762e35fd0a646e8fde23075ec1cfe1307ed669e1f0af
                                                                                                                                                                                                                                                            • Instruction ID: 7ca2c0bf9a1f543ca5eda6e65d51a2ed819bd15cf3bf43ec2e13a3019bdb88d9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bda865ca90fb9742dd0f762e35fd0a646e8fde23075ec1cfe1307ed669e1f0af
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5501D1B2B04B8185D7449F15E8507A873A4EB44BC8F98407AEF5847B9ACE28C5518724
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_mallocP_expand_block
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\record\ssl3_record.c
                                                                                                                                                                                                                                                            • API String ID: 3543690440-2721125279
                                                                                                                                                                                                                                                            • Opcode ID: 36442bf61eeb957f8a13747718b6852b893c845a9f1886979899fa5c728ddf63
                                                                                                                                                                                                                                                            • Instruction ID: 00002c9df82956c642271b81f37ce3a3a888dfa9d1b4f40f0d067aaf3845d574
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 36442bf61eeb957f8a13747718b6852b893c845a9f1886979899fa5c728ddf63
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4B019266B15A0182EB488F25E45066963F0FB4CBD8F548175DF5C87BCDEF2CDA908700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_freeO_memdup
                                                                                                                                                                                                                                                            • String ID: D:\a\1\s\include\internal/packet.h
                                                                                                                                                                                                                                                            • API String ID: 3962629258-2521442236
                                                                                                                                                                                                                                                            • Opcode ID: 5859aadcf2b4eeb33330b57652adaf2f05903adc2a3a2321bbe026c1439f3e30
                                                                                                                                                                                                                                                            • Instruction ID: e7c5ccbcebb49c430812e6a1928b56d95b5c78b7226578236d8da98e2ab81cca
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5859aadcf2b4eeb33330b57652adaf2f05903adc2a3a2321bbe026c1439f3e30
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A4014F32B1AB8281EB549F02E890A9A7764FF58BC4F489075EF9C87B89DF3CD5518700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_freeO_memdup
                                                                                                                                                                                                                                                            • String ID: D:\a\1\s\include\internal/packet.h
                                                                                                                                                                                                                                                            • API String ID: 3962629258-2521442236
                                                                                                                                                                                                                                                            • Opcode ID: 0de0adcc16def4c784bb835723cd13190444f72f64e2884ba791c4086e5a9858
                                                                                                                                                                                                                                                            • Instruction ID: 17647e560601285cf444f4dd33a2de79879f049cce3510548ee7d8ac9507205f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0de0adcc16def4c784bb835723cd13190444f72f64e2884ba791c4086e5a9858
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2D014F32B06B4281EB589F02E890AA97764EF58BC0F489475EF9C87B89DF3CD5518700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_free
                                                                                                                                                                                                                                                            • String ID: ..\s\crypto\packet.c
                                                                                                                                                                                                                                                            • API String ID: 2581946324-3021818708
                                                                                                                                                                                                                                                            • Opcode ID: 6224574b7ed5e2385dc02589e031f659751ba7782648aab1ad9aa000ba038eb9
                                                                                                                                                                                                                                                            • Instruction ID: 7834727ec68ec6ce37f6903da3d0e1317c3536c3be6bc22d08150eaa2befbd1c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6224574b7ed5e2385dc02589e031f659751ba7782648aab1ad9aa000ba038eb9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 16F024A1B2460281EB186B269820B6513E1EF44794F442170EA2C8B3CDDFACD8D18300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_free
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions.c
                                                                                                                                                                                                                                                            • API String ID: 2581946324-1165805907
                                                                                                                                                                                                                                                            • Opcode ID: 4215d94802cf5e2335165e5f2a4fa43dcd70600d1089b7858d4fd7263c0db38c
                                                                                                                                                                                                                                                            • Instruction ID: b8e0fb6afd46d9e3dd74afca8046fc4662be269604a188cb9ec5389184fc7eb9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4215d94802cf5e2335165e5f2a4fa43dcd70600d1089b7858d4fd7263c0db38c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 18F02BF2F0274286E7849B28D8447A42290EF05754F981130DA2CCBBC5EE2D85D28311
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: D_unlockD_write_lock
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1724170673-0
                                                                                                                                                                                                                                                            • Opcode ID: ed82e433cb3c0509164317c214ea3607acdcd7d131f5f7b79a7e857afcc139b8
                                                                                                                                                                                                                                                            • Instruction ID: 9883ed97bd98ad3403fba8622afc650591fa8af076db70c6d66c16a82466a647
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ed82e433cb3c0509164317c214ea3607acdcd7d131f5f7b79a7e857afcc139b8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E121B6627246C141DB48CF25E4942A92394FB48FE8F584372EE6E9B7DDDE68C5518300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: D_read_lockD_unlock
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 102331797-0
                                                                                                                                                                                                                                                            • Opcode ID: 5e7f9065c7574be89edb2e45999f33991c44a3a35ae18b08861fcc82c9ae1c5a
                                                                                                                                                                                                                                                            • Instruction ID: a144be814479232f5c605441141fd4e4fb7309e87b1a0604d0cfe1299d68281b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5e7f9065c7574be89edb2e45999f33991c44a3a35ae18b08861fcc82c9ae1c5a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 94F0A721B2958341FB595B66E950AFC5360FF94780F480071EE2CC73CADE6CE5D24200
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_memcmp
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2788248766-0
                                                                                                                                                                                                                                                            • Opcode ID: 10c13b6818660bc74a409f07be873d51ebdc7e4c7405a6176843b0179abf7b4f
                                                                                                                                                                                                                                                            • Instruction ID: e0df2d7a84f796e100400c6763d2d112e487f4205b009ee52627de7a08cd47bc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 10c13b6818660bc74a409f07be873d51ebdc7e4c7405a6176843b0179abf7b4f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EE210A92B287C145EB350778B025ABDE751FF55345F449334EBEC52A99DF6CE2A04B00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: D_unlockD_write_lock
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1724170673-0
                                                                                                                                                                                                                                                            • Opcode ID: 8cbaf000b5af017c8a76034d2c79b22f0d1f0b76137dcf9630b5a8834ddf1fe4
                                                                                                                                                                                                                                                            • Instruction ID: bbadf8bb84178f2655206199cf5b086847958bce7a31cd967bf9adf181d6af6b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8cbaf000b5af017c8a76034d2c79b22f0d1f0b76137dcf9630b5a8834ddf1fe4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A6E0C242F2858246E748931AE856AB95250EF587CCF184030FE5D86BEADD58CA520640
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: D_run_once
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1403826838-0
                                                                                                                                                                                                                                                            • Opcode ID: c13aa36e8a17a05cf506a0a9c11debc1049b81cce16da8ab96ad0e3a273c0894
                                                                                                                                                                                                                                                            • Instruction ID: 3f0ef9e5a46da51f174dd99ec9d57e5a39c724be1cf3be0ef54f5e7c072ae921
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c13aa36e8a17a05cf506a0a9c11debc1049b81cce16da8ab96ad0e3a273c0894
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F6E0EC24F1954386FF4CA728D8B1AB93390BF41350FD082B5E43DC65E9DE5CA9158B00
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: e01617633d62c7c04581d9db99b67ae7cf5d116ed409b32e1f2b517a31030fcb
                                                                                                                                                                                                                                                            • Instruction ID: 7401c2ccebd71d26920eff96f626991c1986ea97818037b19c6067321994f069
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e01617633d62c7c04581d9db99b67ae7cf5d116ed409b32e1f2b517a31030fcb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A8B0924324E2C10BC302C7B4482444D2FA08583A4076C408F838683283C00C48488302
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84C50
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84C62
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84C99
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84CAB
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84CC4
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84CD6
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84CEF
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D01
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D1D
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D2F
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D4B
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D5D
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D79
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84D8B
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84DA7
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84DB9
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84DD5
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,00007FF762A8590F,00000000,00007FF762A8272E), ref: 00007FF762A84DE7
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AddressErrorLastProc
                                                                                                                                                                                                                                                            • String ID: Failed to get address for %hs$GetProcAddress$PyConfig_Clear$PyConfig_InitIsolatedConfig$PyConfig_Read$PyConfig_SetBytesString$PyConfig_SetString$PyConfig_SetWideStringList$PyErr_Clear$PyErr_Fetch$PyErr_NormalizeException$PyErr_Occurred$PyErr_Print$PyErr_Restore$PyEval_EvalCode$PyImport_AddModule$PyImport_ExecCodeModule$PyImport_ImportModule$PyMarshal_ReadObjectFromString$PyMem_RawFree$PyModule_GetDict$PyObject_CallFunction$PyObject_CallFunctionObjArgs$PyObject_GetAttrString$PyObject_SetAttrString$PyObject_Str$PyPreConfig_InitIsolatedConfig$PyRun_SimpleStringFlags$PyStatus_Exception$PySys_GetObject$PySys_SetObject$PyUnicode_AsUTF8$PyUnicode_Decode$PyUnicode_DecodeFSDefault$PyUnicode_FromFormat$PyUnicode_FromString$PyUnicode_Join$PyUnicode_Replace$Py_DecRef$Py_DecodeLocale$Py_ExitStatusException$Py_Finalize$Py_InitializeFromConfig$Py_IsInitialized$Py_PreInitialize
                                                                                                                                                                                                                                                            • API String ID: 199729137-653951865
                                                                                                                                                                                                                                                            • Opcode ID: 91fe38e706475bc85e8e17d1603b2dd44d209342b91b11e5c33006422c226cfa
                                                                                                                                                                                                                                                            • Instruction ID: 7abf8af8175c20e9390d54b42aea7487db1db7f6c9c2ad26f927efba829dd3e6
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 91fe38e706475bc85e8e17d1603b2dd44d209342b91b11e5c33006422c226cfa
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1C22AD60A0DF07D5FFD5BB64A855DB4A3A4AF48781BC41435DC8E06A60EFFCA489C2B0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AddressErrorLastProc
                                                                                                                                                                                                                                                            • String ID: Failed to get address for %hs$GetProcAddress$Tcl_Alloc$Tcl_ConditionFinalize$Tcl_ConditionNotify$Tcl_ConditionWait$Tcl_CreateInterp$Tcl_CreateObjCommand$Tcl_CreateThread$Tcl_DeleteInterp$Tcl_DoOneEvent$Tcl_EvalEx$Tcl_EvalFile$Tcl_EvalObjv$Tcl_Finalize$Tcl_FinalizeThread$Tcl_FindExecutable$Tcl_Free$Tcl_GetCurrentThread$Tcl_GetObjResult$Tcl_GetString$Tcl_GetVar2$Tcl_Init$Tcl_JoinThread$Tcl_MutexFinalize$Tcl_MutexLock$Tcl_MutexUnlock$Tcl_NewByteArrayObj$Tcl_NewStringObj$Tcl_SetVar2$Tcl_SetVar2Ex$Tcl_ThreadAlert$Tcl_ThreadQueueEvent$Tk_GetNumMainWindows$Tk_Init
                                                                                                                                                                                                                                                            • API String ID: 199729137-3427451314
                                                                                                                                                                                                                                                            • Opcode ID: 3ce57ac688b021c07c17bb9d18c3d2db368ff9ca427b7eb3b8bd4dc412038eb8
                                                                                                                                                                                                                                                            • Instruction ID: e1c8d246f559e9a750e0612fe98391ebb60e653483e83105903ed74ece7a40ca
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3ce57ac688b021c07c17bb9d18c3d2db368ff9ca427b7eb3b8bd4dc412038eb8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C5028164A19F07D5FFD9BB64A915DB4A3A0AF04B45BC40036CC4E0AB64EFFDA449C3A0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Create$Brush$CompatibleFillObjectRectSelectSolid$BitmapPattern
                                                                                                                                                                                                                                                            • String ID: unexpected drawable type in stipple
                                                                                                                                                                                                                                                            • API String ID: 2830929341-1374382833
                                                                                                                                                                                                                                                            • Opcode ID: 22a336f3008ac64b2ca1f2a5429c60e08ea0a26a81b884c6aefe1123c70da050
                                                                                                                                                                                                                                                            • Instruction ID: 34d2f527ba586d6d6875340f1254e2d115cb22f6d597ce5edfcf8f63bb715939
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 22a336f3008ac64b2ca1f2a5429c60e08ea0a26a81b884c6aefe1123c70da050
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A1B15A32B08A96C7DB289F61E464A7AB3A1FF89B85F044035DE5A47B98DF3DD044DB04
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: X509_X_set0_default$E_freeH_freeM_read_bio_O_freeR_newX509X509_free$E_dupH_newH_retrieveL_sk_new_nullL_sk_pop_freeO_ctrlO_newO_s_fileR_clear_errorR_set_debugR_set_errorX509_get_subject_nameX509_new_ex
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_cert.c$SSL_load_client_CA_file_ex
                                                                                                                                                                                                                                                            • API String ID: 1433350638-4230349072
                                                                                                                                                                                                                                                            • Opcode ID: 8a09f4d11c177daa159a154d470a46ef68f5b3f683ecc5a7e6ff8f5d09335e7a
                                                                                                                                                                                                                                                            • Instruction ID: 0545cd3782810184c09c99a60181beb9481e911c4fe6764975c7acf9f8d99348
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8a09f4d11c177daa159a154d470a46ef68f5b3f683ecc5a7e6ff8f5d09335e7a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2C516219B1D60381FF5DBB52A571EB952906F85BC4F84A4B1EC2D877CEEE6CE6018340
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375906
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375914
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375931
                                                                                                                                                                                                                                                            • log10.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375937
                                                                                                                                                                                                                                                            • floor.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA37593D
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA37598C
                                                                                                                                                                                                                                                            • log10.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375992
                                                                                                                                                                                                                                                            • floor.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375998
                                                                                                                                                                                                                                                            • pow.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA3759B6
                                                                                                                                                                                                                                                            • floor.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA3759DA
                                                                                                                                                                                                                                                            • floor.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375A01
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375A38
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375A49
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375A6E
                                                                                                                                                                                                                                                            • pow.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FFDFA375A8D
                                                                                                                                                                                                                                                            • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FFDFA375AA8
                                                                                                                                                                                                                                                            • floor.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FFDFA375ACF
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FFDFA375B06
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FFDFA375B17
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0 ref: 00007FFDFA375B33
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375B93
                                                                                                                                                                                                                                                            • fabs.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375BB2
                                                                                                                                                                                                                                                            • log10.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375BB8
                                                                                                                                                                                                                                                            • floor.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFA374D62), ref: 00007FFDFA375BBE
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fabs$floor$log10
                                                                                                                                                                                                                                                            • String ID: %%.%de$%%.%df
                                                                                                                                                                                                                                                            • API String ID: 2163138323-2067013384
                                                                                                                                                                                                                                                            • Opcode ID: 2e6a8fb3e68770b8c67049dbec2043a8a16a736f24cc3f7f0ebd817e2fe20e45
                                                                                                                                                                                                                                                            • Instruction ID: 89b2e8ad97e8fc5ea0e7116fc7559265c53e0c5341c81b0ec85483fdf26d08f1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2e6a8fb3e68770b8c67049dbec2043a8a16a736f24cc3f7f0ebd817e2fe20e45
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9DA1EE21B18F868BE31BAF789410679F3E9FF567C5F148372E55A72168DF29A4C28240
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Digest$Update$Final_exX_copy_exX_freeX_get0_mdmemcpy$D_get_sizeR_get_modeX_get0_cipherX_new
                                                                                                                                                                                                                                                            • String ID: 666666666666666666666666666666666666666666666666\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
                                                                                                                                                                                                                                                            • API String ID: 1783088893-2009547811
                                                                                                                                                                                                                                                            • Opcode ID: c3cc761bef5fbd9587672d1abe63c9a5577274482d18fe80147167600814398b
                                                                                                                                                                                                                                                            • Instruction ID: 1deb0982a0f7cd8342a4e6d70ce276e7aa3183b210314e369667d75fcbf4c3a7
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c3cc761bef5fbd9587672d1abe63c9a5577274482d18fe80147167600814398b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5481FAA571C7C340EB18DB1AA964ABA5791AF86BC4F8440B6DD5EC7BDEDE3CE5008700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_indentO_printf
                                                                                                                                                                                                                                                            • String ID: %s (0x%02X)$%s=0x%x (%s)$UNKNOWN$cipher_suites (len=%d)$client_version$compression_methods (len=%d)$cookie$session_id${0x%02X, 0x%02X} %s
                                                                                                                                                                                                                                                            • API String ID: 1860387303-676829095
                                                                                                                                                                                                                                                            • Opcode ID: 76b9c860bbbf241bc39a1e67ccccd21ec5372df6ad449af4d54ff4c80fff2ee7
                                                                                                                                                                                                                                                            • Instruction ID: fc9ce9f57be7367115f187290f557b883a67b8e9ad02e07dbef424fa2f7eef2a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 76b9c860bbbf241bc39a1e67ccccd21ec5372df6ad449af4d54ff4c80fff2ee7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8B91F739B186A245EB188B219524AA97B61FF85BD0FD88172DEAD83BDDCF3CD501C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_printfO_puts$O_indentX509$M_write_bio_X509_freeX509_print_exd2i_
                                                                                                                                                                                                                                                            • String ID: ------details-----$------------------$<TRAILING GARBAGE AFTER CERTIFICATE>$<UNPARSEABLE CERTIFICATE>$ASN.1Cert, length=%d$certificate_list, length=%d$context
                                                                                                                                                                                                                                                            • API String ID: 1298273312-331119655
                                                                                                                                                                                                                                                            • Opcode ID: 1dae2ca54575a24730a0b28fedf2b8c2e0d57c8a7e9de36270bdadf7a5f1d81f
                                                                                                                                                                                                                                                            • Instruction ID: 28f7e764f11bb7727ec99caa54200cb5cc51669900b7cb6c109b58a07c3a6332
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1dae2ca54575a24730a0b28fedf2b8c2e0d57c8a7e9de36270bdadf7a5f1d81f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D961142671869245EB588B25E460BA977A1FF447D0F8891B1DEBD83BDDDE3CE540C300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: L_sk_pop_free$E_freeL_sk_newL_sk_pushR_newR_set_debugX509_
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_lib.c$parse_ca_names
                                                                                                                                                                                                                                                            • API String ID: 3454744561-1744826974
                                                                                                                                                                                                                                                            • Opcode ID: fd828e97b03e73bfeb406d2f0033b5edd036ccd1cc65025322a4c200aa49605c
                                                                                                                                                                                                                                                            • Instruction ID: 8dfa730603aa73446fa4d2b5ce3b0539672e642ddd8d569788357680d3360773
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fd828e97b03e73bfeb406d2f0033b5edd036ccd1cc65025322a4c200aa49605c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9851B725F0CA9341FB18AB52D531AB91395BF44788FC494B1DDADC6ADEDE3CE6818700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • PyBuffer_FillInfo.PYTHON313 ref: 70189146
                                                                                                                                                                                                                                                            • PyMemoryView_FromBuffer.PYTHON313 ref: 70189158
                                                                                                                                                                                                                                                            • _PyObject_CallMethod.PYTHON313 ref: 7018917F
                                                                                                                                                                                                                                                            • PyNumber_AsSsize_t.PYTHON313 ref: 7018919E
                                                                                                                                                                                                                                                            • PyErr_SetString.PYTHON313 ref: 701892F1
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • EOF read where not expected, xrefs: 70189242
                                                                                                                                                                                                                                                            • read() returned too much data: %zd bytes requested, %zd returned, xrefs: 701892C5
                                                                                                                                                                                                                                                            • marshal data too short, xrefs: 701892E7
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: BufferBuffer_CallErr_FillFromInfoMemoryMethodNumber_Object_Ssize_tStringView_
                                                                                                                                                                                                                                                            • String ID: EOF read where not expected$marshal data too short$read() returned too much data: %zd bytes requested, %zd returned
                                                                                                                                                                                                                                                            • API String ID: 3081723458-4172231876
                                                                                                                                                                                                                                                            • Opcode ID: 4e1c608dffdc7c705db58bf647ada603513852a5ad00df3d61cf44f8fd3bd16e
                                                                                                                                                                                                                                                            • Instruction ID: 294c5966466909ce28cd38eaf443b6a425eb29b39df0df68a8e7dc4d8a8b7551
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4e1c608dffdc7c705db58bf647ada603513852a5ad00df3d61cf44f8fd3bd16e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DA513A6270DA05D2EA158F69D84835C2365B748FB4F594326CE2E47BE8DF3CE686C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug$Y_free
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_srvr.c$tls_process_cke_ecdhe
                                                                                                                                                                                                                                                            • API String ID: 2633058761-1956247337
                                                                                                                                                                                                                                                            • Opcode ID: 6827c9dde5e40fb7271cd2fc25dbc3e9dde87e445b91196aedfd0a2987057dae
                                                                                                                                                                                                                                                            • Instruction ID: 3b2b09daecf37d91c1ac1438543b91042cbc012aa0adb08dd5d7c5c0ac1d20a2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6827c9dde5e40fb7271cd2fc25dbc3e9dde87e445b91196aedfd0a2987057dae
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 07418135B1CA4341FB18AB52D831BF96650AF55B88FD490B1DD2C87BDEDE2DE6418300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug$Y_free
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_srvr.c$tls_process_cke_dhe
                                                                                                                                                                                                                                                            • API String ID: 2633058761-3621362005
                                                                                                                                                                                                                                                            • Opcode ID: ed2f0ac2989abbb20880f0ef17fdd1c18dc8a0f46ff8240208212cce86f2e5eb
                                                                                                                                                                                                                                                            • Instruction ID: 162ea4079ab58b831eb297a69df6507a47358d861c000ecfcfed2d200d96d5e8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ed2f0ac2989abbb20880f0ef17fdd1c18dc8a0f46ff8240208212cce86f2e5eb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AD418D65B1CA5341FB58AB12D920BBE6690AF45B84FD490B1DD2C87BDEEE3CE6418300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_new$i2d_$L_sk_numR_set_debugX509_$L_sk_value
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_construct_ctos_status_request
                                                                                                                                                                                                                                                            • API String ID: 3024451675-148121689
                                                                                                                                                                                                                                                            • Opcode ID: 200efca5fdb51ee8c8e6b7aec151410704a35242ea61df333bcc970f5f33587c
                                                                                                                                                                                                                                                            • Instruction ID: 87ed45ef436dfa272172829b62e9b014e10ec482b986ec8619baf55839f7e255
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 200efca5fdb51ee8c8e6b7aec151410704a35242ea61df333bcc970f5f33587c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 83518F28B1C64341FB5CA7669831EFA42919FC5784FD480B2ED6DC6BCEDE6CE9428701
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Class$LongMessageSend$HandleLoadModule$CursorIconRegister
                                                                                                                                                                                                                                                            • String ID: Can't set icon; window has no wrapper.$FAILED$ICON$LOOKUP$TOPLEVEL$Unable to set icon$WRAPPER$window "%s" isn't a top-level window
                                                                                                                                                                                                                                                            • API String ID: 3636279047-342970489
                                                                                                                                                                                                                                                            • Opcode ID: a86ec2363340386d0b2c48f950433c9898b48467edf500ba6f38d175ff5423d7
                                                                                                                                                                                                                                                            • Instruction ID: b196599a13f1bd0489d22dd8c5932c9c969b21e6e4ad253fe24614f00766d8f2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a86ec2363340386d0b2c48f950433c9898b48467edf500ba6f38d175ff5423d7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B2C18732B0868686EB6C9B51D5A4EB92395FF45B84F456072CE2E833D8DF3CE985D300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: E_dupL_sk_new_reserveL_sk_numL_sk_pushL_sk_valueR_newR_set_debugR_set_errorX509_
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_cert.c$SSL_dup_CA_list
                                                                                                                                                                                                                                                            • API String ID: 876855465-3127325357
                                                                                                                                                                                                                                                            • Opcode ID: 0a31a2026910ecbc2ad58b2bc3e42c5692a9224a5135d88c55630d5da1030bf5
                                                                                                                                                                                                                                                            • Instruction ID: 7299b8f86b5760bdb6d08fa407c6c04452c8559f3280a84a5f36a6079f8259ba
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0a31a2026910ecbc2ad58b2bc3e42c5692a9224a5135d88c55630d5da1030bf5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4D21B519F1C64386FB5CA765A461EBE42509F85784FC490B5EE2D877CEEE2CEA418240
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Color$ChooseEnableWindow_stricmp_strnicmp
                                                                                                                                                                                                                                                            • String ID: #%02x%02x%02x$COLORDIALOG$H$LOOKUP$NO_MAIN_WINDOW$NULL main window$VALUE$WINDOW$bad window path name "%s"$option$value for "%s" missing
                                                                                                                                                                                                                                                            • API String ID: 1945733794-2582839937
                                                                                                                                                                                                                                                            • Opcode ID: a659773ff047f8aa95780fda5643eafe4fb49529856ada0fc06e0bd8129188b8
                                                                                                                                                                                                                                                            • Instruction ID: 8aceb11daeb8507d7558d3da8fae2af8002b9327ac0e0b5b2e36ed3202142b20
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a659773ff047f8aa95780fda5643eafe4fb49529856ada0fc06e0bd8129188b8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C7A1BD35B09A8286EB589F55E460BB973E0FB88B84F444076EE6D87B98DF3CE044D700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_clnt.c$No groups enabled for max supported SSL/TLS version$tls_construct_ctos_supported_groups
                                                                                                                                                                                                                                                            • API String ID: 193678381-1756869798
                                                                                                                                                                                                                                                            • Opcode ID: 4ea85dbe1c52e2e48815121b84298091847467fee5bfa8165b4d96c3c2b909e6
                                                                                                                                                                                                                                                            • Instruction ID: b171a5c7ddafca50ad82a8d77c3718ce45736edf05c32a83949b2339a11e36cb
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4ea85dbe1c52e2e48815121b84298091847467fee5bfa8165b4d96c3c2b909e6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 70717C25B2C68382EB589711D520FBA26D5EFC1784F9450B1ED6D87BCDDE3DE9018700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_clnt.c$tls_prepare_client_certificate
                                                                                                                                                                                                                                                            • API String ID: 193678381-816577172
                                                                                                                                                                                                                                                            • Opcode ID: 0631d5a9709af4c4a5cdca13957b11041a4571707cdcd962e9d56ca7e6e342d0
                                                                                                                                                                                                                                                            • Instruction ID: ad117853bfcd98f6d65d025ea258376ae4c196b78a94fd5c690b67ce0548cc05
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0631d5a9709af4c4a5cdca13957b11041a4571707cdcd962e9d56ca7e6e342d0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 22718521F1864241FB589B16E460ABA6274EF84788F9851B1EF7D877DEDF2DE8818700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug$X509_get0_pubkey
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_clnt.c$tls_process_ske_ecdhe
                                                                                                                                                                                                                                                            • API String ID: 2988517565-1997102834
                                                                                                                                                                                                                                                            • Opcode ID: 7aecebfbc2668b29183bc662aa50cfd165c4a29700916f123029868e4f2178bc
                                                                                                                                                                                                                                                            • Instruction ID: 7618829e1538a462634f72ec7ffe52e0da2597ea9a2cd61adb69907d5094e098
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7aecebfbc2668b29183bc662aa50cfd165c4a29700916f123029868e4f2178bc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3B51C321B18B9341F758DB52D560EB92360FF89784F849171EEAD83BDADF2ED6908300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_new$R_set_debug$memcmp
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_parse_stoc_renegotiate
                                                                                                                                                                                                                                                            • API String ID: 4071200903-1100612425
                                                                                                                                                                                                                                                            • Opcode ID: 7fdca107e6cc1b938510a6f599ee7e7232782fc1a688be8ba54bb3143102da43
                                                                                                                                                                                                                                                            • Instruction ID: bace86979e3f935b2c799e3bba9d2c61a7e911267486b2ffad03a57e95224530
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7fdca107e6cc1b938510a6f599ee7e7232782fc1a688be8ba54bb3143102da43
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 16416161B1998381FB589B25D560EB922A0EF44B88F9490B2EF3D87BCDDF2CD5528310
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: -class$-colormap$-container$-screen$-use$-visual$CREATE_ONLY$FRAME$can't modify %s option after widget is created$option$option ?arg ...?
                                                                                                                                                                                                                                                            • API String ID: 0-2678313790
                                                                                                                                                                                                                                                            • Opcode ID: 36813c5c75b12d6bb6f86466e4c056cc7e8d7c0135a2e9e8c6a82c9f56bc8667
                                                                                                                                                                                                                                                            • Instruction ID: 8c1efd9c7b334005785f58f3b275a7818663d515a4f1fff510e8cec632c7040a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 36813c5c75b12d6bb6f86466e4c056cc7e8d7c0135a2e9e8c6a82c9f56bc8667
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5FA13169B0CB46C3EB18AB96A874AB963E5FB44BC4F4445B5CD6D477ACDE3CE4848300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: BAD_DEPTH$IMAGE$PITCH$PNG$SIZE$UNKNOWN_COLOR$bit depth is not allowed for given color type$image pitch is out of supported range on this architecture$image total size is out of supported range on this architecture$unknown color type %d$unknown color type field %d
                                                                                                                                                                                                                                                            • API String ID: 0-2707434482
                                                                                                                                                                                                                                                            • Opcode ID: 9531772b976c0cdc78c8d469f237c047c2b7d4ead4c9b3a92044529194618352
                                                                                                                                                                                                                                                            • Instruction ID: 54e08bcf3117795e764db2b86c7352f3b886e2b182a34f0f1208e17e33c02762
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9531772b976c0cdc78c8d469f237c047c2b7d4ead4c9b3a92044529194618352
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8281D075B0C65387EB5DAB789064AB827D1EB45B48F4802B5CE6E427ECDE2DDA85C300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: D_get0_nameL_cleanseM_construct_endM_construct_utf8_stringQ_macR_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\tls13_enc.c$HMAC$finished$properties$tls13_final_finish_mac
                                                                                                                                                                                                                                                            • API String ID: 3095186593-1708336846
                                                                                                                                                                                                                                                            • Opcode ID: 6eb9eadbf8fac9a8c244f704ddea165fd649cbc1ebe15b2029393974c4835fc5
                                                                                                                                                                                                                                                            • Instruction ID: 19499351a9552f9627bc65d53f26ca913ca7ba977e0ca4a5440eed3555550eb3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6eb9eadbf8fac9a8c244f704ddea165fd649cbc1ebe15b2029393974c4835fc5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8E518E32B08B8691E724DB14E460BEA73A0FB89784F844275EE9C47799EF3CE145CB00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debugR_set_error$Y_new
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_rsa_legacy.c$SSL_CTX_use_RSAPrivateKey
                                                                                                                                                                                                                                                            • API String ID: 2166683265-3135413908
                                                                                                                                                                                                                                                            • Opcode ID: 1c5440b5a9f78486ae293910026bd04abfada1e23b16dab2e9a40dfc5dd05139
                                                                                                                                                                                                                                                            • Instruction ID: 6b4749f0447fcb00109486e1e5b3bf3f33ad46a5d6a5a275028b525f09783e7a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1c5440b5a9f78486ae293910026bd04abfada1e23b16dab2e9a40dfc5dd05139
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 28217455B2C68342FB88A765A561AF94251AF887C4FC860B1EE1D87BCFDE2CDA424700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_ctrlO_free_allO_method_typeO_newO_nextO_up_refR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_lib.c$SSL_set_rfd
                                                                                                                                                                                                                                                            • API String ID: 1876162228-2433761532
                                                                                                                                                                                                                                                            • Opcode ID: 90f776c6c08b27f67889fb8440173e74ffb8612f2344ffcbc1bd74336b8dbb3c
                                                                                                                                                                                                                                                            • Instruction ID: abdb0295c2835beee5105a379078a59c33a29c67b94e5c76ac3688e0eef741f9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 90f776c6c08b27f67889fb8440173e74ffb8612f2344ffcbc1bd74336b8dbb3c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1F219015F2858341FF5CA752A831FBA12509F94784F9860B2FE6E87BCADE2CE9904740
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_ctrlO_int_ctrlO_method_typeO_newO_s_socketO_up_refR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_lib.c$SSL_set_wfd
                                                                                                                                                                                                                                                            • API String ID: 475579866-2547745303
                                                                                                                                                                                                                                                            • Opcode ID: 95430999ac75b5da1baf22bc595de9e39229b842a3b613ee165b545bcfc85146
                                                                                                                                                                                                                                                            • Instruction ID: 7b8f4d422983c4bab7868ebfb935e5e96a14c8eae25dd1ac79d6eda0e7ba6288
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 95430999ac75b5da1baf22bc595de9e39229b842a3b613ee165b545bcfc85146
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E711A215F2868342FB9CA712A431FBE0250AF95784F8860B1FD2E87BCEDD6DE9414700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strtol$isdigit
                                                                                                                                                                                                                                                            • String ID: INDEX$MENU$active$bad menu entry index "%s"$end$last$none
                                                                                                                                                                                                                                                            • API String ID: 1262363011-1307195327
                                                                                                                                                                                                                                                            • Opcode ID: a6875897780203a7c0a76f127840bac0403bd425ca525b7c2219e7becc9b1bc1
                                                                                                                                                                                                                                                            • Instruction ID: d5f6d24fd3391605e91dceda1af9b6d2f0df75a43fe8a7048658a027519880e9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a6875897780203a7c0a76f127840bac0403bd425ca525b7c2219e7becc9b1bc1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 15C17222B086878BEB689F59E460AB977E1FB85B84F4441B1DE6E437D8DE3CE444C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ObjectSelect$MetricsReleaseTextstrncmp
                                                                                                                                                                                                                                                            • String ID: ...$FONT_SAMPLE$VALUE$expected a single character but got "$font ?-displayof window? ?option? ?--? ?char?
                                                                                                                                                                                                                                                            • API String ID: 306661206-3834350937
                                                                                                                                                                                                                                                            • Opcode ID: 2aed1b464784d1279070b6a57739b584d47afd2d20776dc11d0a4d63acedd028
                                                                                                                                                                                                                                                            • Instruction ID: 0cb1685601d29c7a97db1a8e770ffc995d2ffd987304cb039f61bd312ff50251
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2aed1b464784d1279070b6a57739b584d47afd2d20776dc11d0a4d63acedd028
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 80917122B09B8287EB14EFA5D4649AD33E5FB44B94F448172CE2E677A8DE3CE445D340
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CharObjectSelectTextWidth$FaceMetricsRelease
                                                                                                                                                                                                                                                            • String ID: unicode$utf-16
                                                                                                                                                                                                                                                            • API String ID: 1149465119-3317161374
                                                                                                                                                                                                                                                            • Opcode ID: 1114a74ef7d9bcde0e0b7275e8bcf8f25d54c1e54de6d24ec086e431a2095469
                                                                                                                                                                                                                                                            • Instruction ID: 894b9f7604459e34efacbda34eac906d4ad2538fa249cfda4c6379ced2bbd103
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1114a74ef7d9bcde0e0b7275e8bcf8f25d54c1e54de6d24ec086e431a2095469
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 81719272708A86C6DB25DF66E4606A977A0FB88F94F444272CE6D83798DF3CD485D700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_lib.c$tls_process_change_cipher_spec
                                                                                                                                                                                                                                                            • API String ID: 193678381-3810074443
                                                                                                                                                                                                                                                            • Opcode ID: cd429f5ceeada9ff1fd9bc91a67c85cadb83a7396586a860847036504701c4f6
                                                                                                                                                                                                                                                            • Instruction ID: f45f49d0bb90932c38effa3d04c351c72927aa5c341ae79310b97c7614b5cafe
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cd429f5ceeada9ff1fd9bc91a67c85cadb83a7396586a860847036504701c4f6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E8414F21B5868781FB6C9B61D871FB51690AF85B58F8890B1CD2D87BCACE6DE681C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: LongWindow$BlockCreateErrorLastReasonShutdown
                                                                                                                                                                                                                                                            • String ID: Needs to remove its temporary files.
                                                                                                                                                                                                                                                            • API String ID: 3975851968-2863640275
                                                                                                                                                                                                                                                            • Opcode ID: 44e53fe94581f3919e9549e222624ce8134aca65504236f29db41f4538cf5799
                                                                                                                                                                                                                                                            • Instruction ID: 4eb117b721ab040c573d7edb6ee92b7983f8efd8eaa6d73bb7460c030d6ba932
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 44e53fe94581f3919e9549e222624ce8134aca65504236f29db41f4538cf5799
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2921A665B08E42C1EFC5AB7AA844979A390EF88B90F884130DE5D477A4DEECD584C260
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strnicmp
                                                                                                                                                                                                                                                            • String ID: -file option isn't supported for %s images$IMAGE$LOOKUP$NOT_FILE_FORMAT$PHOTO$PHOTO_FORMAT$UNRECOGNIZED_DATA$couldn't recognize data in image file "%s"$image file format "%s" is not supported
                                                                                                                                                                                                                                                            • API String ID: 2635805826-3773480712
                                                                                                                                                                                                                                                            • Opcode ID: db07cd5e2bf16cad7228c781eb97a3a639b96b03f5f485bf07a18e5f969cd8fe
                                                                                                                                                                                                                                                            • Instruction ID: 5b202ab454c20b43254b5e7476df46dc252cff76f43615eab157aa6a0befef11
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: db07cd5e2bf16cad7228c781eb97a3a639b96b03f5f485bf07a18e5f969cd8fe
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 72B15036B08B8286EB649F95E8507AA73A0FB88B98F448171CE6D4779CDF3CE145C740
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DrawPalette$ControlDeleteFocusFrameModeRealizeRectReleaseSelect
                                                                                                                                                                                                                                                            • String ID: default state$relief
                                                                                                                                                                                                                                                            • API String ID: 1867084563-1957560746
                                                                                                                                                                                                                                                            • Opcode ID: eeaf5b7c516510e69915369cbc4cd07c665cc504328a5241142d7d09faf218aa
                                                                                                                                                                                                                                                            • Instruction ID: f0d3e95073bc59eff22710aaa109682a05101d4651dcbff4bf0c57198f3a8928
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: eeaf5b7c516510e69915369cbc4cd07c665cc504328a5241142d7d09faf218aa
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7C71817670878687D728DF56E450A6AB7A0FB89B94F048135EEAE47798DF3CE444CB00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_lib.c$ssl_read_internal
                                                                                                                                                                                                                                                            • API String ID: 1552677711-1892056158
                                                                                                                                                                                                                                                            • Opcode ID: 1d1c3011cee07d316ca8084546e9506019f39c3765b74eccc4fa9aef4332d95d
                                                                                                                                                                                                                                                            • Instruction ID: b7cc627e13a9baf4beae0c854509c2b93136cee17c8db0d857c78f4812b19dd7
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1d1c3011cee07d316ca8084546e9506019f39c3765b74eccc4fa9aef4332d95d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2831B235B18B8381EB589B15E460AAE2361EF84B88F944171EE6D877EDCF7CF9419700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Err_$FetchFormatFromObject_RestoreWindowsstrerror
                                                                                                                                                                                                                                                            • String ID: %s (%d:%d)
                                                                                                                                                                                                                                                            • API String ID: 2858978339-1595188566
                                                                                                                                                                                                                                                            • Opcode ID: 50eb626addc7bfa67545d7ac0a2f8a60d92fd0aee50b63c8a612c1301164505e
                                                                                                                                                                                                                                                            • Instruction ID: 286ae0eb7eb0b8c75ac7b15a37e7e21bf29a9f58ac1aed33c84415a2dfbcf1aa
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 50eb626addc7bfa67545d7ac0a2f8a60d92fd0aee50b63c8a612c1301164505e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BF21CF63A19B44CAEB009B55E84839E7760FB89B90F964126DE4E13BA5CE3CC947CB40
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug$X_copy_exX_freeX_new
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_lib.c$tls13_save_handshake_digest_for_pha
                                                                                                                                                                                                                                                            • API String ID: 401794203-262298153
                                                                                                                                                                                                                                                            • Opcode ID: 412538726b70e8aeea752b51d591ae0eec0ce614aada8c58043d0c8b522c0924
                                                                                                                                                                                                                                                            • Instruction ID: 1bc6762b11ed1de5b2f2ae42ae444c6e50040576ea9c1891e5af7cda942407cd
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 412538726b70e8aeea752b51d591ae0eec0ce614aada8c58043d0c8b522c0924
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 62111F64F1994381FB58B7669831FB91190EF54748FC890B5DD2DC66CAEF2CA6418710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strncmp
                                                                                                                                                                                                                                                            • String ID: INDEX$LOOKUP$TCL$bad scan option "%s": must be mark or dragto$dragto$mark$mark|dragto x$scan option
                                                                                                                                                                                                                                                            • API String ID: 1114863663-1778636316
                                                                                                                                                                                                                                                            • Opcode ID: 981a33b50e9b02172309b259f22badbb4beac1ad2dcdd7d1cb9124f5d883c9fd
                                                                                                                                                                                                                                                            • Instruction ID: 2f596156ded41e8b34334c4ad793f71988c8e6c7d4e90673e7835be411fa05ac
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 981a33b50e9b02172309b259f22badbb4beac1ad2dcdd7d1cb9124f5d883c9fd
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 83414165B08A8287EB18AF96E460AB827E1FB45B94F4441B2CE2D577D8DF3CE445C701
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: -$:$f$p$p
                                                                                                                                                                                                                                                            • API String ID: 3215553584-2013873522
                                                                                                                                                                                                                                                            • Opcode ID: 65d4a0ffdc8e7253b8e60b637b85ac8f97459ea152ba9c8238927d2e88e0f15e
                                                                                                                                                                                                                                                            • Instruction ID: c69d4f291705d6ff7ab9b8d735c96ac5ae38cccaefd22a59ce2122ab82b09502
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 65d4a0ffdc8e7253b8e60b637b85ac8f97459ea152ba9c8238927d2e88e0f15e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AB1264A1E29143C6FFA47A169C44A79F691FB40750FE44135DA9A4A9C4DBFCEC80CB34
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: BeepMessage
                                                                                                                                                                                                                                                            • String ID: ?-displayof window? ?-nice?$LOOKUP$NO_MAIN_WINDOW$NULL main window$WINDOW$bad window path name "%s"$option
                                                                                                                                                                                                                                                            • API String ID: 2359647504-1933032461
                                                                                                                                                                                                                                                            • Opcode ID: f3b82cba2ff41ce135d0335ff135a336ff36e3abb6c40f86cef19b3936a5d264
                                                                                                                                                                                                                                                            • Instruction ID: 3dd7fac78014159740ac7a15a62442085940559a861ea912be963827f436e9c5
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f3b82cba2ff41ce135d0335ff135a336ff36e3abb6c40f86cef19b3936a5d264
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 58519E31B08B86C2EB589F56E4209B963E0FB88B94F4441B5DE6D477A8DF3CE545C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetTempPathW.KERNEL32(FFFFFFFF,00000000,?,00007FF762A83101), ref: 00007FF762A87D44
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(?,00007FF762A83101), ref: 00007FF762A87D4A
                                                                                                                                                                                                                                                            • CreateDirectoryW.KERNEL32(?,00007FF762A83101), ref: 00007FF762A87D8C
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A87E70: GetEnvironmentVariableW.KERNEL32(00007FF762A82C4F), ref: 00007FF762A87EA7
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A87E70: ExpandEnvironmentStringsW.KERNEL32 ref: 00007FF762A87EC9
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A99174: _invalid_parameter_noinfo.LIBCMT ref: 00007FF762A9918D
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Environment$CreateCurrentDirectoryExpandPathProcessStringsTempVariable_invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: LOADER: failed to set the TMP environment variable.$LOADER: length of teporary directory path exceeds maximum path length!$TMP$TMP$_MEI%d
                                                                                                                                                                                                                                                            • API String ID: 365913792-1339014028
                                                                                                                                                                                                                                                            • Opcode ID: ffb589f732eab392f51c917e2ec5332ba92e64a2874c8252f98761f4106046c7
                                                                                                                                                                                                                                                            • Instruction ID: 9767917879e26091c9aa768da4af7ba05be658ab7c7376f5a604bb9640e159f2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ffb589f732eab392f51c917e2ec5332ba92e64a2874c8252f98761f4106046c7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 17416B21B19642C4EFE4F7229955AB9A251AF897C0FD04031ED0D4B7A6EEFCE905CA60
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Digest$Final_exInit_ex$UpdateX_freeX_new
                                                                                                                                                                                                                                                            • String ID: exporter
                                                                                                                                                                                                                                                            • API String ID: 3991325671-111224270
                                                                                                                                                                                                                                                            • Opcode ID: c621e826f5224293a2def591db809beb09ffd8caa4d2a00cf2465702a8c7dcb4
                                                                                                                                                                                                                                                            • Instruction ID: 2c067790ee9f3e93251b14bdb768a36de6811bbcd711444fcb721e6bcf2ef8a2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c621e826f5224293a2def591db809beb09ffd8caa4d2a00cf2465702a8c7dcb4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6541A73571978255E7249B16A820BEAB394FF897D4F804072ED9D87B8DDE7CE100CB00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_parse_stoc_psk
                                                                                                                                                                                                                                                            • API String ID: 193678381-1931443905
                                                                                                                                                                                                                                                            • Opcode ID: ab1197f6afbdc2a9b2d3ec61f24795e56c20c0e13283179fcd65244047a83ee2
                                                                                                                                                                                                                                                            • Instruction ID: c01c77a802b307f9de1468074f666e7717dfa643438fbcc889f10b040c08d303
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ab1197f6afbdc2a9b2d3ec61f24795e56c20c0e13283179fcd65244047a83ee2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8C419722B08AC281F7588B29D4607FD2790EF84B48F885171EF6C8B6DADF3CE5818710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: BitsClientRectRelease
                                                                                                                                                                                                                                                            • String ID: ($XGetGeometry: invalid pixmap$XGetGeometry: invalid window$XGetGeometry: unable to get bitmap size
                                                                                                                                                                                                                                                            • API String ID: 3715867303-1062310972
                                                                                                                                                                                                                                                            • Opcode ID: 2430ca4f8abddfd37670a616d22dc78e1aa875caf3937a58ed6bcb5793970419
                                                                                                                                                                                                                                                            • Instruction ID: 56a567504e08404d169e5143925fc53c687ea629b5c35ec8e39d674d4301a53a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2430ca4f8abddfd37670a616d22dc78e1aa875caf3937a58ed6bcb5793970419
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DE412D32708A86C6DB249F55E4A4B6D77B0FB88B94F508171DA9D83798DF3CE844CB00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ($..\s\ssl\ssl_lib.c$ssl_start_async_job
                                                                                                                                                                                                                                                            • API String ID: 1552677711-1319532896
                                                                                                                                                                                                                                                            • Opcode ID: c5605aed95c076cb35e3e2fed6860a124237ec379f2d155d792e0f4a46e6a77d
                                                                                                                                                                                                                                                            • Instruction ID: beb478b69f0726caebfae227b2c2a7b2cd0388dab99ecd27deb96506585cb51a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c5605aed95c076cb35e3e2fed6860a124237ec379f2d155d792e0f4a46e6a77d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2B319035B1868381E7189B14E460BE96360EF44788FA80175EA6C877DDDF7CE990C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_lib.c$tls_process_key_update
                                                                                                                                                                                                                                                            • API String ID: 193678381-597347991
                                                                                                                                                                                                                                                            • Opcode ID: f5043b6557c68b0eb5f314b36da7dfc79faf85b136c8f3666ce1c872bda7e2fe
                                                                                                                                                                                                                                                            • Instruction ID: 2b66938927df78546d99538f0b372b0bfed2527f763b776126f949f9c2b4c6a8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f5043b6557c68b0eb5f314b36da7dfc79faf85b136c8f3666ce1c872bda7e2fe
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 89215C21B1CA4341FB5CAB12D961FB92250AF84784FD490B1DE3D87BDEDE2DEA518301
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_lib.c$SSL_CTX_check_private_key
                                                                                                                                                                                                                                                            • API String ID: 1552677711-2096838628
                                                                                                                                                                                                                                                            • Opcode ID: 5ea4a2f83997b8a4f9335d4e329ff78186c293e41e53f9a9ea782533eb3cb6ab
                                                                                                                                                                                                                                                            • Instruction ID: 97e7121b2f6948d352f004d8a24a45cb7cd6fa31232dc43405a922a83b15ba90
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5ea4a2f83997b8a4f9335d4e329ff78186c293e41e53f9a9ea782533eb3cb6ab
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6101DE58F1A64381FF0CA3A0C471FBA1251AF80B84FD090B1D83C867DEDE2CEA064310
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: MISSING$Missing value for "%s".$REQUIRED$TTK$Ttk$VSAPI$missing required arguments 'class' and/or 'partId'$option
                                                                                                                                                                                                                                                            • API String ID: 0-1444459223
                                                                                                                                                                                                                                                            • Opcode ID: 755f1aab279f20fcae522c5bb1afa1d779e13947278adc93da7cbc932b6174b5
                                                                                                                                                                                                                                                            • Instruction ID: 752caab7b7994b8f36abaa6557501b8e15272ea14b3c422c58a246ffac4a56dd
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 755f1aab279f20fcae522c5bb1afa1d779e13947278adc93da7cbc932b6174b5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 16F19C76B08B42C6DB189F6AE8506AA77E4F788B98F404076DE6D977A8DF3CD405C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: malloc
                                                                                                                                                                                                                                                            • String ID: mask != NULL$seed != NULL$src/pk/pkcs1/pkcs_1_mgf1.c
                                                                                                                                                                                                                                                            • API String ID: 2803490479-2931318352
                                                                                                                                                                                                                                                            • Opcode ID: c993c1000350790cf244aa60c4f5eda5c670dc1efd3dc81dfa9e0007e90314cc
                                                                                                                                                                                                                                                            • Instruction ID: 148a6387132c4e893fe0adf45a9e2332084bd7ce7c52c4c7443e34472480f4ef
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c993c1000350790cf244aa60c4f5eda5c670dc1efd3dc81dfa9e0007e90314cc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 085113BB7092C08ADF12CF369D4877E7A72BB45784F458009DE4B4BE85EA39D949CB10
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • X509_get_subject_name.LIBCRYPTO-3(?,?,00000001,00007FFDFA8E214E), ref: 00007FFDFA8E28EC
                                                                                                                                                                                                                                                            • X509_NAME_dup.LIBCRYPTO-3(?,?,00000001,00007FFDFA8E214E), ref: 00007FFDFA8E28F9
                                                                                                                                                                                                                                                            • X509_NAME_free.LIBCRYPTO-3(?,?,00000001,00007FFDFA8E214E), ref: 00007FFDFA8E2918
                                                                                                                                                                                                                                                            • OPENSSL_sk_push.LIBCRYPTO-3(?,?,00000001,00007FFDFA8E214E), ref: 00007FFDFA8E2925
                                                                                                                                                                                                                                                            • OSSL_STORE_INFO_free.LIBCRYPTO-3(?,?,00000001,00007FFDFA8E214E), ref: 00007FFDFA8E2931
                                                                                                                                                                                                                                                            • OSSL_STORE_eof.LIBCRYPTO-3(?,?,00000001,00007FFDFA8E214E), ref: 00007FFDFA8E2939
                                                                                                                                                                                                                                                            • ERR_clear_error.LIBCRYPTO-3(?,?,00000001,00007FFDFA8E214E), ref: 00007FFDFA8E2946
                                                                                                                                                                                                                                                            • X509_NAME_free.LIBCRYPTO-3(?,?,00000001,00007FFDFA8E214E), ref: 00007FFDFA8E2950
                                                                                                                                                                                                                                                            • OSSL_STORE_close.LIBCRYPTO-3(?,?,00000001,00007FFDFA8E214E), ref: 00007FFDFA8E295B
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: X509_$E_free$E_closeE_dupE_eofL_sk_pushO_freeR_clear_errorX509_get_subject_name
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1726013196-0
                                                                                                                                                                                                                                                            • Opcode ID: 89b92c166f0c0704a1a26ca2fbe8c574dc502a4a06d675c25f696b6f5e6dd0c9
                                                                                                                                                                                                                                                            • Instruction ID: 5fa0609957715278ba20f3ae6349315af76ecf93c0377d4dcbe7b8d171d9f13e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 89b92c166f0c0704a1a26ca2fbe8c574dc502a4a06d675c25f696b6f5e6dd0c9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CA315D69B1D24381FF5DB7A225B1EB952801F45BC0F4460B0ED6E867CEFE6CEA024210
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
                                                                                                                                                                                                                                                            • String ID: csm$csm$csm
                                                                                                                                                                                                                                                            • API String ID: 849930591-393685449
                                                                                                                                                                                                                                                            • Opcode ID: 7d7d5a635fcd63c536a58b816f4712f1a96a9e43b0d550c3d6dd02e630e8922c
                                                                                                                                                                                                                                                            • Instruction ID: 4fb04ca3c646bade232d5dfb056e40162085506b3b525d85fb3244083f28e421
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7d7d5a635fcd63c536a58b816f4712f1a96a9e43b0d550c3d6dd02e630e8922c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: ECD18F32A08B42C6EFA0AB659540BADB7A0FB45788F900136EE4D57B95DFBCE481C711
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AllocVirtualexitmemcpy
                                                                                                                                                                                                                                                            • String ID: @, p$Failed to alloc memory for spp code$P* p
                                                                                                                                                                                                                                                            • API String ID: 693558432-1634945694
                                                                                                                                                                                                                                                            • Opcode ID: 2e93e4e986d9f97d53b3878f1964dfd8b410e0fdcbf4d9eea155c3c6b48b6fc3
                                                                                                                                                                                                                                                            • Instruction ID: 0d06fb704eaf2b5ff1bda9ed347309337fe8eee5616eb925801cacca1f71a989
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2e93e4e986d9f97d53b3878f1964dfd8b410e0fdcbf4d9eea155c3c6b48b6fc3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F351ADB2B12B848ADF558F06E88475C73B9FB08BD4F56812AEE5D47B94EB38C591C304
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • FreeLibrary.KERNEL32(?,?,?,00007FF762AA0316,?,?,-00000018,00007FF762A9BC5B,?,?,?,00007FF762A9BB52,?,?,?,00007FF762A96EFE), ref: 00007FF762AA00F8
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,?,?,00007FF762AA0316,?,?,-00000018,00007FF762A9BC5B,?,?,?,00007FF762A9BB52,?,?,?,00007FF762A96EFE), ref: 00007FF762AA0104
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AddressFreeLibraryProc
                                                                                                                                                                                                                                                            • String ID: api-ms-$ext-ms-
                                                                                                                                                                                                                                                            • API String ID: 3013587201-537541572
                                                                                                                                                                                                                                                            • Opcode ID: d956f0b8ec152b18ca11aa0aed68125bebf2684d60339ba7369f52f17a1fcfe1
                                                                                                                                                                                                                                                            • Instruction ID: 649d171a3d09e9c3c3bcfe1c4dfc809445b60182191a59c10c8b5234ab231205
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d956f0b8ec152b18ca11aa0aed68125bebf2684d60339ba7369f52f17a1fcfe1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 07412621B19A02C1FFD5EB16A810BB5A391BF09BA0F854135DD0E87B94DEFDE845C360
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: HandleLoadModule$ClassCursorIconRegister
                                                                                                                                                                                                                                                            • String ID: TkTopLevel$Unable to register TkTopLevel class
                                                                                                                                                                                                                                                            • API String ID: 1220223050-2494010311
                                                                                                                                                                                                                                                            • Opcode ID: 556643625253ed7d50630c632c4f7a960b89ba01d3922e2c82dfbac0af9800d7
                                                                                                                                                                                                                                                            • Instruction ID: ee84628186856b08c2081e2408d72026bce13d4634c76bde6a674dcfe12536f5
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 556643625253ed7d50630c632c4f7a960b89ba01d3922e2c82dfbac0af9800d7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BA517031B08B46C2EB588B50E5A067973E4FB84B90F5051B6D9AE837D8EF3DE985C740
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Palette$ModeRealizeSelect$DrawEdgeRelease
                                                                                                                                                                                                                                                            • String ID: relief
                                                                                                                                                                                                                                                            • API String ID: 3185835912-743904975
                                                                                                                                                                                                                                                            • Opcode ID: 59dc3359514abddaf2f289b1e4825bae23218361357fdb7f36c9f7e4c3daf2be
                                                                                                                                                                                                                                                            • Instruction ID: df66334ba5525359469c1661a26674d747b5c2bbedea87a0c41c2af57f2a87b6
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 59dc3359514abddaf2f289b1e4825bae23218361357fdb7f36c9f7e4c3daf2be
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0F319376B0874283EB18AF56E46056AB7A0FB89BD1F105036DE5E877A8DF3DE444C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_new$R_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\record\ssl3_record.c$early_data_count_ok
                                                                                                                                                                                                                                                            • API String ID: 476316267-4150192623
                                                                                                                                                                                                                                                            • Opcode ID: 5c54f0c2c42b69c92628c76a614c039758d21d18141a7cb5f852ffb02c2e075f
                                                                                                                                                                                                                                                            • Instruction ID: 165c6cac42d75de5156b209e286761a868d6864aa22b7b0957c213126a9c9702
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5c54f0c2c42b69c92628c76a614c039758d21d18141a7cb5f852ffb02c2e075f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0531A721B1854386FB5C9B25E4A0FBD2291EF84748F9450B6EA2DC7BD9DE3CED418700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug$memcpy
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_clnt.c$dtls_process_hello_verify
                                                                                                                                                                                                                                                            • API String ID: 31086664-1847652839
                                                                                                                                                                                                                                                            • Opcode ID: 07fa7c377fb9e2c3e85c4b3f4c80a9268d23323efae93389544496ab1a4a1784
                                                                                                                                                                                                                                                            • Instruction ID: 1a31fe00e2c1abd04cf7dad747881b65c9580d9268e02ac3d239f12123362dce
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 07fa7c377fb9e2c3e85c4b3f4c80a9268d23323efae93389544496ab1a4a1784
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7621E661B08B8252E7189B14E9207B96260FF4C794FC49271DA7C877DEEE2CD2D08700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_clnt.c$ossl_statem_client13_write_transition$ossl_statem_client_write_transition
                                                                                                                                                                                                                                                            • API String ID: 193678381-362363770
                                                                                                                                                                                                                                                            • Opcode ID: d22fdbb112affdc835ab4f78b4c6e42dc0328af198725e085c2f07972e3c75e6
                                                                                                                                                                                                                                                            • Instruction ID: 9d5a8bb2a543135478330a7ad661f485835de4e302cad9cae0e28ad5c80d5858
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d22fdbb112affdc835ab4f78b4c6e42dc0328af198725e085c2f07972e3c75e6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: FD21D121B18A4382E7489B15E5B0EBC2761EF58788F9490B1E92EC77D9CE2CE5928700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_srvr.c$p$ssl_check_srp_ext_ClientHello
                                                                                                                                                                                                                                                            • API String ID: 193678381-2953162070
                                                                                                                                                                                                                                                            • Opcode ID: 46459223bfa009af9bd0d330c5bcc9680d94e7733332853bdd941ca749adba65
                                                                                                                                                                                                                                                            • Instruction ID: 4405565d93c0b896a0e6d9d33f37299a6ad432b40e7963763421c1b844cfb4ba
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 46459223bfa009af9bd0d330c5bcc9680d94e7733332853bdd941ca749adba65
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EE11E1A1F2C64342F768A725D431FB81650AF84718FD461B1EE3CC66DAEF6CEA818700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_lib.c$SSL_shutdown
                                                                                                                                                                                                                                                            • API String ID: 1552677711-3410285451
                                                                                                                                                                                                                                                            • Opcode ID: e01a6b8ad3575db4ecafd5eb3245e32b2f3a2161471a74a3d5973b7b085d365c
                                                                                                                                                                                                                                                            • Instruction ID: e054858bd75c7cb250677ef97ea9c74fde449a6d6a0420f92ac7f1af586fb108
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e01a6b8ad3575db4ecafd5eb3245e32b2f3a2161471a74a3d5973b7b085d365c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4921C325F286C382FB58A710E421BBA2350EF84758F9442B2ED7D877D9DF7CEA458610
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: L_sk_numR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_lib.c$SSL_CTX_set_ssl_version
                                                                                                                                                                                                                                                            • API String ID: 2983925012-1434314342
                                                                                                                                                                                                                                                            • Opcode ID: de7af9a8002a7265b59531912c3e72b1205b8a41de960d78bd4ae598ca37786d
                                                                                                                                                                                                                                                            • Instruction ID: 4e29a810352cb37f62632ad9af33a3a58dea7d1e65b84a47d90ade691836fa86
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: de7af9a8002a7265b59531912c3e72b1205b8a41de960d78bd4ae598ca37786d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4F11E564B1C60392FB5CA7A0A861AF91250AF44748F8481B4ED2CC73CEDE7CE9428300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug$X_copy_ex
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_lib.c$tls13_restore_handshake_digest_for_pha
                                                                                                                                                                                                                                                            • API String ID: 3813578642-2862071989
                                                                                                                                                                                                                                                            • Opcode ID: 014ffa14c80ab47ebd4243da50ec09e5cece0ad2e46f9c323556154d44df1dcc
                                                                                                                                                                                                                                                            • Instruction ID: 3290ff6f3e7275e78532075e23213cfe42f985197cfa8a472371c9e4ec3a5429
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 014ffa14c80ab47ebd4243da50ec09e5cece0ad2e46f9c323556154d44df1dcc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0A015E54F1C54381FB5CA362A831FF905409F84388FD860B1DD2CC6BCAEE1CDA818700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fwrite$S_double_to_stringstrlen
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4243900985-0
                                                                                                                                                                                                                                                            • Opcode ID: f2a18d47840bebb76e4ee471963179028cc42b4c8b19f064614cbc55886a8c8a
                                                                                                                                                                                                                                                            • Instruction ID: 0c96fa16201ad5da9063c83b12b4113f05bc2fe770ce5d870ff57af6c1de982d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f2a18d47840bebb76e4ee471963179028cc42b4c8b19f064614cbc55886a8c8a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2A61B3A3305B8486DB06CF61E95439D37B5F748FE8F958226CE5E07788DA38C695C780
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchr
                                                                                                                                                                                                                                                            • String ID: , "#x,y"$, <index>$, n, ne, e, se, s, sw, w, nw, or center$H$OFFSET$VALUE$bad offset "%s": expected "x,y"
                                                                                                                                                                                                                                                            • API String ID: 2830005266-4019575897
                                                                                                                                                                                                                                                            • Opcode ID: f43346f8fed5eda50b2fa0b8848dcd5bd21bf3dff20c50e663a315537a1f9ed5
                                                                                                                                                                                                                                                            • Instruction ID: 7b33b6326f547624442d79e2a1a9136b27da510213d1661bbd411cf18235aab8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f43346f8fed5eda50b2fa0b8848dcd5bd21bf3dff20c50e663a315537a1f9ed5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E9619226B08B5686E709EFA69860AB937E5BF45BD4F148272DD2E573D8EF3CD4418300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strncmp
                                                                                                                                                                                                                                                            • String ID: ?boolean?$LOOKUP$TOPLEVEL$option$option window ?arg ...?$tracing$window "%s" isn't a top-level window
                                                                                                                                                                                                                                                            • API String ID: 1114863663-1970093346
                                                                                                                                                                                                                                                            • Opcode ID: 73196f88650483e316a518618d6619902b31e63800dadfeddd73f044055421b4
                                                                                                                                                                                                                                                            • Instruction ID: 642e91c15b6033b658b11f52f2e070749e571dc5e10b6d69e84ba06c7e4daba4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 73196f88650483e316a518618d6619902b31e63800dadfeddd73f044055421b4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1751B632B08A46D6EB189B65E860ABC33A4FB44B84F414072CE6D97398DF3CE945D300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_free$O_new$O_s_connect
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3895418919-0
                                                                                                                                                                                                                                                            • Opcode ID: 09d7bef003b35f56610a8ffa23070becaf30355512767d9973eed380cd1290e9
                                                                                                                                                                                                                                                            • Instruction ID: dee03a8fd9bb8a2a53245575edaf0b38cb224fefe6f89b2dfb9ec1e4c758ca93
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 09d7bef003b35f56610a8ffa23070becaf30355512767d9973eed380cd1290e9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EE115A05F2D74341FF9CA7526571AB942815F95BC8E4861B4ED2E4BBCFEEACE6424300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strncmp
                                                                                                                                                                                                                                                            • String ID: TCL$Usage: %s dump ?-all -image -text -mark -tag -window? ?-command script? index ?index2?$WRONGARGS$end$option$unexpected switch fallthrough
                                                                                                                                                                                                                                                            • API String ID: 1114863663-3976441248
                                                                                                                                                                                                                                                            • Opcode ID: 76ee9171219d672615a54174031f4987fe0b98a9c5eb5cd0c81bc8e963060e02
                                                                                                                                                                                                                                                            • Instruction ID: 885f5b3a15519d298354db8243cb345229f4df2fde4d3e16ea0665f20885f842
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 76ee9171219d672615a54174031f4987fe0b98a9c5eb5cd0c81bc8e963060e02
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8DC18E32B1978182DB689F95E450B6AB7E0FB88B94F448176EE5E4B798DF3CE444C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Sleep_amsg_exit
                                                                                                                                                                                                                                                            • String ID: p"p$@+!p
                                                                                                                                                                                                                                                            • API String ID: 1015461914-3699326670
                                                                                                                                                                                                                                                            • Opcode ID: bcd4b4baac9f08988e5c213aecf1d1386b9581e12dfe6454379e387d22a1bde6
                                                                                                                                                                                                                                                            • Instruction ID: 2634bde140a41d8e12d0f139c61d20f7b1c7aa99a57314fcc524c52e481dc51a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bcd4b4baac9f08988e5c213aecf1d1386b9581e12dfe6454379e387d22a1bde6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9D41C133B05648C9E7038B16FD4435A2279B788BE5F564126EE0D47795EE7CE9D2CB00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_ctrlR_newR_set_debugmemcpy
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_dtls.c$dtls1_retransmit_message
                                                                                                                                                                                                                                                            • API String ID: 152836652-3409696843
                                                                                                                                                                                                                                                            • Opcode ID: eb185db770c5c399314ec9ff4d4e9ba1ee8b48febe3c0dd6f3e67cc8817c356f
                                                                                                                                                                                                                                                            • Instruction ID: a31fc8801a2e5d778f51c90031817a6010e206aa8cb53376884352accd8f20bf
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: eb185db770c5c399314ec9ff4d4e9ba1ee8b48febe3c0dd6f3e67cc8817c356f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DA517C36314B85D2D7989B25E590BAA77A8FB88B84F504036EFAC83785DF79D0A5C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: O_ctrl$R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\d1_lib.c$dtls1_check_timeout_num
                                                                                                                                                                                                                                                            • API String ID: 1786956097-2777391390
                                                                                                                                                                                                                                                            • Opcode ID: fb2a60d7eef8c5264e7618323a273bbfffb5bf7cc9a8c4468f3375c36fc04c90
                                                                                                                                                                                                                                                            • Instruction ID: a24f2b780e510432d405ac359c1a7cba3feccaf09bb7cc0a9b6e80b3b19c2549
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fb2a60d7eef8c5264e7618323a273bbfffb5bf7cc9a8c4468f3375c36fc04c90
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7B519E72B2468282DB9CDB26D564BFC36A1EB84B84F4441B5DB2E477D9CF7CE0918700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,00007FF762A82AC6,?,00007FF762A82BC5), ref: 00007FF762A82360
                                                                                                                                                                                                                                                            • FormatMessageW.KERNEL32(?,?,?,?,?,?,?,?,00007FF762A82AC6,?,00007FF762A82BC5), ref: 00007FF762A8241A
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentFormatMessageProcess
                                                                                                                                                                                                                                                            • String ID: %ls$%ls: $<FormatMessageW failed.>$[PYI-%d:ERROR]
                                                                                                                                                                                                                                                            • API String ID: 27993502-4247535189
                                                                                                                                                                                                                                                            • Opcode ID: 0a5126680d9a5a33d726664b64f5652ef3955638bb5392e7feaf9fce88ad1497
                                                                                                                                                                                                                                                            • Instruction ID: 66952ce7c9cbe640506a4bce4fc7b276847041c5182a4b3f933631286dc01645
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0a5126680d9a5a33d726664b64f5652ef3955638bb5392e7feaf9fce88ad1497
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E031B562B08A4181EBA0BB65B814AFAE251FF84BD5F800135EF8D53B59DEFCD506C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • LoadLibraryExW.KERNEL32(?,?,?,00007FF762A8D50A,?,?,?,00007FF762A8D1FC,?,?,?,00007FF762A8CDF9), ref: 00007FF762A8D2DD
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,00007FF762A8D50A,?,?,?,00007FF762A8D1FC,?,?,?,00007FF762A8CDF9), ref: 00007FF762A8D2EB
                                                                                                                                                                                                                                                            • LoadLibraryExW.KERNEL32(?,?,?,00007FF762A8D50A,?,?,?,00007FF762A8D1FC,?,?,?,00007FF762A8CDF9), ref: 00007FF762A8D315
                                                                                                                                                                                                                                                            • FreeLibrary.KERNEL32(?,?,?,00007FF762A8D50A,?,?,?,00007FF762A8D1FC,?,?,?,00007FF762A8CDF9), ref: 00007FF762A8D383
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,?,?,00007FF762A8D50A,?,?,?,00007FF762A8D1FC,?,?,?,00007FF762A8CDF9), ref: 00007FF762A8D38F
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Library$Load$AddressErrorFreeLastProc
                                                                                                                                                                                                                                                            • String ID: api-ms-
                                                                                                                                                                                                                                                            • API String ID: 2559590344-2084034818
                                                                                                                                                                                                                                                            • Opcode ID: ec1d8984956c5f4cef63aabdc1ab3d005d502d88db624b4fbd9ceb099b80f4f4
                                                                                                                                                                                                                                                            • Instruction ID: 23d55cf940a4fdfde352bc3151eb89f74e18843ff0b99df9127ee714e4cee9d5
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ec1d8984956c5f4cef63aabdc1ab3d005d502d88db624b4fbd9ceb099b80f4f4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 69319221B1AE42D1EF91BB22A800A79A394FF49BA0F990536DD5D4B784DFFCE445C320
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchr
                                                                                                                                                                                                                                                            • String ID: , "#x,y"$, <index>$, n, ne, e, se, s, sw, w, nw, or center$OFFSET$VALUE$bad offset "%s": expected "x,y"
                                                                                                                                                                                                                                                            • API String ID: 2830005266-3316042839
                                                                                                                                                                                                                                                            • Opcode ID: 7c8e540d24c5b17aeb677f78c70aefb307d965981cd734d12e50057b8dcabd72
                                                                                                                                                                                                                                                            • Instruction ID: 8e38e8abe435762dec3c1b9ab9bf1a28f9dd68a95c4cf017ba391550ecff2568
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7c8e540d24c5b17aeb677f78c70aefb307d965981cd734d12e50057b8dcabd72
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D8313025709B5682EB099F5AE4647B927A0FF85BA4F4441B2CD2E573E8EF3CE1459300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_srvr.c$dtls_construct_hello_verify_request
                                                                                                                                                                                                                                                            • API String ID: 193678381-1802759638
                                                                                                                                                                                                                                                            • Opcode ID: 2850ca749253e857390bc61ba79b17576458301e42ec05df5474438db862f8bb
                                                                                                                                                                                                                                                            • Instruction ID: df395d3abc65123690ad4464648a3fab66d3ff83ec37a7fa3ba1eb6c005d9fcf
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2850ca749253e857390bc61ba79b17576458301e42ec05df5474438db862f8bb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1931B625B1868341F7589B11E860FF92650EF98BD8F985171EE6D87BDECF2CD5418700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Token$InformationProcess$CloseConvertCurrentErrorHandleLastOpenString
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 995526605-0
                                                                                                                                                                                                                                                            • Opcode ID: 4b16fab3d36e05ad3a3445a5c074aa8767ee98c8fbd83efe929b6b0b20bb971a
                                                                                                                                                                                                                                                            • Instruction ID: a70eae16e7ee41aba460752b8da8f3fba74745b7f239b9a07a5e81812939342e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4b16fab3d36e05ad3a3445a5c074aa8767ee98c8fbd83efe929b6b0b20bb971a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A4215575B0CA42C1EF90AB55A84096AE3A1EF857E0F904235DE9D47AE4DEFCD445C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strncmp
                                                                                                                                                                                                                                                            • String ID: ORIENTATION$VALUE$bad orientation "%s": must be vertical or horizontal$horizontal$vertical
                                                                                                                                                                                                                                                            • API String ID: 1114863663-2193956672
                                                                                                                                                                                                                                                            • Opcode ID: 3d259dddfe438d550d3715601501e6e392b88d69fbdcec59ca5b17d174f87079
                                                                                                                                                                                                                                                            • Instruction ID: 9edc2cca0cb121c445cbbd7936535a35bd1827a7fd3e518288a4f4430abfc66f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3d259dddfe438d550d3715601501e6e392b88d69fbdcec59ca5b17d174f87079
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3F216D25B08A5686EB58AF95A46097963E0FF55B90F488171DAAD4B2DCDF3CE045C700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions.c$final_renegotiate
                                                                                                                                                                                                                                                            • API String ID: 193678381-1135624566
                                                                                                                                                                                                                                                            • Opcode ID: d4426147b3ccce134b531e04148ddf8622f480012cec1f154ba5b40c37154f52
                                                                                                                                                                                                                                                            • Instruction ID: 51181ae7b8b2e2e97a23fc79ca3e89528362c959604023048b9e88cbcf53817d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d4426147b3ccce134b531e04148ddf8622f480012cec1f154ba5b40c37154f52
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6411A021F5914342FB6D9354E8A6FB412409F86355FD850B0E92CCABDACE3DAA828700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
                                                                                                                                                                                                                                                            • String ID: CONOUT$
                                                                                                                                                                                                                                                            • API String ID: 3230265001-3130406586
                                                                                                                                                                                                                                                            • Opcode ID: 09a7ef29c2f791f79e4b414a588c98caae924e0a86b8d7fe5631f15f3a619b4d
                                                                                                                                                                                                                                                            • Instruction ID: eb12f1851bcb1c9878626ede341390a1ec5c6537cb24efeb3d48ad4405937d90
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 09a7ef29c2f791f79e4b414a588c98caae924e0a86b8d7fe5631f15f3a619b4d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 45118461718A41C6EBD0AB52E844729B2A0FF88BE4F904234DD5D47B94CFFCD444C790
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debugR_set_errormemcpy
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_lib.c$SSL_CTX_set_session_id_context
                                                                                                                                                                                                                                                            • API String ID: 1331007688-1727046036
                                                                                                                                                                                                                                                            • Opcode ID: 5f896278a7051c55df5368c5f29cea42bee8b2c7200fccf92a2291c6ce1353ad
                                                                                                                                                                                                                                                            • Instruction ID: e4566fcc06955db596109ac5e40d1eef001ff8568a142b63a0282208dac7edd4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5f896278a7051c55df5368c5f29cea42bee8b2c7200fccf92a2291c6ce1353ad
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3DF0E534F2805362F7ACB3A48862FF900509F84300FD080B0E52D86BDEDD9D6A454710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debugR_set_errormemcpy
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\ssl_lib.c$SSL_set_session_id_context
                                                                                                                                                                                                                                                            • API String ID: 1331007688-2523474329
                                                                                                                                                                                                                                                            • Opcode ID: 9bb603b4da55ab756aec237d2dd3c42fa578c3e8bf15eb550f550ff7c5317006
                                                                                                                                                                                                                                                            • Instruction ID: 0bbec49a249223670ff9ded4534b42959bffbcfe689c6cb57792ce2d4ff12536
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9bb603b4da55ab756aec237d2dd3c42fa578c3e8bf15eb550f550ff7c5317006
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2CF09219F2859352F76CB3A4D862FF91150AF84340FD090B1E92C86BDBDD6DAA860B10
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: bad const entries to bmapOptions in ImgBmapCmd$option$option ?arg ...?$tkConfigSpec.threadTable
                                                                                                                                                                                                                                                            • API String ID: 0-710070775
                                                                                                                                                                                                                                                            • Opcode ID: c7adc2d3dfcf261ba6ad0a608db822c5165b417362711c27dff588d7db895964
                                                                                                                                                                                                                                                            • Instruction ID: 8e94ca06162c7b3447dfc6db1c7c37a7adbe2dc35d9a49b40cf5a0e5e3e04c6a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c7adc2d3dfcf261ba6ad0a608db822c5165b417362711c27dff588d7db895964
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B7F16731B09B4287EB18AF96E864AB933A4FB89B84F444075DE2D477A8DF3CD945C701
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcess.KERNEL32(FFFFFFFF,?,?,00000000,00007FF762A88706), ref: 00007FF762A879E2
                                                                                                                                                                                                                                                            • K32EnumProcessModules.KERNEL32(?,?,00000000,00007FF762A88706), ref: 00007FF762A87A39
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A88950: MultiByteToWideChar.KERNEL32(?,?,?,00007FF762A83A04,00000000,00007FF762A81965), ref: 00007FF762A88989
                                                                                                                                                                                                                                                            • K32GetModuleFileNameExW.KERNEL32(?,?,00000000,00007FF762A88706), ref: 00007FF762A87AC8
                                                                                                                                                                                                                                                            • K32GetModuleFileNameExW.KERNEL32(?,?,00000000,00007FF762A88706), ref: 00007FF762A87B34
                                                                                                                                                                                                                                                            • FreeLibrary.KERNEL32(?,?,00000000,00007FF762A88706), ref: 00007FF762A87B45
                                                                                                                                                                                                                                                            • FreeLibrary.KERNEL32(?,?,00000000,00007FF762A88706), ref: 00007FF762A87B5A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileFreeLibraryModuleNameProcess$ByteCharCurrentEnumModulesMultiWide
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3462794448-0
                                                                                                                                                                                                                                                            • Opcode ID: b9b63f54144ba03940088346b196338d5c2960aef7cb953cd42f14819606a153
                                                                                                                                                                                                                                                            • Instruction ID: ba9d769ff319d81d3f4927f3d1f1f41821441393657c6b842fe01330002a6561
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b9b63f54144ba03940088346b196338d5c2960aef7cb953cd42f14819606a153
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2041B366B19682C1EFB0AB12A844AAAE395FF48BC4F840135DF8D97795DEFCD501C720
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Palette$DeleteDrawEdgeModeRealizeReleaseSelect
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1417962085-0
                                                                                                                                                                                                                                                            • Opcode ID: f150c320a4626fbe41249a25cf46f38c3cfcfe922d916238c3e8a0e50543d58f
                                                                                                                                                                                                                                                            • Instruction ID: 0baea1f332d2c5f0462485f1b873510c55ad32e733fdc11acde0b4f1557b2762
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f150c320a4626fbe41249a25cf46f38c3cfcfe922d916238c3e8a0e50543d58f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2A319376B0868287E754EF66E860A69B7A0FB88BC4F045076DE5D87799CF3CE444CB00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C1D7
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C20D
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C23A
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C24B
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C25C
                                                                                                                                                                                                                                                            • SetLastError.KERNEL32(?,?,?,00007FF762A95E51,?,?,?,?,00007FF762A9B392,?,?,?,?,00007FF762A980CB), ref: 00007FF762A9C277
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Value$ErrorLast
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2506987500-0
                                                                                                                                                                                                                                                            • Opcode ID: cd140ed500cd0c82a50e9bec5cbca94b7f65b5ea9b6864ee2a07c94a3d21de84
                                                                                                                                                                                                                                                            • Instruction ID: e5af5d55bf96298790d327a77ed8d5003dbd11848b76ced79e338d94becddc0c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cd140ed500cd0c82a50e9bec5cbca94b7f65b5ea9b6864ee2a07c94a3d21de84
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6C114C20E1CB42C2FFD4B3A65A41A79D1425F48BA0FA44735DD2E16BE6DEECA805C760
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fabs
                                                                                                                                                                                                                                                            • String ID: (horizontal scrolling command executed by text)$ $
                                                                                                                                                                                                                                                            • API String ID: 3906731895-1218255861
                                                                                                                                                                                                                                                            • Opcode ID: ae011e1da2b714a703af178e474b492f0b9e33b12ad557f2a1a685265b40dc6b
                                                                                                                                                                                                                                                            • Instruction ID: 72d4bf2e43f7db07af5ef5e82f4950a6ae69ac4b4f3bad12d1b1900ddcc93896
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ae011e1da2b714a703af178e474b492f0b9e33b12ad557f2a1a685265b40dc6b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9771AD22B14B8582E7169F79D4546E963A4FF9DBD8F048372DE6D637A9EF28D0428300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MessageSendTextWindow
                                                                                                                                                                                                                                                            • String ID: window ?newTitle?
                                                                                                                                                                                                                                                            • API String ID: 893732450-417226443
                                                                                                                                                                                                                                                            • Opcode ID: 4a902224eea40daa3ba986301a04d28a237949b0052c429a3d25949cd7618f81
                                                                                                                                                                                                                                                            • Instruction ID: 9dbe54a7ca4ba8184a6773fa018277d71ce348e902fd61adf440f4f74b280ac1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4a902224eea40daa3ba986301a04d28a237949b0052c429a3d25949cd7618f81
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B2518032719A85C2DB588B12E864BB923A0FB88FA4F045271DE7E877D8DF3CD1458700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\t1_lib.c$tls12_copy_sigalgs
                                                                                                                                                                                                                                                            • API String ID: 1552677711-2872464142
                                                                                                                                                                                                                                                            • Opcode ID: de738f4223b762254d798ee3f030c5c4710f3fb5bd1c0625696672452cc75c07
                                                                                                                                                                                                                                                            • Instruction ID: 793039ce0406e5e226db354c10e606c532bb198c8ee56e23d4d565390010d88b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: de738f4223b762254d798ee3f030c5c4710f3fb5bd1c0625696672452cc75c07
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9631A326F0866245F7689A25D424A7A6392EF84BC4F9C9071DF7CCB7C9CFACE9408340
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debugR_set_error
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\s3_msg.c$ssl3_do_change_cipher_spec
                                                                                                                                                                                                                                                            • API String ID: 1552677711-2597545827
                                                                                                                                                                                                                                                            • Opcode ID: 60e520d8aebe081696f54a5925cd5329a05629a48b89abccf59f5ae7d3e1307c
                                                                                                                                                                                                                                                            • Instruction ID: 3633915bec9b4960f96e4773935955334c6e188210a8b5f74a3118a38387a4a2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 60e520d8aebe081696f54a5925cd5329a05629a48b89abccf59f5ae7d3e1307c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7121E432B1468682EB4C8B69E8947AD13A0FB88B84F985071DA2D877D9CE3CC8C1C740
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AddressFreeHandleLibraryModuleProc
                                                                                                                                                                                                                                                            • String ID: CorExitProcess$mscoree.dll
                                                                                                                                                                                                                                                            • API String ID: 4061214504-1276376045
                                                                                                                                                                                                                                                            • Opcode ID: f90418b582b416691a14bbb2ae6c6b71f2096e7654ee2338269033ad2dc175a6
                                                                                                                                                                                                                                                            • Instruction ID: ca0ca4163430e266e0447d1206e1fbe60c4528e3ebc94023d0a33cc5d61dacc9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f90418b582b416691a14bbb2ae6c6b71f2096e7654ee2338269033ad2dc175a6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 10F0C821E18A02C2EF946B10E844B79D320EF48761FD4063ACD5E465E4CFECD444C760
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • PyFunction_NewWithQualName.PYTHON313 ref: 7019309C
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Function_NameQualWith
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 34993411-0
                                                                                                                                                                                                                                                            • Opcode ID: ef5d882891a984cbbeaf19598054102080780fcfc7270a8da7b3ac04c027a61b
                                                                                                                                                                                                                                                            • Instruction ID: 28f8a021961db1ae4f9359b6b370dfcc81f602371d3e9d9a2470f0044392a3fb
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ef5d882891a984cbbeaf19598054102080780fcfc7270a8da7b3ac04c027a61b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C5414F32726BC086DB165F56AA4475D22B5F754B88F2981389F4F47F28EF39D891C308
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: sprintfstrlen
                                                                                                                                                                                                                                                            • String ID: ../src/platforms/windows/hdinfo.c$/%d:$No any serial number of harddisk got
                                                                                                                                                                                                                                                            • API String ID: 1090396089-4267867539
                                                                                                                                                                                                                                                            • Opcode ID: 0b270c3a68b26a0c29bb9df2e1a6663fd443877262d63a55ef449ebf61b5fc53
                                                                                                                                                                                                                                                            • Instruction ID: 358bc3e1ed0b2f4d248958e119cd5bfaea6171df37b7d619b5303f0583377866
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0b270c3a68b26a0c29bb9df2e1a6663fd443877262d63a55ef449ebf61b5fc53
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3531AC53B380D44BEB028B39BC40BAD6612B75ABE0FA84331ED1657A88D57899C6C708
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • FlsGetValue.KERNEL32(?,?,?,00007FF762A9B4E7,?,?,00000000,00007FF762A9B782,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9C2AF
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A9B4E7,?,?,00000000,00007FF762A9B782,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9C2CE
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A9B4E7,?,?,00000000,00007FF762A9B782,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9C2F6
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A9B4E7,?,?,00000000,00007FF762A9B782,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9C307
                                                                                                                                                                                                                                                            • FlsSetValue.KERNEL32(?,?,?,00007FF762A9B4E7,?,?,00000000,00007FF762A9B782,?,?,?,?,?,00007FF762A9B70E), ref: 00007FF762A9C318
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Value
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3702945584-0
                                                                                                                                                                                                                                                            • Opcode ID: f43b7e8ffdaa9f4f156d0b1eb130a323da5c860b472f5ddb223cc1376774324f
                                                                                                                                                                                                                                                            • Instruction ID: a4dc2ebadb1afc0c3fde04c17fdc47dab259f9fa8ccef5eb07a43353b3505cbb
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f43b7e8ffdaa9f4f156d0b1eb130a323da5c860b472f5ddb223cc1376774324f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 81113860E1CB42C2FFD8B3669941A7AE1425F487A0FE44735ED2D167D6DEECA805C620
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Value
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3702945584-0
                                                                                                                                                                                                                                                            • Opcode ID: 5830a724a110e18c9dc77d9d0afd73a4b7733b8d85f13529bf141d4281ca4b95
                                                                                                                                                                                                                                                            • Instruction ID: fb6eeae55dbbdb4ea9d8c9201b159eddf0659c53d3be8551d5598476f4d9439f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5830a724a110e18c9dc77d9d0afd73a4b7733b8d85f13529bf141d4281ca4b95
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DC11E650E28702C2FFD9B2664C51A79D1424F69360EF80B39DD2E196E2DDECBC49CA60
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: X509_$E_dupE_freeL_sk_new_nullL_sk_pushX509_get_subject_name
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2231116090-0
                                                                                                                                                                                                                                                            • Opcode ID: 712267dbf220d7e88cc7398d0bf8103df0ea73be6231437d623d14cdf0da1634
                                                                                                                                                                                                                                                            • Instruction ID: cab27f37e23e4d51ab7d8fb9b9ea9790252e348ad4b0933c5a775fb789d49c04
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 712267dbf220d7e88cc7398d0bf8103df0ea73be6231437d623d14cdf0da1634
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C8F0F965F1D60380FF4DA765A971BB902915F44BC4F489071ED2C877CEFE6CE8404200
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Palette$DeleteDrawEdgeModeRealizeReleaseSelect
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1417962085-0
                                                                                                                                                                                                                                                            • Opcode ID: 6afd0942f838d39ebf27b18e9751cf14c4f2419546be634831a756ba57f56ade
                                                                                                                                                                                                                                                            • Instruction ID: 37b866032d730e6a25bc58186b5ef9ef9df9bad8a5ac7c29d8544b7549a47338
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6afd0942f838d39ebf27b18e9751cf14c4f2419546be634831a756ba57f56ade
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 33F04425B08643C3F718BF96F46083963A0AF86BD1F105075CE5B47798CE7DE0858700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Palette$DeleteDrawEdgeModeRealizeReleaseSelect
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1417962085-0
                                                                                                                                                                                                                                                            • Opcode ID: 9ab765aa9acdea87c5fd4daa5b53e318745ca2030bdc4831e9903f9a53502aab
                                                                                                                                                                                                                                                            • Instruction ID: 95edd41ddf9d1109038da6e0c44fdb8c196b519916d0836746860931e09a0468
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9ab765aa9acdea87c5fd4daa5b53e318745ca2030bdc4831e9903f9a53502aab
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7FF04425B08643C3F718BF96F86083963A0AF86BD2F105075CE5B47798CE7DE0858700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Palette$DeleteDrawEdgeModeRealizeReleaseSelect
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1417962085-0
                                                                                                                                                                                                                                                            • Opcode ID: d3248f4eef2a148c864aa84d2b47cc2491a639f149807ee35d61a8bec0546c35
                                                                                                                                                                                                                                                            • Instruction ID: e0bb408aed36b60c3e823549dccbb0287a6d07d2cd7164a992f6c2383850a65e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d3248f4eef2a148c864aa84d2b47cc2491a639f149807ee35d61a8bec0546c35
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 48F04425B08643C3F718BF96F46083963A1AF86BD1F105075CE5B47798CE7DE0858700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Palette$DeleteDrawEdgeModeRealizeReleaseSelect
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1417962085-0
                                                                                                                                                                                                                                                            • Opcode ID: 8478bbcdd0190cde79158d6ccafa2085e547d746aff20ad6c48c372a5f350f57
                                                                                                                                                                                                                                                            • Instruction ID: 2b0517da8892d4277e335c8cb6180a9f768aa6fd23cd6063fb5bb50274121bcb
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8478bbcdd0190cde79158d6ccafa2085e547d746aff20ad6c48c372a5f350f57
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F7F03125B0864783F718AF96F46083963A0AF86BD2F105075CE5B47799CE7DE0858700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: abortfwrite
                                                                                                                                                                                                                                                            • String ID: '$illegal index register
                                                                                                                                                                                                                                                            • API String ID: 1067672060-451399654
                                                                                                                                                                                                                                                            • Opcode ID: c0f7cf555bdd8ab06e1202336d5bccdc5f353f75817d448e9e03fcec8ebc84d7
                                                                                                                                                                                                                                                            • Instruction ID: 1eb61466bdc5d1b0328500554ca32f988dddc1c2fd5c4d159e35bde0e78b00e3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c0f7cf555bdd8ab06e1202336d5bccdc5f353f75817d448e9e03fcec8ebc84d7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6F916D7761AB89C4DB128F3DE890A4C3F65E395F88BAAC112CB4D47B14CA7EC956C311
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
                                                                                                                                                                                                                                                            • String ID: csm
                                                                                                                                                                                                                                                            • API String ID: 2395640692-1018135373
                                                                                                                                                                                                                                                            • Opcode ID: ab412f78eb90613ff4c98a1fac2d50a5770803065215d444c3ce453a3de23157
                                                                                                                                                                                                                                                            • Instruction ID: 8b839578d54c4051ecafa202a9e52c89a6f399a9b07acbfb5e63abde33a77a4e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ab412f78eb90613ff4c98a1fac2d50a5770803065215d444c3ce453a3de23157
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0C519332B19602CADF98AF15E044E79B7A2EB44B98F914231DE4947785EFFCE841CB10
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CallEncodePointerTranslator
                                                                                                                                                                                                                                                            • String ID: MOC$RCC
                                                                                                                                                                                                                                                            • API String ID: 3544855599-2084237596
                                                                                                                                                                                                                                                            • Opcode ID: 2d0d38728c8b81eb1afee087d1255ca92539906646f1d2432080e5defd871a42
                                                                                                                                                                                                                                                            • Instruction ID: d7af30e578c9a96058b7463cdc39b83fe55648c0987b07dd193f63e56634c4de
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2d0d38728c8b81eb1afee087d1255ca92539906646f1d2432080e5defd871a42
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 18616E32908BC5C1DBA0AB25E540BAAF7A0FB95794F444635EE9D03B95DFBCE190CB10
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_srvr.c$ossl_statem_server13_write_transition
                                                                                                                                                                                                                                                            • API String ID: 193678381-3318936413
                                                                                                                                                                                                                                                            • Opcode ID: 0078360293fa6774baecf074ce71a66c5cd5d0e725b8f867d0eb2be1ebc03443
                                                                                                                                                                                                                                                            • Instruction ID: 54db0f7d2ff71585d7ce1330ce5f0a0ff0e61ea9f579f11eef32626baf4f61d7
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0078360293fa6774baecf074ce71a66c5cd5d0e725b8f867d0eb2be1ebc03443
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 580104A3F18643C2E3449754F8BABAF2760DF58398F9A9071DA2CC23D9DE1CD5428301
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_construct_ctos_sig_algs
                                                                                                                                                                                                                                                            • API String ID: 193678381-4035473336
                                                                                                                                                                                                                                                            • Opcode ID: 11d015de1a9fcf0067619224bc33120071bddcdfca4f466b925c15e431c974bc
                                                                                                                                                                                                                                                            • Instruction ID: 59ac79117c5fc24e389469018974c76f4d0d175c3115e2bf9103b6582fc36a63
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 11d015de1a9fcf0067619224bc33120071bddcdfca4f466b925c15e431c974bc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B831B321B1C68341F758A712E961BFA5691AF94BC4F8800B1ED6D87BDFDF2CD8818700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • CreateDirectoryW.KERNEL32(00000000,?,00007FF762A828EC,FFFFFFFF,00000000,00007FF762A8336A), ref: 00007FF762A87372
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CreateDirectory
                                                                                                                                                                                                                                                            • String ID: %.*s$%s%c$\
                                                                                                                                                                                                                                                            • API String ID: 4241100979-1685191245
                                                                                                                                                                                                                                                            • Opcode ID: edef38ff62529b20aa9e4dd174cb85ee92fdf6a12d4b4b11e6a9369b37dc6bc2
                                                                                                                                                                                                                                                            • Instruction ID: 2e76ebc460690b9bf58e07e7c156120a813b5508b20d4fd994585967942e66a2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: edef38ff62529b20aa9e4dd174cb85ee92fdf6a12d4b4b11e6a9369b37dc6bc2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F631B821719AC5C5EFA1AB21E810BEAA354EF84BE0F840631EEAD477D5DEECD245C710
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_construct_ctos_srp
                                                                                                                                                                                                                                                            • API String ID: 0-2342567248
                                                                                                                                                                                                                                                            • Opcode ID: 358a17fbe3d2d3da706c97d863231402fb8d59c6bc4c98501c55b40440b14115
                                                                                                                                                                                                                                                            • Instruction ID: 2f7fd98242e4ef37121d959460a622637691f5665d0260bccd5471f23b56d433
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 358a17fbe3d2d3da706c97d863231402fb8d59c6bc4c98501c55b40440b14115
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 22219450F2C18301FB6CA722AA21FBD05C09F907D4F8821B0ED2D8BACEDD6DE9818700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(FFFFFFFF,00000000,00000000,?,00000000,00007FF762A8866F), ref: 00007FF762A8226E
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: %ls$WARNING$[PYI-%d:%ls]
                                                                                                                                                                                                                                                            • API String ID: 2050909247-3372507544
                                                                                                                                                                                                                                                            • Opcode ID: cd56b085d0efe57ed851e26dcf7edcd69fea37fd872acd839253eedc34ddd336
                                                                                                                                                                                                                                                            • Instruction ID: 1555bf8a3fd2d24aa679b595dd03b99e05ba00b997130c612a3d8ff2a36efca4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cd56b085d0efe57ed851e26dcf7edcd69fea37fd872acd839253eedc34ddd336
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5921A422A19B8281EB90AB51F845AEAB354FF847C0F800135EE8D53A5ADEFCD115C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_srvr.c$tls_construct_stoc_maxfragmentlen
                                                                                                                                                                                                                                                            • API String ID: 193678381-2570358037
                                                                                                                                                                                                                                                            • Opcode ID: e764bcf132bf6faa665165a84e2b9699e2ee4015a3bf704b29aa579b509d1a60
                                                                                                                                                                                                                                                            • Instruction ID: 46fe201477fae90f648dffe6b610f7bbd86b0b126cd5aaf0e93da6d81594e4b1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e764bcf132bf6faa665165a84e2b9699e2ee4015a3bf704b29aa579b509d1a60
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CF119322B2C64342FB5C9766F925FF916809F84784F8811B1ED2D87BDBDE6ED5814700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_srvr.c$tls_construct_stoc_server_name
                                                                                                                                                                                                                                                            • API String ID: 193678381-1140354471
                                                                                                                                                                                                                                                            • Opcode ID: 3a756125b3207988a74fb8d1924fecf43250ba1ea85abce27b618cecaadc4e08
                                                                                                                                                                                                                                                            • Instruction ID: 1608f63b1a1a89f5d97a7d1f88d57139b70593c8f59de7230a2bddf13a5b3549
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3a756125b3207988a74fb8d1924fecf43250ba1ea85abce27b618cecaadc4e08
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8911D662F2854241FB9C971AE564FB922D0DF48788F9840B1ED2CC7BDADE2DD9828704
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_srvr.c$tls_construct_stoc_psk
                                                                                                                                                                                                                                                            • API String ID: 0-812599056
                                                                                                                                                                                                                                                            • Opcode ID: 7759dbcdb6dcc623fed96bae2ebdba9b6fa5abd33760e9c0f9445c232100274e
                                                                                                                                                                                                                                                            • Instruction ID: a9b920a44120498143a69874be95436b47b979ba8f366f87cc8ed8e96ee31b9e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7759dbcdb6dcc623fed96bae2ebdba9b6fa5abd33760e9c0f9445c232100274e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BA114251B2814341FB5CA716F565FBA42819F447C4F881172EE2E8BFCEEE6DD9418700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_srvr.c$tls_construct_stoc_session_ticket
                                                                                                                                                                                                                                                            • API String ID: 193678381-585220546
                                                                                                                                                                                                                                                            • Opcode ID: 08531af34148c9eb46279d5b5725f194c4b74fa605b4ccc2fe9728b145e0cd5b
                                                                                                                                                                                                                                                            • Instruction ID: 97ee640a14ff82a1658efacd4528d190a8e61cb9ce1a4f9d080887280d099524
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 08531af34148c9eb46279d5b5725f194c4b74fa605b4ccc2fe9728b145e0cd5b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3F118221F2C54341F7589716E921FBA5591DF847C4F884170ED2D8BBDADE6DD9424700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MetricsSystem
                                                                                                                                                                                                                                                            • String ID: default state$relief
                                                                                                                                                                                                                                                            • API String ID: 4116985748-1957560746
                                                                                                                                                                                                                                                            • Opcode ID: d3bb2ddb81abfa36b7463f999a8cd2e25b28a1d9b7eb4f24b22a65e1368ed14d
                                                                                                                                                                                                                                                            • Instruction ID: c9fa0272a1716cc869bfd83d83bd7efc18bd15c27deff09fcbba44c67aef2b42
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d3bb2ddb81abfa36b7463f999a8cd2e25b28a1d9b7eb4f24b22a65e1368ed14d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: FF216A76718B81C6EB149F50F4946AA77A0FB88B44F40013ADA9D83BA8EF3CD048CB00
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_construct_ctos_ems
                                                                                                                                                                                                                                                            • API String ID: 0-3344448950
                                                                                                                                                                                                                                                            • Opcode ID: 048f3258da17d452128b3dfe0fcc02fbe07d7544ed73dbfa607138d2c96df71b
                                                                                                                                                                                                                                                            • Instruction ID: 6220ffe14994e4b2bacf683b492cbf3b17fa435c25790daf656a56e3dba212ac
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 048f3258da17d452128b3dfe0fcc02fbe07d7544ed73dbfa607138d2c96df71b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EA018061B1C58341FB58A316F961FBA0580AF84788F8851B0ED6D8BBDBEE6DD9818700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_srvr.c$tls_post_process_client_key_exchange
                                                                                                                                                                                                                                                            • API String ID: 193678381-3756838607
                                                                                                                                                                                                                                                            • Opcode ID: 4a84cbd147b1bea7423760b5dee6167f430bcb53616c76c17688b1a55df6592b
                                                                                                                                                                                                                                                            • Instruction ID: c9dea5f3b1da352360a639639a2fcbcd61b5929c010ce017196c1c8da31d09f8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4a84cbd147b1bea7423760b5dee6167f430bcb53616c76c17688b1a55df6592b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CF018461F2954341F75867659866FF901809F50708FE890B0D82CC66DAEE6CDAC1C300
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_srvr.c$ossl_statem_server_write_transition
                                                                                                                                                                                                                                                            • API String ID: 0-415349073
                                                                                                                                                                                                                                                            • Opcode ID: 12f49911946bf1d0b5f81ba942b7627f5eabe78301388d9eddc08d01160e5485
                                                                                                                                                                                                                                                            • Instruction ID: 291ffe1c7271e6c924a691b1e77fa01dabe9536e75c3bf36d77a386dad2c51ef
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 12f49911946bf1d0b5f81ba942b7627f5eabe78301388d9eddc08d01160e5485
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 54018061F1864382E7589716D8A1FB81751EF88748FD480B1DE2DC63D9CE6DEA918200
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_srvr.c$tls_construct_cert_status_body
                                                                                                                                                                                                                                                            • API String ID: 193678381-3528029177
                                                                                                                                                                                                                                                            • Opcode ID: 395af32739d9e1388a7ace2919e8de19fd8d20465216ca2341515999ba12ecb2
                                                                                                                                                                                                                                                            • Instruction ID: be83f7553811ca773d242c7579f9b6ec0e78cc0e488b8aa5799fba7c97acef89
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 395af32739d9e1388a7ace2919e8de19fd8d20465216ca2341515999ba12ecb2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AB017121B2864341E7589722E961FF91750AF49BC8F889071EE2D8BBDEEF5DD6818700
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\record\rec_layer_s3.c$ssl3_write_bytes
                                                                                                                                                                                                                                                            • API String ID: 193678381-176253594
                                                                                                                                                                                                                                                            • Opcode ID: 97a01b1f6b63d07d8817d16f0667c58319c8e769393afd9c5622f99b9a14cdde
                                                                                                                                                                                                                                                            • Instruction ID: 82ac22f567ebcd3f6835f12b706924afcbd0cc796137389949a477adf2480aeb
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 97a01b1f6b63d07d8817d16f0667c58319c8e769393afd9c5622f99b9a14cdde
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 76F08226B5C58241F725E761F831BEA16405F85378F840177DD2D466CA8D3CD1828300
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                            • String ID: ..\s\ssl\statem\statem_clnt.c$ossl_statem_client13_write_transition
                                                                                                                                                                                                                                                            • API String ID: 193678381-2379272181
                                                                                                                                                                                                                                                            • Opcode ID: aa43094e0e029467302f7513210e467e9110677a21eeea44cc079694d053710a
                                                                                                                                                                                                                                                            • Instruction ID: 74a8752285d0a4278db8cf63af0c0a33ac33e8f9e7803941403ece31a2f8a842
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: aa43094e0e029467302f7513210e467e9110677a21eeea44cc079694d053710a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3FE08620B1C54396E7589B56E5B1EFD1210EF84398FC050B5E92DC6ACECE6CD6468740
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileWrite$ConsoleErrorLastOutput
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2718003287-0
                                                                                                                                                                                                                                                            • Opcode ID: fabcd4fad7fa856dcf2e9951dc7cbf89ababb6e1d40fd4369e0489b0ae7d9f25
                                                                                                                                                                                                                                                            • Instruction ID: 6bf35f70c8acc521bfa49695b1f98c02fa60a18b2b1cd4e1ff810336a8dcceea
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fabcd4fad7fa856dcf2e9951dc7cbf89ababb6e1d40fd4369e0489b0ae7d9f25
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 12D12832F18A40C9EB50EF76D8406AC77B5FB44B98B908235CE4E57B99DEB8D446C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _get_daylight$_isindst
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4170891091-0
                                                                                                                                                                                                                                                            • Opcode ID: 89e82a0bcb92f9a57c8ce538440e566bc748d838767a3902d6c6661200ebf515
                                                                                                                                                                                                                                                            • Instruction ID: 07ad77d79be9885219963a825f5c60011a734088f6fa3077714404a29e0fb325
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 89e82a0bcb92f9a57c8ce538440e566bc748d838767a3902d6c6661200ebf515
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 53510473F04212CAEF94EF249991BBCA7A5AF10358F900235DE1E52EE5DBB8A441C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: File$ErrorHandleInformationLastNamedPeekPipeType
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2780335769-0
                                                                                                                                                                                                                                                            • Opcode ID: 77215611d5833cc4261aa3ce6efef3cbe316a0555a56b2abfd6bea145bf69a9d
                                                                                                                                                                                                                                                            • Instruction ID: e675deaff6cbeed685f9e7f28762bb57f6ea507e701365a7dacd9b1192d3232d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 77215611d5833cc4261aa3ce6efef3cbe316a0555a56b2abfd6bea145bf69a9d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A8517122E24602C9FB94EF72D8407BDA3A1AF44B88FA08535DE0947749DFF8D841C7A0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MetricsSystem
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4116985748-0
                                                                                                                                                                                                                                                            • Opcode ID: e823f4d2a7430ac650f479550248100a024e66ba2c560c68515800446523c689
                                                                                                                                                                                                                                                            • Instruction ID: cad765467942cdcc4d48bdeae20f1e4b0a1a43fcdbcdb363cb7a2a014e467f12
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e823f4d2a7430ac650f479550248100a024e66ba2c560c68515800446523c689
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7C31C125B0465683E718EB66D968F7823E0FB89B94F045071DF1D83BD9DE3DD8818740
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memset$CreateDeleteIndirectObjectRect
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4288220209-0
                                                                                                                                                                                                                                                            • Opcode ID: e1a317a4ba9bc4b0dad78ef384bb38582dab478c59f18b85210112678d3e58ea
                                                                                                                                                                                                                                                            • Instruction ID: 38376e671d3ebb52686269c9f1e4ee1eced77ca5c870d6e192ec65dee35c5d44
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e1a317a4ba9bc4b0dad78ef384bb38582dab478c59f18b85210112678d3e58ea
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7A318B72B05B8587EB28DF66D0A096977E0FB98F84B094236DB5C03B58DF38E551CB40
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: B_exCalc_D_priv_bytes_exL_cleanseN_bin2bn
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1900010111-0
                                                                                                                                                                                                                                                            • Opcode ID: 2e650176fec4419a9493c1c0973c0eefb012a33611a762d3c9d977bb0268c2fd
                                                                                                                                                                                                                                                            • Instruction ID: 122067d2f071bf30ccdcb011c485e2a991f3828f53be755690a479eca26dd377
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2e650176fec4419a9493c1c0973c0eefb012a33611a762d3c9d977bb0268c2fd
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8B317C26719A4281FB989F29D464BA923A0FF88B88F984036DE5D8B7DDDF3CD541C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CountTick$MessagePeek
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4145102785-0
                                                                                                                                                                                                                                                            • Opcode ID: d183bd6de85830525cb7ceee59674c147852317086f488bb6f66b97bacb00325
                                                                                                                                                                                                                                                            • Instruction ID: aa1bb5836c1de0d1ef682f8591ce90a3703f12a689013548ce40c659a79bdf58
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d183bd6de85830525cb7ceee59674c147852317086f488bb6f66b97bacb00325
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D1E06D72F2514BC3E7146B90E86896833A1FF50B45F4850B0E12A829D8DF3DA589DB04
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DeleteObject
                                                                                                                                                                                                                                                            • String ID: GC already registered in Tk_GetGC$called GCInit after GCCleanup
                                                                                                                                                                                                                                                            • API String ID: 1531683806-2292843906
                                                                                                                                                                                                                                                            • Opcode ID: f782b4660893fe0f24548096de4a558d9de1656e03ccc94a1b00e878edc6c854
                                                                                                                                                                                                                                                            • Instruction ID: 579eec5c1faa90115747a5df415eb0547ac7bdff18880ba1e3dc6625c3869f78
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f782b4660893fe0f24548096de4a558d9de1656e03ccc94a1b00e878edc6c854
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 83B15372B05B818AE7A4CF65E464BAC37B5F748B88F408026CA6D97798DF38E454C740
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • _invalid_parameter_noinfo.LIBCMT ref: 00007FF762A99F82
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A9B464: HeapFree.KERNEL32(?,?,?,00007FF762AA3F92,?,?,?,00007FF762AA3FCF,?,?,00000000,00007FF762AA4495,?,?,?,00007FF762AA43C7), ref: 00007FF762A9B47A
                                                                                                                                                                                                                                                              • Part of subcall function 00007FF762A9B464: GetLastError.KERNEL32(?,?,?,00007FF762AA3F92,?,?,?,00007FF762AA3FCF,?,?,00000000,00007FF762AA4495,?,?,?,00007FF762AA43C7), ref: 00007FF762A9B484
                                                                                                                                                                                                                                                            • GetModuleFileNameW.KERNEL32(?,?,?,?,?,00007FF762A8C165), ref: 00007FF762A99FA0
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorFileFreeHeapLastModuleName_invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: C:\Users\user\Desktop\ROh2ijuEpr.exe
                                                                                                                                                                                                                                                            • API String ID: 3580290477-1435481288
                                                                                                                                                                                                                                                            • Opcode ID: 6a4dbdaa8dd2b454c87b42bcae1ae77807c0d922a2c4c320371c355071f6a322
                                                                                                                                                                                                                                                            • Instruction ID: 02a1199e031b997a4e238caaeadfd03397ceba76a0f8b22a0a1ff78659e265c8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6a4dbdaa8dd2b454c87b42bcae1ae77807c0d922a2c4c320371c355071f6a322
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 56418032E18B12C5EF94FF26A9408B8A7A5FB44780BA44036ED4D47B56DEFDE841C260
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorFileLastWrite
                                                                                                                                                                                                                                                            • String ID: U
                                                                                                                                                                                                                                                            • API String ID: 442123175-4171548499
                                                                                                                                                                                                                                                            • Opcode ID: 57f6403a17afa6857eb93518903eebf05678db2d18f563f749b6ba14b42682ba
                                                                                                                                                                                                                                                            • Instruction ID: f3713a92358fd7d41139c798a35f3fbaecbd9df67ad5917f0a9b95c49fad62b9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 57f6403a17afa6857eb93518903eebf05678db2d18f563f749b6ba14b42682ba
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1541A462B28A41C5DBA0AF26E8447A9A7A0FB94794F904131EE8D87758DFFCD441C750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2001926560.00007FFDFA8D1000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFDFA8D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001899526.00007FFDFA8D0000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001926560.00007FFDFA953000.00000020.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002014486.00007FFDFA955000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002050433.00007FFDFA97D000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA982000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA988000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2002077632.00007FFDFA990000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa8d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Time$System$File
                                                                                                                                                                                                                                                            • String ID: gfff
                                                                                                                                                                                                                                                            • API String ID: 2838179519-1553575800
                                                                                                                                                                                                                                                            • Opcode ID: a0b97f4aea56fea0423c07e2c95279f2c9599c66744ee81c656443d2e1a48d07
                                                                                                                                                                                                                                                            • Instruction ID: 5849752bee54b136bba6a29c7753494347837ac2cd576a5cb28ac11347abac1d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a0b97f4aea56fea0423c07e2c95279f2c9599c66744ee81c656443d2e1a48d07
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: FA212572B1864686DB98CF29D4207B877E4EB88B84F44C179DA9DC7798DE3CE104C740
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.2000747180.00007FFDFA2D1000.00000020.00000001.01000000.00000036.sdmp, Offset: 00007FFDFA2D0000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000720400.00007FFDFA2D0000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000863128.00007FFDFA3D1000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000911172.00007FFDFA41D000.00000004.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000937005.00007FFDFA41E000.00000008.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2001132307.00007FFDFA427000.00000002.00000001.01000000.00000036.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ffdfa2d0000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DeleteObject
                                                                                                                                                                                                                                                            • String ID: Unable to free colormap, palette is still selected$unknown display passed to Tk_FreeColormap
                                                                                                                                                                                                                                                            • API String ID: 1531683806-343019491
                                                                                                                                                                                                                                                            • Opcode ID: e1279803d79908b8517ba06c5d936c1c9f5662a97df91f3b7625159be7d56a23
                                                                                                                                                                                                                                                            • Instruction ID: f5dd61fc665ceee993acfb383e55a975c1dde241321330091ee7327f7579d485
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e1279803d79908b8517ba06c5d936c1c9f5662a97df91f3b7625159be7d56a23
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 54316E3A709A56C3EB18AF56D86097967A4FB84F80F4840B1CE2D87798EF3CE450D340
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(00000000,?,?,?,00000000,00007FF762A828DA,FFFFFFFF,00000000,00007FF762A8336A), ref: 00007FF762A8218E
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentProcess
                                                                                                                                                                                                                                                            • String ID: WARNING$[PYI-%d:%s]
                                                                                                                                                                                                                                                            • API String ID: 2050909247-3752221249
                                                                                                                                                                                                                                                            • Opcode ID: 28628bd70d5a97629098dcd42eabd330bee057474c06a66384895197b474a4b9
                                                                                                                                                                                                                                                            • Instruction ID: 0eb64d26c4cd515024161dbb68a1f0abd9e0ac644ae1bd99e8c06514ef7b796c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 28628bd70d5a97629098dcd42eabd330bee057474c06a66384895197b474a4b9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6A114D72A19B8181EBA0AB51B881AEAB364FF887C4F800135EE8D53A59DEFCD155C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1989950599.0000000070181000.00000020.00000001.01000000.0000001C.sdmp, Offset: 70180000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1989924822.0000000070180000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990007416.0000000070203000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990033081.0000000070207000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990056614.0000000070208000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990083385.0000000070220000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990106509.0000000070223000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990130120.0000000070225000.00000008.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1990155549.0000000070229000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_70180000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Err_Format
                                                                                                                                                                                                                                                            • String ID: %s (%d:%d)
                                                                                                                                                                                                                                                            • API String ID: 376477240-1595188566
                                                                                                                                                                                                                                                            • Opcode ID: 3b0374ab8133883e3a59bbbf7a988afd3c0cf2285bdd71a4074ed055bd09bec3
                                                                                                                                                                                                                                                            • Instruction ID: f4c6eea8ab31af412ec2d7f4c810720686570b54ed503f18f719bd6f96c837ae
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3b0374ab8133883e3a59bbbf7a988afd3c0cf2285bdd71a4074ed055bd09bec3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1A01DF73E18B6489D7019719E88538D3761EB99BA0F9A4126CD4E17BA2CE2CC983C780
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ExceptionFileHeaderRaise
                                                                                                                                                                                                                                                            • String ID: csm
                                                                                                                                                                                                                                                            • API String ID: 2573137834-1018135373
                                                                                                                                                                                                                                                            • Opcode ID: 778d4a5eeee770603d02c5501bef52114850414878b0bee781498c4a1570bacf
                                                                                                                                                                                                                                                            • Instruction ID: 41bac1b582cd0326c5eade36639e426b90208622e18df68967ba50a053486a85
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 778d4a5eeee770603d02c5501bef52114850414878b0bee781498c4a1570bacf
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BC114C32608B8182EBA09B15F440669B7E0FB88B84F984234EEDD47B54DFBCD551C710
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000003.00000002.1999944971.00007FF762A81000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF762A80000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999917246.00007FF762A80000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.1999979870.00007FF762AAD000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC0000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000010144.00007FF762AC3000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000003.00000002.2000254219.00007FF762AC6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_3_2_7ff762a80000_ROh2ijuEpr.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DriveType_invalid_parameter_noinfo
                                                                                                                                                                                                                                                            • String ID: :
                                                                                                                                                                                                                                                            • API String ID: 2595371189-336475711
                                                                                                                                                                                                                                                            • Opcode ID: a21020f9989eba13c36801fee87724dcdfb53302495b3b0e02d80308072ceaa1
                                                                                                                                                                                                                                                            • Instruction ID: 98b49f67d9fef050f3940b7c82424ffe5923bd8f5c34704510572d160a3f00f1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a21020f9989eba13c36801fee87724dcdfb53302495b3b0e02d80308072ceaa1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AB017122A1C202C5EFF0BF609462A7EA3A0FF48744FC41535DE4D82A95DFECD504CA64